# get_site_email_key

Source: https://modulify.ai/docs/api/emails/get-site-email-key

Reveals the email key of a site in plain text, with the API URL it goes with, creating the key when the site has none yet.

- Title: Reveal the email key of a site
- Scope: `credentials:reveal`
- Access: Makes changes
- Endpoint: `POST /v1/get_site_email_key`

It is the server only credential the site's own server code sends with every email, injected as `EMAIL_PRIVATE_KEY` next to `EMAIL_URL`, and anyone holding it can send email as the site. The answer carries the `key`, the `url` it goes with and `keyChangedAt`.

The key is returned in full, so it lands in the conversation. The tool tells the client never to print it, never to put it in a page, a client component or a committed file, and never to send it anywhere you did not ask for. It also tells the client to reach for it only when you explicitly ask to see or copy your key, for example to send from a server of your own outside Modulify.

It is refused while the site's own `EMAIL_URL` or `EMAIL_PRIVATE_KEY` secret keeps Modulify email off. It is the only tool that returns the key, and `credentials:reveal` is unticked by default when you create a token. See [The email key](https://modulify.ai/docs/automations/emails#the-email-key).

## Request

Call it with a `POST` to `https://api.modulify.ai/v1/get_site_email_key`, sending the inputs below as a JSON object. The token needs the `credentials:reveal` scope.

It makes changes, so send an [Idempotency-Key](https://modulify.ai/docs/api/idempotency) header whenever you might retry it. A retry with the same key gets the first answer back instead of running again.

```bash
curl -X POST https://api.modulify.ai/v1/get_site_email_key \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"projectId":"PROJECT_ID"}'
```

Over MCP, the same method is the [get_site_email_key tool](https://modulify.ai/docs/mcp/emails/get-site-email-key).

## Inputs

| Input | Type | Required | Description |
| --- | --- | --- | --- |
| `projectId` | string | Yes | The site id. |

## Response

Every call answers with the [JSON envelope](https://modulify.ai/docs/api/requests-and-responses#the-response) of `success`, `message`, `data`, `code` and `version`. `data` holds the result described above, and on a method that returns a total, `count` carries it. The [response headers](https://modulify.ai/docs/api/requests-and-responses#headers-on-every-method-call) carry the call's `X-Request-Id` and what is left of your per-minute budget in `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset`. [Errors](https://modulify.ai/docs/api/errors) explains every status code a call can answer with.