Create Neon Auth integration
API Reference / Legacy Auth / Create Neon Auth integration
POST /projects/auth/create
Section titled “POST /projects/auth/create”Deprecated. Use /projects/{project_id}/branches/{branch_id}/auth instead. Removal scheduled for March 1, 2026.
Use this endpoint if the frontend integration flow can't be used.
Request body
Section titled “Request body”auth_provider(string, required) Authentication provider integrated with this Neon Auth configuration.better_authintegrates with Better Auth (the current, recommended provider).stackintegrates with Stack Auth (deprecated).mockis a simulated provider for local development and testing only. Possible values:mock,stack,better_authproject_id(string, required) The Neon project ID. Returned asidfromGET /projects.branch_id(string, required) The Neon branch ID. Returned asidfromGET /projects/{project_id}/branches.database_name(string, optional) Name of the database to associate with the Neon Auth integration. When omitted, the integration uses the project's default database.role_name(string, optional, deprecated) Deprecated. The database role for the auth integration. Omit this field; it is ignored.
Response (201)
Section titled “Response (201)”auth_provider(string, optional) Authentication provider integrated with this Neon Auth configuration.better_authintegrates with Better Auth (the current, recommended provider).stackintegrates with Stack Auth (deprecated).mockis a simulated provider for local development and testing only. Possible values:mock,stack,better_authauth_provider_project_id(string, optional) Project ID assigned by the auth provider for this integration.pub_client_key(string, optional) Publishable SDK key from the auth provider. Populated only for Stack Auth (deprecated); empty for Better Auth.secret_server_key(string, optional) Secret server-side SDK key from the auth provider. Populated only for Stack Auth (deprecated); empty for Better Auth. Treat as a credential.jwks_url(string, optional) URL of the provider's JWKS endpoint used to verify JWTs.schema_name(string, optional) Postgres schema containing the auth integration tables. Defaults toneon_auth.table_name(string, optional) Postgres table in the integration schema where synced user records are stored.base_url(string, optional) Base URL of the Neon Auth service for this integration. Set as the NEON_AUTH_BASE_URL environment variable in your application.
Code examples
Section titled “Code examples”curl "https://console.neon.tech/api/v2/projects/auth/create" \
-X POST \
-H "Authorization: Bearer $NEON_API_KEY"import { createNeonClient, raw } from '@neon/sdk';
const neon = createNeonClient({ apiKey: process.env.NEON_API_KEY });
const { data } = await raw.createNeonAuthIntegration({
client: neon.client
});Errors
Section titled “Errors”default General Error.
The request may or may not be safe to retry, depending on the HTTP method, response status code, and whether a response was received.
- If no response is returned from the API, a network error or timeout likely occurred.
- In some cases, the request may have reached the server and been successfully processed, but the response failed to reach the client. As a result, retrying non-idempotent requests can lead to unintended results.
The following HTTP methods are considered non-idempotent: POST, PATCH, DELETE, and PUT. Retrying these methods is generally not safe.
The following methods are considered idempotent: GET, HEAD, and OPTIONS. Retrying these methods is safe in the event of a network error or timeout.
Any request that returns a 503 Service Unavailable response is always safe to retry.
Any request that returns a 423 Locked response is safe to retry. 423 Locked indicates that the resource is temporarily locked, for example, due to another operation in progress.
-
request_id(string, optional) Unique identifier for the request, useful for debugging. You can set this value manually by including anX-Request-IDheader in the request. If not provided, the value will be generated automatically. -
code(string, required) Machine-readable code classifying the error type. Seemessagefor a human-readable explanation. Default: `` -
message(string, required) Error message