Reveal one environment variable
get_secret
Returns the value of one environment variable in plain text, decrypting it when it is stored encrypted.
This is the real credential the site runs with, so it lands wherever the response goes, an AI client's transcript included, the moment the tool is called. The tool tells the client never to print it, put it in a page or a committed file, or send it anywhere you did not ask for.
It also reveals a platform-managed variable such as DATABASE_URL, DATABASE_TOKEN or the CDN private key, the keys to the site's database and file storage, matching the eye icon on a managed row in the product. The tool tells the client to be certain you asked for that specific value, and to call it only when you explicitly ask to see or move a value, never to check what something is set to. See Secrets.
Request
Call it with a POST to https://api.modulify.ai/v1/get_secret, sending the inputs below as a JSON object. The token needs the credentials:reveal scope.
It only reads and changes nothing, so retrying it is safe.
curl -X POST https://api.modulify.ai/v1/get_secret \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"projectId":"PROJECT_ID","secretId":"SECRET_ID"}'Over MCP, the same method is the get_secret tool.
Inputs
| Input | Type | Required | Description |
|---|---|---|---|
projectId |
string | Yes | The site id. |
secretId |
string | Yes | The variable id from list_secrets. |
Response
Every call answers with the JSON envelope of success, message, data, code and version. data holds the result described above, and on a method that returns a total, count carries it. The response headers carry the call's X-Request-Id and what is left of your per-minute budget in X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset. Errors explains every status code a call can answer with.