GET
/projects/{project_id}/branches/{branch_id}/credentialsList credentials on the branchReturns metadata for customer-issued credentials on the branch. Secrets are never included.
Note: This endpoint is currently in Beta.
Parameters
project_idstringpathrequiredThe Neon project ID
branch_idstringpathrequiredThe Neon branch ID
Responses
objectListCredentialsResponse
credentialsarray of objectrequiredShow child attributes
Show array items
branch_idstringcreated_atstring · date-timerequiredexpires_atstring · date-timeWhen the credential expires; absent means never expires. The verifier refuses to authenticate after `expires_at <= now()`.
function_idstringlast_used_atstring · date-timenamestringCustomer-supplied label; absent when not provided at issuance.
principal_typestringrequiredrevoked_atstring · date-timescopesarray of stringrequiredShow child attributes
token_idstringrequiredOpaque credential id (e.g. nak_live_<32hex>).
token_id_shortstringrequired{
"credentials": [
{
"branch_id": "string",
"created_at": "2026-06-09T00:00:00Z",
"expires_at": "2026-06-09T00:00:00Z",
"function_id": "string",
"last_used_at": "2026-06-09T00:00:00Z",
"name": "string",
"principal_type": "string",
"revoked_at": "2026-06-09T00:00:00Z",
"scopes": [
"ai_gateway:invoke"
],
"token_id": "string",
"token_id_short": "string"
}
]
}objectGeneralError
codestringrequiredmessagestringrequiredError message
request_idstringUnique identifier for the request, useful for debugging. You can set this value manually by including an `X-Request-ID` header in the request. If not provided, the value will be generated automatically.
{
"code": "",
"message": "string",
"request_id": "string"
}