Rotate the email key of a site
rotate_site_email_key
Replaces the email key of a site with a new one, so the old key stops working at once and everywhere.
The preview gets the new key right away, but a published site keeps the old one until it is published again, so its emails fail until then, and the tool tells the client to remind you to publish right after. Anything outside Modulify that used the old key breaks until the new one is pasted in.
The new key is not returned, and get_site_email_key reads it. The tool tells the client to rotate only when a key has leaked or you ask, never as routine maintenance. Like get_site_email_key, it is refused while the site's own EMAIL_URL or EMAIL_PRIVATE_KEY secret keeps Modulify email off. It needs the Delete projects permission. See The email key.
Request
Call it with a POST to https://api.modulify.ai/v1/rotate_site_email_key, sending the inputs below as a JSON object. The token needs the config:write scope.
This method is marked destructive: it deletes or overwrites data. Check the inputs before you call it, and send an Idempotency-Key header whenever you might retry it.
curl -X POST https://api.modulify.ai/v1/rotate_site_email_key \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"projectId":"PROJECT_ID"}'Over MCP, the same method is the rotate_site_email_key tool.
Inputs
| Input | Type | Required | Description |
|---|---|---|---|
projectId |
string | Yes | The site id. |
Response
Every call answers with the JSON envelope of success, message, data, code and version. data holds the result described above, and on a method that returns a total, count carries it. The response headers carry the call's X-Request-Id and what is left of your per-minute budget in X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset. Errors explains every status code a call can answer with.