---
title: "List credentials on the branch"
method: GET
path: "/projects/{project_id}/branches/{branch_id}/credentials"
tags: ["Credentials"]
---

# List credentials on the branch

`GET /projects/{project_id}/branches/{branch_id}/credentials`

Returns metadata for customer-issued credentials on the branch.
Secrets are never included.

**Note**: This endpoint is currently in Private Beta.

## Response `200`

The list of credentials

- ListCredentialsResponse
  - `credentials` CredentialMeta[], required
    - `token_id` string, required — Opaque credential id (e.g. nak_live_<32hex>).
    - `token_id_short` string, required
    - `name` string — Customer-supplied label; absent when not provided at issuance.
    - `scopes` CredentialScope[], required
    - `branch_id` string
    - `principal_type` string, required
    - `function_id` string
    - `created_at` string, date-time, required
    - `last_used_at` string, date-time
    - `revoked_at` string, date-time
    - `expires_at` string, date-time — When the credential expires; absent means never expires. The verifier refuses to authenticate after `expires_at <= now()`.

## Other responses

- `default` — General Error. The request may or may not be safe to retry, depending on the HTTP method, response status code, and whether a response was received. - If no response is returned from the API, a network error or timeout likely occurred. - In some cases, the request may have reached the server and been successfully processed, but the response failed to reach the client. As a result, retrying non-idempotent requests can lead to unintended results. The following HTTP methods are considered non-idempotent: `POST`, `PATCH`, `DELETE`, and `PUT`. Retrying these methods is generally **not safe**. The following methods are considered idempotent: `GET`, `HEAD`, and `OPTIONS`. Retrying these methods is **safe** in the event of a network error or timeout. Any request that returns a `503 Service Unavailable` response is always safe to retry. Any request that returns a `423 Locked` response is safe to retry. `423 Locked` indicates that the resource is temporarily locked, for example, due to another operation in progress.

---

[API](https://skmtc.net/neon/apis/neon-api.md) · [All operations](https://skmtc.net/neon/apis/neon-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/neon/neon-api/revisions/cfde79a5c713/schema)
