Skip to main content
Neon Docs

Search documentation

Type to search this documentation.

Retrieve masking rules

GET/projects/{project_id}/branches/{branch_id}/masking_rulesRetrieve masking rules

Retrieves the masking rules for the specified anonymized branch. Masking rules define how sensitive data should be anonymized using PostgreSQL Anonymizer.

Note: This endpoint is currently in Beta.

Parameters

project_idstringpathrequired

The Neon project ID

pattern ^[a-z0-9-]{1,60}$

branch_idstringpathrequired

The branch ID

pattern ^[a-z0-9-]{1,60}$

Responses

200Masking rules retrieved successfullyapplication/json
objectMaskingRulesResponse
masking_rulesarray of objectrequired

List of masking rules for the branch

Show child attributes
Show array items
column_namestringrequired

The name of the column to be masked

database_namestringrequired

The name of the database containing the table to be masked

masking_functionstring

The PostgreSQL Anonymizer masking function to apply. Can be a predefined function (e.g., 'anon.random_string(10)', 'anon.fake_email()') or a custom function definition (e.g., 'anon.hash(column_name)')

masking_valuestring

A literal value to set on the column when masking.

schema_namestringrequired

The name of the schema containing the table to be masked

table_namestringrequired

The name of the table containing the column to be masked

Example response
{
  "masking_rules": [
    {
      "column_name": "email",
      "database_name": "neondb",
      "masking_function": "anon.fake_email()",
      "schema_name": "public",
      "table_name": "users"
    }
  ]
}
defaultGeneral Error. The request may or may not be safe to retry, depending on the HTTP method, response status code, and whether a response was received. - If no response is returned from the API, a network error or timeout likely occurred. - In some cases, the request may have reached the server and been successfully processed, but the response failed to reach the client. As a result, retrying non-idempotent requests can lead to unintended results. The following HTTP methods are considered non-idempotent: `POST`, `PATCH`, `DELETE`, and `PUT`. Retrying these methods is generally **not safe**. The following methods are considered idempotent: `GET`, `HEAD`, and `OPTIONS`. Retrying these methods is **safe** in the event of a network error or timeout. Any request that returns a `503 Service Unavailable` response is always safe to retry. Any request that returns a `423 Locked` response is safe to retry. `423 Locked` indicates that the resource is temporarily locked, for example, due to another operation in progress. application/json
objectGeneralError
codestringrequired

default ""

messagestringrequired

Error message

request_idstring

Unique identifier for the request, useful for debugging. You can set this value manually by including an `X-Request-ID` header in the request. If not provided, the value will be generated automatically.

Example response
{
  "code": "",
  "message": "string",
  "request_id": "string"
}
Documentation menu