Skip to main content
Neon Postgres Docs

Search documentation

Type to search this documentation.

Create Neon Auth integration

POST/projects/auth/createCreate Neon Auth integration

Deprecated. Use /projects/{project_id}/branches/{branch_id}/auth instead. Removal scheduled for March 1, 2026. Use this endpoint if the frontend integration flow can't be used.

Request body

required
application/json
objectNeonAuthCreateIntegrationRequest
auth_providerstringrequired

Authentication provider integrated with this Neon Auth configuration. `better_auth` integrates with Better Auth (the current, recommended provider). `stack` integrates with Stack Auth (deprecated). `mock` is a simulated provider for local development and testing only.

one of "mock", "stack", "better_auth"

branch_idstringrequired

The Neon branch ID. Returned as `id` from `GET /projects/{project_id}/branches`.

pattern ^[a-z0-9-]{1,60}$

database_namestring

Name of the database to associate with the Neon Auth integration. When omitted, the integration uses the project's default database.

project_idstringrequired

The Neon project ID. Returned as `id` from `GET /projects`.

pattern ^[a-z0-9-]{1,60}$

role_namestring

Deprecated. The database role for the auth integration. Omit this field; it is ignored.

Example request
{
  "auth_provider": "better_auth",
  "branch_id": "br-cool-darkness-12345678",
  "database_name": "string",
  "project_id": "wispy-forest-12345678",
  "role_name": "string"
}

Responses

201Creates Neon Auth integrationapplication/json
objectNeonAuthCreateIntegrationResponse
auth_providerstringrequired

Authentication provider integrated with this Neon Auth configuration. `better_auth` integrates with Better Auth (the current, recommended provider). `stack` integrates with Stack Auth (deprecated). `mock` is a simulated provider for local development and testing only.

one of "mock", "stack", "better_auth"

auth_provider_project_idstringrequired

Project ID assigned by the auth provider for this integration.

base_urlstring

Base URL of the Neon Auth service for this integration. Set as the NEON_AUTH_BASE_URL environment variable in your application.

jwks_urlstringrequired

URL of the provider's JWKS endpoint used to verify JWTs.

pub_client_keystringrequired

Publishable SDK key from the auth provider. Populated only for Stack Auth (deprecated); empty for Better Auth.

schema_namestringrequired

Postgres schema containing the auth integration tables. Defaults to `neon_auth`.

secret_server_keystringrequired

Secret server-side SDK key from the auth provider. Populated only for Stack Auth (deprecated); empty for Better Auth. Treat as a credential.

table_namestringrequired

Postgres table in the integration schema where synced user records are stored.

Example response
{
  "auth_provider": "better_auth",
  "auth_provider_project_id": "string",
  "base_url": "string",
  "jwks_url": "string",
  "pub_client_key": "string",
  "schema_name": "string",
  "secret_server_key": "string",
  "table_name": "string"
}
defaultGeneral Error. The request may or may not be safe to retry, depending on the HTTP method, response status code, and whether a response was received. - If no response is returned from the API, a network error or timeout likely occurred. - In some cases, the request may have reached the server and been successfully processed, but the response failed to reach the client. As a result, retrying non-idempotent requests can lead to unintended results. The following HTTP methods are considered non-idempotent: `POST`, `PATCH`, `DELETE`, and `PUT`. Retrying these methods is generally **not safe**. The following methods are considered idempotent: `GET`, `HEAD`, and `OPTIONS`. Retrying these methods is **safe** in the event of a network error or timeout. Any request that returns a `503 Service Unavailable` response is always safe to retry. Any request that returns a `423 Locked` response is safe to retry. `423 Locked` indicates that the resource is temporarily locked, for example, due to another operation in progress. application/json
objectGeneralError
codestringrequired

default ""

messagestringrequired

Error message

request_idstring

Unique identifier for the request, useful for debugging. You can set this value manually by including an `X-Request-ID` header in the request. If not provided, the value will be generated automatically.

Example response
{
  "code": "",
  "message": "string",
  "request_id": "string"
}
Documentation menu