neon-js

neon-js is a cursor rule for coding agents from neondatabase/ai-rules. It costs 0 tokens per session (3,148 once invoked), scanned A, a copy of neon-auth, MIT.

Guidelines for using Neon’s JavaScript SDK to handle user authentication and query database data through its API.

In plain words
What is it for?
Use them when adding authentication, database queries, or both to Next.js, React, or Node.js applications.
Why use it?
They help you choose the right Neon package and avoid adding database features when you only need sign-in or sign-up.

Cursor rule

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/neondatabase/ai-rules/neon-js
Clone the repo
git clone --depth 1 https://github.com/neondatabase/ai-rules

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for neon-js

README.md
[![agentmods](https://agentmods.dev/badge/rules/neondatabase/ai-rules/neon-js.svg)](https://agentmods.dev/rules/neondatabase/ai-rules/neon-js)
Your own site
<a href="https://agentmods.dev/rules/neondatabase/ai-rules/neon-js"><img src="https://agentmods.dev/badge/rules/neondatabase/ai-rules/neon-js.svg" alt="Measured on agentmods" height="20"></a>
Per session 0 Nothing until a file matches its globs; then the whole rule loads.
When invoked 3,148 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. Scan, not verified.
Origin 86% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.03148
Opus 5 $0.00000 $0.01574
Sonnet 5 $0.00000 $0.00630
Haiku 4.5 $0.00000 $0.00315

Measured 4d ago against content hash a8cf9f3757db, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

neon-js scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

> curl -s -o /tmp/neon-auth-setup.md https://raw.githubusercontent.com/neondatabase-labs/ai-rules/main/references/neon-auth-setup-nextjs.md
Origin

This is a copy

86% identical to neon-auth — 361 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

neon-js.mdc · 325 lines

How it starts

The opening of the file, as written. The whole thing — 325 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Neon JS SDK Guidelines

For AI Agents with file access (Claude Code, etc.): For complete documentation without summarization, fetch references using:

curl -s -o /tmp/neon-auth-setup.md https://raw.githubusercontent.com/neondatabase-labs/ai-rules/main/references/neon-auth-setup-nextjs.md

Then read the downloaded file. Replace nextjs with react-spa or nodejs as needed.

Overview

The @neondatabase/neon-js SDK provides a unified client for Neon Auth and Data API. It combines authentication handling with PostgREST-compatible database queries.

Package Selection

Use Case Package Notes
Auth + Data API @neondatabase/neon-js Full SDK, includes everything
Auth only @neondatabase/auth Smaller bundle, no database dependencies
Data API only @neondatabase/postgrest-js Bring your own auth

Do NOT install @neondatabase/neon-js if you only need authentication - use @neondatabase/auth instead for a smaller bundle.

Installation

npm install @neondatabase/neon-js

Quick Setup Patterns

Next.js (Most Common)

1. API Route Handler:

// app/api/auth/[...path]/route.ts
import { authApiHandler } from "@neondatabase/neon-js/auth/next";
export const { GET, POST } = authApiHandler();

2. Auth Client:

// lib/auth/client.ts
import { createAuthClient } from "@neondatabase/neon-js/auth/next";
export const authClient = createAuthClient();

3. Database Client:

// lib/db/client.ts
import { createClient } from "@neondatabase/neon-js";
import type { Database } from "./database.types";

export const dbClient = createClient<Database>({
  auth: { url: process.env.NEXT_PUBLIC_NEON_AUTH_URL! },
  dataApi: { url: process.env.NEON_DATA_API_URL! },
});

Complete setup: See Setup Reference - Next.js for auth, and Data API Reference for database

Read the full file on GitHub · 325 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 325 lines · 3,148 tokens per session scan A a8cf9f3757db

Subscribe to this mod's changes

neon-js is a cursor rule published in the GitHub repository neondatabase/ai-rules (86 stars, last pushed 3mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 3,148 tokens. A static security scan graded it A with 1 finding (makes network calls). It is 86% identical to neon-auth, differing in 361 lines, and is treated as a copy.