Skip to main content
Neon Postgres Docs
current

Search documentation

Type to search this documentation.

On this pageOverview

Neon CLI command: neon-auth

The neon auth command manages Managed Better Auth on a database branch from the terminal. You can enable or disable Managed Better Auth, configure OAuth providers, trusted domains, email settings, and...

The neon-auth command manages Managed Better Auth on a database branch from the terminal. You can enable or disable Managed Better Auth, configure OAuth providers, trusted domains, email settings, and webhooks, and manage auth users.

Subcommands: config, disable, domain, enable, oauth-provider, plugins, status, user

If --project-id or --branch are omitted, the CLI resolves them from your context file, auto-selects when there is only one option, and otherwise asks you to pass the flag.

Provisions Managed Better Auth on the current branch.

Bash
neon neon-auth enable [options]
Option Description Type Default Required
--database-name Database name to use for auth data string — No
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth enable

Shows whether Managed Better Auth is configured on the branch and displays the current connection details.

Bash
neon neon-auth status [options]
Option Description Type Default Required
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth status

Removes Managed Better Auth from the branch.

Bash
neon neon-auth disable [options]
Option Description Type Default Required
--delete-data Permanently delete all Neon Auth data and schema from the database boolean false No
--branch Branch ID or name string — No
--project-id Project ID string — No

Remove Managed Better Auth from the branch and delete its data:

Bash
neon neon-auth disable --delete-data

The oauth-provider subcommands manage the OAuth providers (google, github, and vercel) for the branch.

Subcommands: add, delete, list, update

Lists the OAuth providers configured for the branch.

Bash
neon neon-auth oauth-provider list [options]
Option Description Type Default Required
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth oauth-provider list

Adds an OAuth provider.

Bash
neon neon-auth oauth-provider add [options]
Option Description Type Default Required
--oauth-client-id OAuth client ID from your provider app. Omit to use Neon's shared OAuth app. string — No
--oauth-client-secret OAuth client secret from your provider app. Omit to use Neon's shared OAuth app. string — No
--provider-id OAuth provider ID. Supported values: google, github, vercel string — Yes
--branch Branch ID or name string — No
--project-id Project ID string — No

Add the Google OAuth provider with your own credentials:

Bash
neon neon-auth oauth-provider add --provider-id google --oauth-client-id <client-id> --oauth-client-secret <client-secret>

Updates the credentials for an existing OAuth provider.

Bash
neon neon-auth oauth-provider update [options]
Option Description Type Default Required
--oauth-client-id OAuth client ID from your provider app. Omit to use Neon's shared OAuth app. string — No
--oauth-client-secret OAuth client secret from your provider app. Omit to use Neon's shared OAuth app. string — No
--provider-id OAuth provider ID. Supported values: google, github, vercel string — Yes
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth oauth-provider update --provider-id github --oauth-client-id <client-id> --oauth-client-secret <client-secret>

Deletes an OAuth provider from the branch.

Bash
neon neon-auth oauth-provider delete [options]
Option Description Type Default Required
--provider-id OAuth provider ID. Supported values: google, github, vercel string — Yes
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth oauth-provider delete --provider-id vercel

The domain subcommands manage the trusted domains that Managed Better Auth accepts as redirect URIs for the branch.

Subcommands: add, allow-localhost, delete, list

Lists the trusted domains configured for the branch.

Bash
neon neon-auth domain list [options]
Option Description Type Default Required
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth domain list

Adds a trusted domain.

Bash
neon neon-auth domain add <domain> [options]
Option Description Type Default Required
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth domain add https://app.example.com

A trusted domain is an origin, so include the protocol (https://, or http:// for local development) and omit any trailing slash. Use https://app.example.com, not app.example.com or https://app.example.com/. See Configure trusted domains.

Deletes a trusted domain.

Bash
neon neon-auth domain delete <domain> [options]
Option Description Type Default Required
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth domain delete example.com

Manages localhost connection settings for the branch.

Subcommands: disable, enable, get

Gets the current localhost connection setting.

Bash
neon neon-auth domain allow-localhost get [options]
Option Description Type Default Required
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth domain allow-localhost get

neon neon-auth domain allow-localhost enable

Section titled “neon neon-auth domain allow-localhost enable”

Allows localhost connections for local development.

Bash
neon neon-auth domain allow-localhost enable [options]
Option Description Type Default Required
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth domain allow-localhost enable

neon neon-auth domain allow-localhost disable

Section titled “neon neon-auth domain allow-localhost disable”

Restricts localhost connections.

Bash
neon neon-auth domain allow-localhost disable [options]
Option Description Type Default Required
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth domain allow-localhost disable

The config subcommands configure auth features for the branch: email and password authentication, the email provider, the organization plugin, and webhooks.

Subcommands: email-password, email-provider, organization, webhook

Manages email and password authentication settings.

Subcommands: get, update

Gets the current email and password configuration.

Bash
neon neon-auth config email-password get [options]
Option Description Type Default Required
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth config email-password get

Updates the email and password configuration.

Bash
neon neon-auth config email-password update [options]
Option Description Type Default Required
--auto-sign-in-after-verification Auto sign in users after verifying their email boolean — No
--disable-sign-up Disable new user sign ups boolean — No
--email-verification-method Email verification method string — No
--enabled Enable email and password authentication boolean — No
--require-email-verification Require email verification before users can sign in boolean — No
--send-verification-email-on-sign-in Send verification email on sign in boolean — No
--send-verification-email-on-sign-up Send verification email on sign up boolean — No
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth config email-password update --enabled --require-email-verification

Manages the email provider configuration.

Subcommands: get, test, update

Gets the current email provider configuration.

Bash
neon neon-auth config email-provider get [options]
Option Description Type Default Required
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth config email-provider get

Updates the email provider configuration.

Bash
neon neon-auth config email-provider update [options]
Option Description Type Default Required
--host SMTP host (required for standard) string — No
--password SMTP password (required for standard) string — No
--port SMTP port (required for standard) number — No
--sender-email Sender email address string — No
--sender-name Sender display name string — No
--type Email provider type Possible values: standard, shared string — Yes
--username SMTP username (required for standard) string — No
--branch Branch ID or name string — No
--project-id Project ID string — No

Configure the standard email provider type with your own SMTP server:

Bash
neon neon-auth config email-provider update --type standard --host smtp.example.com --port 587 --username example_username --password AbC123dEf --sender-email noreply@example.com --sender-name "Example App"

Sends a test email through your saved SMTP provider so you can verify it works. Configure the provider first with update.

Bash
neon neon-auth config email-provider test [options]
Option Description Type Default Required
--recipient-email Email address to deliver the test message to string — Yes
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth config email-provider test --recipient-email user@example.com

Manages organization plugin settings.

Subcommands: get, update

Gets the current organization plugin configuration.

Bash
neon neon-auth config organization get [options]
Option Description Type Default Required
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth config organization get

Updates the organization plugin configuration.

Bash
neon neon-auth config organization update [options]
Option Description Type Default Required
--creator-role Role assigned to organization creator Possible values: admin, owner string — No
--enabled Enable the organization plugin boolean — No
--limit Maximum number of organizations a user can create number — No
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth config organization update --enabled --limit 5 --creator-role owner

Manages webhook configuration.

Subcommands: get, update

Gets the current webhook configuration.

Bash
neon neon-auth config webhook get [options]
Option Description Type Default Required
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth config webhook get

Updates the webhook configuration.

Bash
neon neon-auth config webhook update [options]
Option Description Type Default Required
--enabled Enable webhooks boolean — Yes
--enabled-events Events to enable Possible values: user.before_create, user.created, send.otp, send.magic_link string — No
--timeout Webhook timeout in seconds (1-10) number — No
--url Webhook endpoint URL string — No
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth config webhook update --enabled --url https://example.com/webhooks/neon-auth --enabled-events user.created --timeout 5

The plugins subcommands show the Managed Better Auth plugin configurations for the branch.

Subcommands: get, list

Lists all plugin configurations.

Bash
neon neon-auth plugins list [options]
Option Description Type Default Required
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth plugins list

Gets a specific plugin configuration.

Bash
neon neon-auth plugins get <plugin-name> [options]
Option Description Type Default Required
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth plugins get organization

The user subcommands manage Managed Better Auth users on the branch.

Subcommands: create, delete, set-role

Creates an auth user.

Bash
neon neon-auth user create [options]
Option Description Type Default Required
--email User email address string — Yes
--name User display name (defaults to email if not provided) string — No
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth user create --email alex@example.com --name "Alex Lopez"

Deletes an auth user.

Bash
neon neon-auth user delete <user-id> [options]
Option Description Type Default Required
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth user delete <user-id>

Sets roles for an auth user.

Bash
neon neon-auth user set-role <user-id> [options]
Option Description Type Default Required
--roles Roles to assign string — Yes
--branch Branch ID or name string — No
--project-id Project ID string — No
Bash
neon neon-auth user set-role <user-id> --roles admin
Suggest an edit

Propose a replacement for this page. The site team reviews it before applying any changes.

Export
Documentation menu