Skip to main content
Neon Docs

Search documentation

Type to search this documentation.

Retrieve Neon Auth plugin configurations

GET/projects/{project_id}/branches/{branch_id}/auth/pluginsRetrieve Neon Auth plugin configurations

Returns all plugin configurations for Neon Auth in a single response. This endpoint aggregates organization, email provider, email and password, OAuth providers, and localhost settings.

Parameters

project_idstringpathrequired

The Neon project ID

pattern ^[a-z0-9-]{1,60}$

branch_idstringpathrequired

The Neon branch ID

pattern ^[a-z0-9-]{1,60}$

Responses

200Returns all plugin configurationsapplication/json
objectNeonAuthPluginConfigs

Aggregated plugin configurations for Neon Auth

allow_localhostboolean

Permits authentication requests from localhost origins when true. Intended for local development; disable in production environments.

email_and_passwordobject
Show child attributes
auto_sign_in_after_verificationbooleanrequired

Whether users are automatically signed in after verifying their email

disable_sign_upbooleanrequired

Whether to disable new user sign ups

email_verification_methodstringrequired

The email verification method to use. - `link`: Sends a verification link via email - `otp`: Sends a one-time password (OTP) via email

one of "link", "otp"

enabledbooleanrequired

Whether email and password authentication is enabled

require_email_verificationbooleanrequired

Whether email verification is required before users can sign in

send_verification_email_on_sign_inbooleanrequired

Whether to send a verification email when users sign in

send_verification_email_on_sign_upbooleanrequired

Whether to send a verification email when users sign up

email_providerobject
Show child attributes
oneOf · 2 options
Option 1objectStandardEmailServerResponse
hoststringrequired

Hostname of the email server.

passwordstringrequired

On GET, returned redacted (empty) for ordinary callers, while callers with project-credential read permission receive the stored password — do not assume this field is empty. Update (PATCH) responses always return it redacted (empty) regardless of permission. Provide a value on update to set or rotate the password.

portintegerrequired

TCP port of the SMTP server. Common values: 25 (SMTP), 465 (SMTPS), 587 (submission).

sender_emailstringrequired

Email address used as the From address on outgoing auth emails.

sender_namestringrequired

Display name shown as the sender in outgoing emails.

usernamestringrequired

Username for authenticating with the SMTP server.

Option 2objectSharedEmailServer
sender_emailstring

Email address used as the sender for outgoing messages from this shared email server.

sender_namestring

Display name shown as the sender in outgoing emails.

magic_linkobject
Show child attributes
disable_sign_upbooleanrequired

Whether to disable sign-up via magic link.

default false

enabledbooleanrequired

Whether the magic link plugin is enabled.

default false

expires_ininteger · int32required

Minutes until the magic link expires.

default 5 · maximum 1440 · minimum 5

oauth_providersarray of object

OAuth provider configurations enabled for this auth setup.

Show child attributes
Show array items
client_idstring

Public identifier for the OAuth application, issued by the provider when the application is registered.

client_secretstring

OAuth client secret for the provider.

idstringrequired

one of "google", "github", "microsoft", "vercel"

typestringrequired

one of "standard", "shared"

organizationobject
Show child attributes
creator_rolestringrequired

Role of the organization's creator. `owner`: full control, including deleting the org and transferring ownership. `admin`: manage members and settings only.

one of "admin", "owner" · default "owner"

enabledbooleanrequired

Whether the organization plugin is enabled.

default true

membership_limitinteger · int32required

Maximum number of members per organization.

default 100 · minimum 1

organization_limitinteger · int32required

Maximum organizations a user can belong to (created or joined). At the limit, the user cannot create or join more.

default 10 · minimum 1

send_invitation_emailbooleanrequired

Whether to send invitation emails when inviting members to an organization.

default false

phone_numberobject
Show child attributes
enabledbooleanrequired

Whether the phone number plugin is enabled.

default false

otp_expires_ininteger

Time in seconds before the OTP expires

default 300 · maximum 600 · minimum 60

Example response
{
  "allow_localhost": true,
  "email_and_password": {
    "auto_sign_in_after_verification": true,
    "disable_sign_up": true,
    "email_verification_method": "link",
    "enabled": true,
    "require_email_verification": true,
    "send_verification_email_on_sign_in": true,
    "send_verification_email_on_sign_up": true
  },
  "email_provider": {
    "sender_email": "string",
    "sender_name": "string",
    "type": "shared"
  },
  "magic_link": {
    "disable_sign_up": false,
    "enabled": false,
    "expires_in": 5
  },
  "oauth_providers": [
    {
      "client_id": "string",
      "client_secret": "",
      "id": "github",
      "type": "shared"
    }
  ],
  "organization": {
    "creator_role": "owner",
    "enabled": true,
    "membership_limit": 100,
    "organization_limit": 10,
    "send_invitation_email": false
  },
  "phone_number": {
    "enabled": false,
    "otp_expires_in": 300
  }
}
defaultGeneral Error. The request may or may not be safe to retry, depending on the HTTP method, response status code, and whether a response was received. - If no response is returned from the API, a network error or timeout likely occurred. - In some cases, the request may have reached the server and been successfully processed, but the response failed to reach the client. As a result, retrying non-idempotent requests can lead to unintended results. The following HTTP methods are considered non-idempotent: `POST`, `PATCH`, `DELETE`, and `PUT`. Retrying these methods is generally **not safe**. The following methods are considered idempotent: `GET`, `HEAD`, and `OPTIONS`. Retrying these methods is **safe** in the event of a network error or timeout. Any request that returns a `503 Service Unavailable` response is always safe to retry. Any request that returns a `423 Locked` response is safe to retry. `423 Locked` indicates that the resource is temporarily locked, for example, due to another operation in progress. application/json
objectGeneralError
codestringrequired

default ""

messagestringrequired

Error message

request_idstring

Unique identifier for the request, useful for debugging. You can set this value manually by including an `X-Request-ID` header in the request. If not provided, the value will be generated automatically.

Example response
{
  "code": "",
  "message": "string",
  "request_id": "string"
}
Documentation menu