/projects/{project_id}/branches/{branch_id}/buckets/{bucket_name}/objects/{object_key}/presignPresign an upload or download for an object in a bucketReturns a presigned URL that transfers bytes directly to or from the object's bucket on the specified branch, without the caller ever handling S3 credentials. The operation field selects the direction:
uploadreturns a presignedPUTURL (the callerPUTs the file
bytes straight to url with the returned headers). Authorized with project write access.
downloadreturns a presignedGETURL (the callerGETs the
bytes straight from url). Authorized with project read access.
The platform mints a short-lived credential and builds the SigV4-signed URL against the branch's S3 data-plane host, returning it together with the HTTP method, any headers the caller must echo, and the URL's expiry.
Served by the user's session (no customer S3 credentials required).
Note: This endpoint is currently in Beta.
Parameters
project_idstringpathrequiredThe Neon project ID
branch_idstringpathrequiredThe Neon branch ID
bucket_namestringpathrequiredThe bucket name
object_keystringpathrequiredThe object key. Keys may contain `/`; the `/` characters of nested keys must be percent-encoded (`%2F`) in the path segment.
Request body
requiredapplication/json
Options for the presigned URL. The `operation` selects upload (`PUT`) or download (`GET`); the remaining fields are optional.
content_typestringThe `Content-Type` to bind into the signed request. Only meaningful for `upload`: when set, the caller MUST send the same `Content-Type` header on the `PUT`, and the value is echoed back in the response `headers`. Ignored for `download`.
expires_in_secondsinteger · int64How long the presigned URL stays valid, in seconds. Defaults to 900 (15 minutes); capped at 604800 (7 days).
operationstringrequiredThe transfer direction. `upload` returns a presigned `PUT` URL; `download` returns a presigned `GET` URL.
{
"content_type": "string",
"expires_in_seconds": 900,
"operation": "download"
}Responses
expires_atstring · date-timerequiredWhen the presigned URL stops being valid.
headersobjectrequiredHeaders the caller MUST send verbatim on the request (e.g. `Content-Type` when it was signed on an upload). May be empty.
methodstringrequiredThe HTTP method to use against `url`: `PUT` for an upload, `GET` for a download.
urlstringrequiredThe presigned URL. Transfer the object bytes by issuing `method url` with the returned `headers`.
{
"expires_at": "2026-06-09T00:00:00Z",
"headers": {
"additionalProp1": "string"
},
"method": "string",
"url": "string"
}codestringrequiredmessagestringrequiredError message
request_idstringUnique identifier for the request, useful for debugging. You can set this value manually by including an `X-Request-ID` header in the request. If not provided, the value will be generated automatically.
{
"code": "",
"message": "string",
"request_id": "string"
}codestringrequiredmessagestringrequiredError message
request_idstringUnique identifier for the request, useful for debugging. You can set this value manually by including an `X-Request-ID` header in the request. If not provided, the value will be generated automatically.
{
"code": "",
"message": "string",
"request_id": "string"
}