neon.roles.reset_password ​
Reset a Neon role's password and return the new password
Resets a role's password on a Neon branch and returns the new plaintext password.
Issues POST /projects/{neon_project_id}/branches/{neon_branch_id}/roles/{role_name}/reset_password. Neon generates a fresh password and returns it in the response role object. This atomic surfaces that plaintext password in its terminal state_data so that a calling orchestration (C-05, neon.role.reset_password) can build a connection string from it.
SECURITY: the returned password is plaintext and MUST NOT be persisted as-is. It is returned ONLY because the orchestrating workflow needs it to construct a connection string; that orchestration is responsible for encrypting it before any DB write. This atomic performs no DB writes. Workflow state_data is ephemeral and encrypted at rest by the engine.
Inputs:
- neon_project_id: Neon project id (required)
- neon_branch_id: Neon branch id the role lives on (required)
- role_name: name of the role whose password is reset (required)
Outputs (terminal state_data):
- neon_project_id: str — pass-through project id
- neon_branch_id: str — pass-through branch id
- role_name: str — confirmed role name
- password: str — the new plaintext password (do NOT persist as plaintext)
Plugin required: context.get_plugin("neon") must expose .api_token.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | Base |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
connection_uuid | uuid | No | — | Cloud connection holding the Neon credential |
neon_project_id | string | Yes | — | Neon project id |
neon_branch_id | string | Yes | — | Neon branch id the role lives on |
role_name | string | Yes | — | Name of the role whose password is reset |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
connection_uuid | uuid | No | — | — |
neon_project_id | string | No | — | — |
neon_branch_id | string | No | — | — |
role_name | string | No | — | — |
password | string | No | — | New plaintext password — do NOT persist as plaintext |
failure_reason | string | No | — | — |
failure_type | string | No | — | — |
failed_action | string | No | — | — |
failed_at_state | string | No | — | — |
failed_step | string | No | — | — |
failed_layer | string | No | — | — |
error | string | No | — | — |
error_type | string | No | — | — |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | execute | Reset-password request accepted |
completed | No | Yes | Yes | — | Neon role password reset |
failed | No | Yes | No | — | Neon role password reset failed |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | execute | completed | Reset Neon role password |
* (any state) | fail | failed | Mark workflow failed |
API Usage ​
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "neon.roles.reset_password",
"initial_data": {
"neon_project_id": "value",
"neon_branch_id": "value",
"role_name": "value"
}
}