Skip to main content
Neon Docs

Search documentation

Type to search this documentation.

Create Neon Data API

POST/projects/{project_id}/branches/{branch_id}/data-api/{database_name}Create Neon Data API

Creates a new instance of Neon Data API in the specified branch. The Data API exposes a REST interface over the branch database. The database_name path parameter determines which database the API serves.

Parameters

project_idstringpathrequired

The Neon project ID

pattern ^[a-z0-9-]{1,60}$

branch_idstringpathrequired

The Neon branch ID

pattern ^[a-z0-9-]{1,60}$

database_namestringpathrequired

The database name

Request body

application/json
objectDataAPICreateRequest

Create Neon Data API

add_default_grantsboolean

Grant all permissions to the tables in the public schema to authenticated users

default false

auth_providerstring

Authentication provider for the Neon Data API. `neon_auth`: use Neon's built-in managed authentication (no JWKS configuration required). `external`: use an external JWT provider, which requires `jwks_url`. When omitted, no auth provider is configured (existing setup is kept).

one of "neon_auth", "external"

jwks_urlstring · uri

URL of the JWKS endpoint used to verify JWTs for this Data API. Required when configuring JWT-based authentication; omit when using a non-JWT auth provider.

jwt_audiencestring

Expected `aud` claim in incoming JWTs. When set, tokens with a different audience are rejected; tokens with no audience are still accepted. Omit to skip audience validation.

provider_namestring

Display name for the authentication provider. Accepted values include "Clerk", "Stytch", and "Auth0", but any non-empty string is valid. Optional field.

settingsobject

Configuration settings for the Neon Data API

Show child attributes
db_aggregates_enabledboolean

Enable aggregates feature

default true

db_anon_rolestring

Database role to use for anonymous requests

default "anonymous"

db_extra_search_pathstring

Extra schemas to add to the search path

db_max_rowsinteger

Hard limit on the number of rows returned in a single Data API response. No limit when unset.

db_schemasarray of string

List of schemas to expose via the API. Default: ["public"]

Show child attributes
jwt_cache_max_lifetimeinteger

Maximum lifetime of the Data API's JWT cache, in seconds.

jwt_role_claim_keystring

JWT claim key to use for role extraction

default ".role"

openapi_modestring

OpenAPI specification mode (ignore-privileges, disabled)

default "disabled"

server_cors_allowed_originsstring

CORS allowed origins

server_timing_enabledboolean

When enabled, the Data API adds `Server-Timing` headers to each response showing database execution and internal processing time. Default: disabled.

skip_auth_schemaboolean

Skip creating the auth schema and RLS functions

default false

Example request
{
  "add_default_grants": false,
  "auth_provider": "external",
  "jwks_url": "https://example.com",
  "jwt_audience": "string",
  "provider_name": "string",
  "settings": {
    "db_aggregates_enabled": true,
    "db_anon_role": "anonymous",
    "db_extra_search_path": "string",
    "db_max_rows": 0,
    "db_schemas": [
      "string"
    ],
    "jwt_cache_max_lifetime": 0,
    "jwt_role_claim_key": ".role",
    "openapi_mode": "disabled",
    "server_cors_allowed_origins": "string",
    "server_timing_enabled": true
  },
  "skip_auth_schema": false
}

Responses

201Creates a new appapplication/json
objectDataAPICreateResponse

Neon Data API created successfully

urlstring · urirequired

URL of the created Data API endpoint.

Example response
{
  "url": "https://example.com"
}
defaultGeneral Error. The request may or may not be safe to retry, depending on the HTTP method, response status code, and whether a response was received. - If no response is returned from the API, a network error or timeout likely occurred. - In some cases, the request may have reached the server and been successfully processed, but the response failed to reach the client. As a result, retrying non-idempotent requests can lead to unintended results. The following HTTP methods are considered non-idempotent: `POST`, `PATCH`, `DELETE`, and `PUT`. Retrying these methods is generally **not safe**. The following methods are considered idempotent: `GET`, `HEAD`, and `OPTIONS`. Retrying these methods is **safe** in the event of a network error or timeout. Any request that returns a `503 Service Unavailable` response is always safe to retry. Any request that returns a `423 Locked` response is safe to retry. `423 Locked` indicates that the resource is temporarily locked, for example, due to another operation in progress. application/json
objectGeneralError
codestringrequired

default ""

messagestringrequired

Error message

request_idstring

Unique identifier for the request, useful for debugging. You can set this value manually by including an `X-Request-ID` header in the request. If not provided, the value will be generated automatically.

Example response
{
  "code": "",
  "message": "string",
  "request_id": "string"
}
Documentation menu