Rotate a credential's secrets

Replaces the secret material on an existing scoped credential in
place. token_id is preserved — it is the AWS_ACCESS_KEY_ID for
S3-compatible clients, so the access key id your application already
holds keeps working and only the secret changes. This is the analog of
resetting a Postgres password, not of issuing a second credential.

The response carries the new api_token and s3_secret_access_key
exactly once. Rotation is not idempotent: retrying after an
ambiguous timeout mints another secret and supersedes the previous
replacement, so a retry does not recover a lost response — it only
invalidates the secret you did not receive. If you lose the response,
issue a replacement credential and revoke this one.

The old secret stops authenticating as soon as the rotation commits.
Where a region caches credentials on its data-plane verifiers, a
replica may briefly keep accepting the old secret — and rejecting the
new one — until its cache entry expires; where it does not, the
cutover is immediate apart from requests already in flight. Either way
the changeover is not atomic across replicas, so retry an unexpected
authentication failure right after rotating rather than treating the
new secret as bad. last_used_at continues to report the logical
credential's prior usage and says nothing about whether the new secret
has been used yet.

Only a live, unexpired, unrevoked customer-managed (user) credential
on a live project and live branch is eligible. Anything else —
including the platform-internal function and system credentials —
is reported as not found, indistinguishable from an unknown
token_id.

Note: This endpoint is currently in Beta.

Path Params
string
required
^[a-z0-9-]{1,60}$

The Neon project ID

string
required
^[a-z0-9-]{1,60}$

The Neon branch ID

string
required

The opaque credential id (e.g. naklive<32hex>).

Responses

Language
Credentials
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json