Reveal every environment variable
get_all_secrets
Returns every environment variable a person set on a site in plain text at once, keyed by variable id.
The ids pair with list_secrets for the names. This is the whole credential set of the site in one response, so the tool tells the client never to print it, write it to a file or send it anywhere.
Platform-managed variables are left out, exactly as Copy secrets and Download secrets in the Secrets tab leave them out, so DATABASE_URL, DATABASE_TOKEN and the CDN keys do not appear here, and get_secret reads them one at a time. Everything else does appear, including credentials Modulify stored for you during an import, such as SHOPIFY_STOREFRONT_TOKEN, and the tool points the client at get_secret by id when you genuinely need one of those.
A variable whose stored value can no longer be decrypted is listed in failed rather than returned, and needs re-entering. See Secrets.
Request
Call it with a POST to https://api.modulify.ai/v1/get_all_secrets, sending the inputs below as a JSON object. The token needs the credentials:reveal scope.
It only reads and changes nothing, so retrying it is safe.
curl -X POST https://api.modulify.ai/v1/get_all_secrets \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"projectId":"PROJECT_ID"}'Over MCP, the same method is the get_all_secrets tool.
Inputs
| Input | Type | Required | Description |
|---|---|---|---|
projectId |
string | Yes | The site id. |
Response
Every call answers with the JSON envelope of success, message, data, code and version. data holds the result described above, and on a method that returns a total, count carries it. The response headers carry the call's X-Request-Id and what is left of your per-minute budget in X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset. Errors explains every status code a call can answer with.