Rotate the analytics API key
rotate_analytics_key
Replaces the analytics API key of a site with a freshly generated one and returns the new key in plain text.
The old key stops working immediately and everywhere. Only the preview is pushed the new value, and only while its container is running: a published site keeps the key it was built with, so its own analytics calls fail until it is published again. Anything outside the site that used the old key breaks until the new one is pasted in, and the tool tells the client to tell you both of those things when it rotates.
It needs the Delete projects permission in the workspace. The new key comes back as analyticsKey, so the warnings on get_analytics_key apply here too. While the key is already being changed, the call answers The analytics API key is being changed right now. Try again in a moment!
Rotate when a key has leaked, not as routine maintenance. It makes no analytics lookup. See API access.
Request
Call it with a POST to https://api.modulify.ai/v1/rotate_analytics_key, sending the inputs below as a JSON object. The token needs the credentials:reveal scope.
This method is marked destructive: it deletes or overwrites data. Check the inputs before you call it, and send an Idempotency-Key header whenever you might retry it.
curl -X POST https://api.modulify.ai/v1/rotate_analytics_key \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"projectId":"PROJECT_ID"}'Over MCP, the same method is the rotate_analytics_key tool.
Inputs
| Input | Type | Required | Description |
|---|---|---|---|
projectId |
string | Yes | The site id. |
Response
Every call answers with the JSON envelope of success, message, data, code and version. data holds the result described above, and on a method that returns a total, count carries it. The response headers carry the call's X-Request-Id and what is left of your per-minute budget in X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset. Errors explains every status code a call can answer with.