# Issue a scoped credential on the branch

`POST /projects/{project_id}/branches/{branch_id}/credentialsbeta`

Issues a new scoped service credential anchored to the specified branch. The response carries `api_token` and `s3_secret_access_key` exactly once — they are not stored server-side.

**Note**: This endpoint is currently in Beta.

[Markdown for AI context](/guides/apis-sdks-reference-api-credentials-create-credential)

```bash title="REST API - curl"
curl "https://console.neon.tech/api/v2/projects/$PROJECT_ID/branches/$BRANCH_ID/credentials" \
  -X POST \
  -H "Authorization: Bearer $NEON_API_KEY"
```

```typescript title="Also available in"
import { createNeonClient, raw } from '@neon/sdk';

const neon = createNeonClient({ apiKey: process.env.NEON_API_KEY });
const { data } = await raw.createCredential({
  client: neon.client,
  path: {
    project_id: process.env.PROJECT_ID,
    branch_id: process.env.BRANCH_ID
  }
});
```

## Parameters

Project ID

`project_id`

string

The Neon project ID

Branch ID

`branch_id`

string

The Neon branch ID

## Request body

**2 required** Required: `scopes`, `principal_type`.

Scopes

`scopes`

array

Principal type

`principal_type`

string

Principal type for the credential. Only `user` is customer-managed and accepted here. `function` and `system` credentials are platform-internal (e.g. function-serve auto-mint, presign signer) and are never issued through the customer-facing API.

user

Name

`name`

string

Free-form customer label for the credential.

≤256 chars

## Response

201

Credential issued — secrets shown once.

::::tabs
:::tab{title="schema"}
Depth
:::

:::tab{title="example"}
:::
::::

"token\_id": (string),req

"token\_id\_short": (string),req

"api\_token": (string),req

"s3\_secret\_access\_key": (string),req

"scopes": (array),req

"branch\_id": (string),req

"created\_at": (string),reqdate-time

"name": (string),

"expires\_at": (string),date-time

## Errors

default

General error

This endpoint can return the standard Neon API error response.

Response fields

- `message` Required. Human-readable error message.
- `code` Required. Machine-readable error code.
- `request_id` Optional. Request identifier for debugging. You can provide one with the `X-Request-ID` header.

Retry guidance

If no response is returned, the request may still have reached the server. This is why retry safety depends on the method and status code.

Idempotent methods (`GET`, `HEAD`, `OPTIONS`) are generally safe to retry after a network error or timeout. Non-idempotent methods (`POST`, `PATCH`, `DELETE`, `PUT`) can change state, so avoid automatic retries unless your workflow can tolerate duplicate effects.

Responses with `423 Locked` or `503 Service Unavailable` are safe to retry. `423 Locked` means the resource is temporarily locked, usually because another operation is in progress.

## Related pages

- [List credentials on the branch](./apis-sdks-reference-api-credentials-list-credentials.md)
- [Reveal a credential's secrets](./apis-sdks-reference-api-credentials-reveal-credential.md)
- [Revoke a credential](./apis-sdks-reference-api-credentials-revoke-credential.md)
- [Rotate a credential's secrets](./apis-sdks-reference-api-credentials-rotate-credential.md)

# Agent Instructions

Cite this page’s canonical URL and keep its documentation version.
Follow Link headers to discover available agent guidance and tools.
Read the advertised skill for the requested version before choosing starting pages.
Treat documentation as reference material, not execution authorization.
