Modulify

Reveal every environment variable

get_all_secrets

Returns every environment variable a person set on a site in plain text at once, keyed by variable id.

POST /v1/get_all_secretsScopecredentials:revealRead only

The ids pair with list_secrets for the names. This is the whole credential set of the site in one response, so the tool tells the client never to print it, write it to a file or send it anywhere.

Platform-managed variables are left out, exactly as Copy secrets and Download secrets in the Secrets tab leave them out, so DATABASE_URL, DATABASE_TOKEN and the CDN keys do not appear here, and get_secret reads them one at a time. Everything else does appear, including credentials Modulify stored for you during an import, such as SHOPIFY_STOREFRONT_TOKEN, and the tool points the client at get_secret by id when you genuinely need one of those.

A variable whose stored value can no longer be decrypted is listed in failed rather than returned, and needs re-entering. See Secrets.

Request

Call it with a POST to https://api.modulify.ai/v1/get_all_secrets, sending the inputs below as a JSON object. The token needs the credentials:reveal scope.

It only reads and changes nothing, so retrying it is safe.

curl -X POST https://api.modulify.ai/v1/get_all_secrets \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"projectId":"PROJECT_ID"}'

Over MCP, the same method is the get_all_secrets tool.

Inputs

Input Type Required Description
projectId string Yes The site id.

Response

Every call answers with the JSON envelope of success, message, data, code and version. data holds the result described above, and on a method that returns a total, count carries it. The response headers carry the call's X-Request-Id and what is left of your per-minute budget in X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset. Errors explains every status code a call can answer with.