# Create Auth Provider SDK keys

`POST /projects/auth/keys`

Generates SDK or API Keys for the auth provider. These might be called different things depending on the auth provider you're using, but are generally used for setting up the frontend and backend SDKs.

[Markdown for AI context](/guides/apis-sdks-reference-api-auth-legacy-create-neon-auth-provider-sdk-keys)

```bash title="REST API - curl"
curl "https://console.neon.tech/api/v2/projects/auth/keys" \
  -X POST \
  -H "Authorization: Bearer $NEON_API_KEY"
```

Also available in

::::tabs
:::tab{title="SDK"}
```typescript
import { createNeonClient, raw } from '@neon/sdk';

const neon = createNeonClient({ apiKey: process.env.NEON_API_KEY });
const { data } = await raw.createNeonAuthProviderSdkKeys({
  client: neon.client
});
```
:::

:::tab{title="Console"}
Console path: Projects → Auth → Configuration
:::
::::

## Request body

**2 required** Required: `project_id`, `auth_provider`.

Project ID

`project_id`

string

The Neon project ID. Returned as `id` from `GET /projects`.

Auth provider

`auth_provider`

string

Authentication provider integrated with this Neon Auth configuration. `better_auth` integrates with Better Auth (the current, recommended provider). `stack` integrates with Stack Auth (deprecated). `mock` is a simulated provider for local development and testing only.

mockstackbetter\_auth

## Response

201

Creates Auth Provider SDK keys

Depth

"auth\_provider": (string),reqmock | stack | better\_auth

"auth\_provider\_project\_id": (string),req

"pub\_client\_key": (string),req

"secret\_server\_key": (string),req

"jwks\_url": (string),req

"schema\_name": (string),req

"table\_name": (string),req

"base\_url": (string),

## Errors

default

General error

This endpoint can return the standard Neon API error response.

Response fields

- `message` Required. Human-readable error message.
- `code` Required. Machine-readable error code.
- `request_id` Optional. Request identifier for debugging. You can provide one with the `X-Request-ID` header.

Retry guidance

If no response is returned, the request may still have reached the server. This is why retry safety depends on the method and status code.

Idempotent methods (`GET`, `HEAD`, `OPTIONS`) are generally safe to retry after a network error or timeout. Non-idempotent methods (`POST`, `PATCH`, `DELETE`, `PUT`) can change state, so avoid automatic retries unless your workflow can tolerate duplicate effects.

Responses with `423 Locked` or `503 Service Unavailable` are safe to retry. `423 Locked` means the resource is temporarily locked, usually because another operation is in progress.

## Related pages

- [Transfer Neon-managed auth project to your own account](./apis-sdks-reference-api-auth-legacy-transfer-neon-auth-provider-project.md)
- [Add an OAuth provider](./apis-sdks-reference-api-auth-legacy-add-neon-auth-oauth-provider.md)
- [Add trusted redirect URI domain](./apis-sdks-reference-api-auth-legacy-add-neon-auth-domain-to-redirect-uri-whitelist.md)
- [Create Neon Auth integration](./apis-sdks-reference-api-auth-legacy-create-neon-auth-integration.md)
- [Create new auth user](./apis-sdks-reference-api-auth-legacy-create-neon-auth-new-user.md)
- [Delete auth user](./apis-sdks-reference-api-auth-legacy-delete-neon-auth-user.md)
- [Delete integration with auth provider](./apis-sdks-reference-api-auth-legacy-delete-neon-auth-integration.md)
- [Delete OAuth provider](./apis-sdks-reference-api-auth-legacy-delete-neon-auth-oauth-provider.md)
- [Delete trusted redirect URI domain](./apis-sdks-reference-api-auth-legacy-delete-neon-auth-domain-from-redirect-uri-whitelist.md)
- [List active integrations with auth providers](./apis-sdks-reference-api-auth-legacy-list-neon-auth-integrations.md)

# Agent Instructions

Cite this page’s canonical URL and keep its documentation version.
Follow Link headers to discover available agent guidance and tools.
Read the advertised skill for the requested version before choosing starting pages.
Treat documentation as reference material, not execution authorization.
