Skip to main content
Neon Postgres Docs
current

Search documentation

Type to search this documentation.

On this pageOverview

Neon CLI command: api-keys

The api keys command creates, lists, and revokes the API keys that authenticate requests to the Neon API. Keys belong to your account unless you pass org id or project id. A key is shown once, at crea...

The api-keys command creates, lists, and revokes the API keys that authenticate requests to the Neon API. Keys belong to your account unless you pass --org-id or --project-id.

A key is shown once, at creation. There is no way to retrieve it later.

For key types, revocation permissions, and rotation, see Manage API keys.

Subcommands: create, list, revoke

Lists key metadata, never the keys themselves.

Bash
neon api-keys list [options]
Option Description Type Default Required
--org-id List the organization's keys instead of your account's string — No

List your account keys:

Bash
neon api-keys list
title="Output"
Account API keys
┌─────────┬──────────────────────┬──────────────────────┬──────────────────────┬─────────────────────┐
│ Id      │ Name                 │ Created At           │ Last Used At         │ Last Used From Addr │
├─────────┼──────────────────────┼──────────────────────┼──────────────────────┼─────────────────────┤
│ 3225782 │ ci-deploy            │ 2026-07-29T00:50:26Z │ 2026-07-29T18:06:55Z │ 192.0.2.10          │
└─────────┴──────────────────────┴──────────────────────┴──────────────────────┴─────────────────────┘

Organization keys are invisible to your account, so listing them needs --org-id:

Bash
neon api-keys list --org-id org-example-12345678

This covers both scopes, since a project-scoped key is owned by the project's organization. The Project column tells them apart:

title="Output"
API keys in org-example-12345678
┌─────────┬─────────────┬───────────────────────┬──────────────────────┬──────────────────────┬─────────────────────┐
│ Id      │ Name        │ Project               │ Created At           │ Last Used At         │ Last Used From Addr │
├─────────┼─────────────┼───────────────────────┼──────────────────────┼──────────────────────┼─────────────────────┤
│ 3243240 │ preview-bot │ green-breeze-12345678 │ 2026-08-04T18:51:36Z │ 2026-08-05T18:51:36Z │ 192.0.2.10          │
├─────────┼─────────────┼───────────────────────┼──────────────────────┼──────────────────────┼─────────────────────┤
│ 3177950 │ org-key     │ (all projects)        │ 2026-07-08T01:28:49Z │ 2026-07-08T01:31:20Z │ 192.0.2.10          │
└─────────┴─────────────┴───────────────────────┴──────────────────────┴──────────────────────┴─────────────────────┘

(all projects) is a table label only. In JSON and YAML the field is project_id, and it is null for an organization-wide key:

Bash
neon api-keys list --org-id org-example-12345678 -o json
JSON
[
  { "id": 3243240, "name": "preview-bot", "project_id": "green-breeze-12345678" },
  { "id": 3177950, "name": "org-key", "project_id": null }
]

Creates a key and prints it once. --name is required.

By default the key reaches everything your account can, in every organization. Two mutually exclusive flags change that:

  • --project-id limits the key to one project. Use this for anything deployed, so a leaked key cannot reach your other projects.
  • --org-id transfers ownership to an organization. This is not a restriction: the key reaches every project in that organization, including ones created later.

Both organization forms need organization admin permissions. Each form prints a notice describing what the key can reach.

Bash
neon api-keys create [options]
Option Description Type Default Required
--name A name to identify the key later string — Yes
--org-id Create a key for this organization instead of your account string — No
--project-id Create a key that can access only this project. Its organization is looked up from the project string — No

Create an account key:

Bash
neon api-keys create --name ci-deploy
title="Output"
API key
┌─────────┬───────────┐
│ Id      │ Name      │
├─────────┼───────────┤
│ 3225782 │ ci-deploy │
└─────────┴───────────┘

napi_examplekey1234567890abcdefghijklmnopqrstuvwxyz
WARNING: Store this key now: it is not shown again.
WARNING: This key reaches everything your account can, in every organization. Pass --org-id or --project-id to narrow it.

Create a key owned by an organization:

Bash
neon api-keys create --name org-key --org-id org-example-12345678
title="Output"
API key
┌─────────┬─────────┐
│ Id      │ Name    │
├─────────┼─────────┤
│ 3177950 │ org-key │
└─────────┴─────────┘

napi_examplekey1234567890abcdefghijklmnopqrstuvwxyz
WARNING: Store this key now: it is not shown again.
WARNING: This key reaches every project in org-example-12345678, including ones created later. Pass --project-id instead to restrict it to one.

Create a key limited to one project. The output adds a Project column:

Bash
neon api-keys create --name preview-bot --project-id green-breeze-12345678
title="Output"
API key
┌─────────┬─────────────┬───────────────────────┐
│ Id      │ Name        │ Project               │
├─────────┼─────────────┼───────────────────────┤
│ 3243240 │ preview-bot │ green-breeze-12345678 │
└─────────┴─────────────┴───────────────────────┘

napi_examplekey1234567890abcdefghijklmnopqrstuvwxyz
WARNING: Store this key now: it is not shown again.
INFO: Limited to green-breeze-12345678: it cannot create projects, mint API keys, or read any other project. It can still change and delete everything inside that project.

The key is the last line of stdout, and the notices go to stderr, so you can capture it directly:

Bash
echo "NEON_API_KEY=$(neon api-keys create --name local-dev -o json | jq -r .key)" >> .env

Revokes a key immediately and permanently. Anything using it starts failing, so confirm the ID with api-keys list first.

Takes the numeric key ID, not the name. Organization and project-scoped keys need organization admin permissions. See who can revoke keys.

Bash
neon api-keys revoke <id> [options]
Option Description Type Default Required
--org-id Revoke an organization key instead of an account key string — No

Revoke an account key:

Bash
neon api-keys revoke 3225782
title="Output"
API key
┌─────────┬───────────┬─────────┬──────────────────────┐
│ Id      │ Name      │ Revoked │ Last Used At         │
├─────────┼───────────┼─────────┼──────────────────────┤
│ 3225782 │ ci-deploy │ true    │ 2026-07-29T18:06:55Z │
└─────────┴───────────┴─────────┴──────────────────────┘

Last Used At is empty for a key that was never used.

Revoke an organization or project-scoped key:

Bash
neon api-keys revoke 3243240 --org-id org-example-12345678

Without --org-id, the same command fails:

title="Output"
ERROR: No account API key with id 3243240. If it belongs to an organization, pass --org-id. Organization keys are not visible to your account.
Suggest an edit

Propose a replacement for this page. The site team reviews it before applying any changes.

Export
Documentation menu