/projects/{project_id}/branches/{branch_id}/credentials/{token_id}/rotateRotate a credential's secretsReplaces the secret material on an existing scoped credential in place. token_id is preserved — it is the AWS_ACCESS_KEY_ID for S3-compatible clients, so the access key id your application already holds keeps working and only the secret changes. This is the analog of resetting a Postgres password, not of issuing a second credential.
The response carries the new api_token and s3_secret_access_key exactly once. Rotation is not idempotent: retrying after an ambiguous timeout mints another secret and supersedes the previous replacement, so a retry does not recover a lost response — it only invalidates the secret you did not receive. If you lose the response, issue a replacement credential and revoke this one.
The old secret stops authenticating as soon as the rotation commits. Where a region caches credentials on its data-plane verifiers, a replica may briefly keep accepting the old secret — and rejecting the new one — until its cache entry expires; where it does not, the cutover is immediate apart from requests already in flight. Either way the changeover is not atomic across replicas, so retry an unexpected authentication failure right after rotating rather than treating the new secret as bad. last_used_at continues to report the logical credential's prior usage and says nothing about whether the new secret has been used yet.
Only a live, unexpired, unrevoked customer-managed (user) credential on a live project and live branch is eligible. Anything else — including the platform-internal function and system credentials — is reported as not found, indistinguishable from an unknown token_id.
Note: This endpoint is currently in Beta.
Parameters
project_idstringpathrequiredThe Neon project ID
branch_idstringpathrequiredThe Neon branch ID
token_idstringpathrequiredThe opaque credential id (e.g. nak_live_<32hex>).
Responses
The replacement secret material for an existing credential, returned exactly once. `token_id`, `scopes`, `branch_id` and `created_at` are unchanged by the rotation — only `api_token` and `s3_secret_access_key` are new.
api_tokenstringrequiredThe new Bearer token; returned exactly once.
branch_idstringrequiredcreated_atstring · date-timerequiredWhen the credential was originally issued. Rotation replaces the secrets in place and does not reset this.
expires_atstring · date-timeWhen the credential expires; absent means never expires. Rotation does not extend it.
namestringCustomer-supplied label carried on the credential. Absent when none was set at issuance.
principal_typestringrequiredAlways `user`: only customer-managed credentials are rotatable through this endpoint.
s3_secret_access_keystringrequiredThe new nsk_live_<64 hex> AWS_SECRET_ACCESS_KEY; returned exactly once.
scopesarray of stringrequiredShow child attributes
token_idstringrequiredOpaque credential id (e.g. nak_live_<32hex>), unchanged by the rotation. Doubles as the `AWS_ACCESS_KEY_ID` for SigV4.
token_id_shortstringrequiredFirst 12 hex chars of token_id; safe to log.
{
"api_token": "",
"branch_id": "string",
"created_at": "2026-06-09T00:00:00Z",
"expires_at": "2026-06-09T00:00:00Z",
"name": "string",
"principal_type": "user",
"s3_secret_access_key": "string",
"scopes": [
"ai_gateway:invoke"
],
"token_id": "string",
"token_id_short": "string"
}codestringrequiredmessagestringrequiredError message
request_idstringUnique identifier for the request, useful for debugging. You can set this value manually by including an `X-Request-ID` header in the request. If not provided, the value will be generated automatically.
{
"code": "",
"message": "string",
"request_id": "string"
}