# rotate_site_email_key

Source: https://modulify.ai/docs/api/emails/rotate-site-email-key

Replaces the email key of a site with a new one, so the old key stops working at once and everywhere.

- Title: Rotate the email key of a site
- Scope: `config:write`
- Access: Destructive
- Endpoint: `POST /v1/rotate_site_email_key`

The preview gets the new key right away, but a published site keeps the old one until it is published again, so its emails fail until then, and the tool tells the client to remind you to publish right after. Anything outside Modulify that used the old key breaks until the new one is pasted in.

The new key is not returned, and `get_site_email_key` reads it. The tool tells the client to rotate only when a key has leaked or you ask, never as routine maintenance. Like `get_site_email_key`, it is refused while the site's own `EMAIL_URL` or `EMAIL_PRIVATE_KEY` secret keeps Modulify email off. It needs the **Delete projects** permission. See [The email key](https://modulify.ai/docs/automations/emails#the-email-key).

## Request

Call it with a `POST` to `https://api.modulify.ai/v1/rotate_site_email_key`, sending the inputs below as a JSON object. The token needs the `config:write` scope.

> **Warning**
>
> This method is marked destructive: it deletes or overwrites data. Check the inputs before you call it, and send an [Idempotency-Key](https://modulify.ai/docs/api/idempotency) header whenever you might retry it.

```bash
curl -X POST https://api.modulify.ai/v1/rotate_site_email_key \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"projectId":"PROJECT_ID"}'
```

Over MCP, the same method is the [rotate_site_email_key tool](https://modulify.ai/docs/mcp/emails/rotate-site-email-key).

## Inputs

| Input | Type | Required | Description |
| --- | --- | --- | --- |
| `projectId` | string | Yes | The site id. |

## Response

Every call answers with the [JSON envelope](https://modulify.ai/docs/api/requests-and-responses#the-response) of `success`, `message`, `data`, `code` and `version`. `data` holds the result described above, and on a method that returns a total, `count` carries it. The [response headers](https://modulify.ai/docs/api/requests-and-responses#headers-on-every-method-call) carry the call's `X-Request-Id` and what is left of your per-minute budget in `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset`. [Errors](https://modulify.ai/docs/api/errors) explains every status code a call can answer with.