Skip to main content
Neon Docs

Search documentation

Type to search this documentation.

List JWKS URLs

GET/projects/{project_id}/jwksList JWKS URLs

Returns the JWKS URLs available for verifying JWTs used as the authentication mechanism for the specified project.

Parameters

project_idstringpathrequired

The Neon project ID

pattern ^[a-z0-9-]{1,60}$

Responses

200The JWKS URLs available for the projectapplication/json
objectProjectJWKSResponse

The list of configured JWKS definitions for a project

jwksarray of objectrequired

JWKS configurations associated with the project.

Show child attributes
Show array items
branch_idstring

The Neon branch ID. Returned as `id` from `GET /projects/{project_id}/branches`.

pattern ^[a-z0-9-]{1,60}$

created_atstring · date-timerequired

The date and time when the JWKS was created

idstringrequired

The JWKS configuration's ID.

jwks_urlstringrequired

URL of the provider's JWKS endpoint used to verify JWTs.

jwt_audiencestring

Expected JWT `aud` claim value configured for this JWKS.

project_idstringrequired

The Neon project ID. Returned as `id` from `GET /projects`.

pattern ^[a-z0-9-]{1,60}$

provider_namestringrequired

The name of the authentication provider (e.g., Clerk, Stytch, Auth0)

role_namesarray of string

Database role names that are permitted to authenticate using this JWKS configuration.

Show child attributes
updated_atstring · date-timerequired

The date and time when the JWKS was last modified

Example response
{
  "jwks": [
    {
      "branch_id": "string",
      "created_at": "2026-06-09T00:00:00Z",
      "id": "string",
      "jwks_url": "string",
      "jwt_audience": "string",
      "project_id": "string",
      "provider_name": "string",
      "role_names": [
        "string"
      ],
      "updated_at": "2026-06-09T00:00:00Z"
    }
  ]
}
defaultGeneral Error. The request may or may not be safe to retry, depending on the HTTP method, response status code, and whether a response was received. - If no response is returned from the API, a network error or timeout likely occurred. - In some cases, the request may have reached the server and been successfully processed, but the response failed to reach the client. As a result, retrying non-idempotent requests can lead to unintended results. The following HTTP methods are considered non-idempotent: `POST`, `PATCH`, `DELETE`, and `PUT`. Retrying these methods is generally **not safe**. The following methods are considered idempotent: `GET`, `HEAD`, and `OPTIONS`. Retrying these methods is **safe** in the event of a network error or timeout. Any request that returns a `503 Service Unavailable` response is always safe to retry. Any request that returns a `423 Locked` response is safe to retry. `423 Locked` indicates that the resource is temporarily locked, for example, due to another operation in progress. application/json
objectGeneralError
codestringrequired

default ""

messagestringrequired

Error message

request_idstring

Unique identifier for the request, useful for debugging. You can set this value manually by including an `X-Request-ID` header in the request. If not provided, the value will be generated automatically.

Example response
{
  "code": "",
  "message": "string",
  "request_id": "string"
}
Documentation menu