Project

Adds a JWKS URL to the specified project for verifying JWTs used as the authentication mechanism.

The URL must be a valid HTTPS URL that returns a JSON Web Key Set.

The provider_name field allows you to specify which authentication provider you're using (e.g., Clerk, Auth0, AWS Cognito).

The branch_id scopes the JWKS URL to specific branches; if not specified, it applies to all branches.

The role_names scopes the URL to specific roles; if not specified, default roles are used (authenticator, authenticated, anonymous).

The jwt_audience specifies which aud values are accepted in JWTs.

post/projects/{project_id}/jwks

Request

  • Base URL: https://console.neon.tech/api/v2
  • URL: https://console.neon.tech/api/v2/projects/{project_id}/jwks
  • Auth: one of:
    • HTTP bearer
    • API key in cookie zenith
    • API key in cookie keycloak_token

Request body

jwks_urlstring required

URL of the provider's JWKS endpoint used to verify JWTs.

provider_namestring required

The name of the authentication provider (e.g., Clerk, Stytch, Auth0)

branch_idstring

The Neon branch ID. Returned as id from GET /projects/{project_id}/branches.

jwt_audiencestring

Expected aud claim in incoming JWTs. When set, tokens with a different audience are rejected; tokens with no audience are still accepted. Omit to skip audience validation.

role_namesstring[]

Deprecated. The roles the JWKS should be mapped to. By default, the JWKS is mapped to the authenticator, authenticated, and anonymous roles.

skip_role_creationboolean

Deprecated. Only used with Neon RLS. If true, role creation is skipped.

Response

The JWKS URL was added to the project's authentication connections

Example response

{
  "operations": [
    {
      "id": "d8ac46eb-a757-42b1-9907-f78322ee394e",
      "project_id": "spring-example-302709",
      "branch_id": "br-wispy-meadow-118737",
      "endpoint_id": "ep-silent-smoke-806639",
      "action": "start_compute",
      "status": "finished",
      "failures_count": 0,
      "created_at": "2022-11-15T20:02:00Z",
      "updated_at": "2022-11-15T20:02:02Z",
      "total_duration_ms": 200
    }
  ]
}

Changes

    • ●

      added the new epc_sync enum value to the ////// response property for the response status

    • ●

      added the new tenant_attach_safekeepers enum value to the ////// response property for the response status

    • ●

      added the new tenant_detach_safekeepers enum value to the ////// response property for the response status