Delete an environment variable
delete_secret
Deletes one environment variable from a site.
The value cannot be recovered afterwards, and removing a variable the site depends on breaks it on the next build. The tool tells the client to confirm with you first.
A platform-managed variable such as DATABASE_URL cannot be deleted, and the call is refused with This secret is locked and cannot be deleted! See Secrets.
Request
Call it with a POST to https://api.modulify.ai/v1/delete_secret, sending the inputs below as a JSON object. The token needs the config:write scope.
This method is marked destructive: it deletes or overwrites data. Check the inputs before you call it, and send an Idempotency-Key header whenever you might retry it.
curl -X POST https://api.modulify.ai/v1/delete_secret \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"projectId":"PROJECT_ID","secretId":"SECRET_ID"}'Over MCP, the same method is the delete_secret tool.
Inputs
| Input | Type | Required | Description |
|---|---|---|---|
projectId |
string | Yes | The site id. |
secretId |
string | Yes | The variable id from list_secrets. |
Response
Every call answers with the JSON envelope of success, message, data, code and version. data holds the result described above, and on a method that returns a total, count carries it. The response headers carry the call's X-Request-Id and what is left of your per-minute budget in X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset. Errors explains every status code a call can answer with.