Skip to main content
Neon Postgres Docs
current

Search documentation

Type to search this documentation.

On this pageOverview

Create Auth Provider SDK keys

Generates SDK or API Keys for the auth provider. These might be called different things depending

POST /projects/auth/keys

Generates SDK or API Keys for the auth provider. These might be called different things depending on the auth provider you're using, but are generally used for setting up the frontend and backend SDKs.

Markdown for AI context

REST API - curl
curl "https://console.neon.tech/api/v2/projects/auth/keys" \
  -X POST \
  -H "Authorization: Bearer $NEON_API_KEY"

Also available in

TypeScript
import { createNeonClient, raw } from '@neon/sdk';

const neon = createNeonClient({ apiKey: process.env.NEON_API_KEY });
const { data } = await raw.createNeonAuthProviderSdkKeys({
  client: neon.client
});

Console path: Projects → Auth → Configuration

2 required Required: project_id, auth_provider.

Project ID

project_id

string

The Neon project ID. Returned as id from GET /projects.

Auth provider

auth_provider

string

Authentication provider integrated with this Neon Auth configuration. better_auth integrates with Better Auth (the current, recommended provider). stack integrates with Stack Auth (deprecated). mock is a simulated provider for local development and testing only.

mockstackbetter_auth

201

Creates Auth Provider SDK keys

Depth

"auth_provider": (string),reqmock | stack | better_auth

"auth_provider_project_id": (string),req

"pub_client_key": (string),req

"secret_server_key": (string),req

"jwks_url": (string),req

"schema_name": (string),req

"table_name": (string),req

"base_url": (string),

default

General error

This endpoint can return the standard Neon API error response.

Response fields

  • message Required. Human-readable error message.
  • code Required. Machine-readable error code.
  • request_id Optional. Request identifier for debugging. You can provide one with the X-Request-ID header.

Retry guidance

If no response is returned, the request may still have reached the server. This is why retry safety depends on the method and status code.

Idempotent methods (GET, HEAD, OPTIONS) are generally safe to retry after a network error or timeout. Non-idempotent methods (POST, PATCH, DELETE, PUT) can change state, so avoid automatic retries unless your workflow can tolerate duplicate effects.

Responses with 423 Locked or 503 Service Unavailable are safe to retry. 423 Locked means the resource is temporarily locked, usually because another operation is in progress.

Suggest an edit

Propose a replacement for this page. The site team reviews it before applying any changes.

Export
Documentation menu