# get_secret

Source: https://modulify.ai/docs/api/secrets/get-secret

Returns the value of one environment variable in plain text, decrypting it when it is stored encrypted.

- Title: Reveal one environment variable
- Scope: `credentials:reveal`
- Access: Read only
- Endpoint: `POST /v1/get_secret`

This is the real credential the site runs with, so it lands wherever the response goes, an AI client's transcript included, the moment the tool is called. The tool tells the client never to print it, put it in a page or a committed file, or send it anywhere you did not ask for.

It also reveals a platform-managed variable such as `DATABASE_URL`, `DATABASE_TOKEN` or the CDN private key, the keys to the site's database and file storage, matching the eye icon on a managed row in the product. The tool tells the client to be certain you asked for that specific value, and to call it only when you explicitly ask to see or move a value, never to check what something is set to. See [Secrets](https://modulify.ai/docs/data/secrets#read-a-value-back).

## Request

Call it with a `POST` to `https://api.modulify.ai/v1/get_secret`, sending the inputs below as a JSON object. The token needs the `credentials:reveal` scope.

It only reads and changes nothing, so retrying it is safe.

```bash
curl -X POST https://api.modulify.ai/v1/get_secret \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"projectId":"PROJECT_ID","secretId":"SECRET_ID"}'
```

Over MCP, the same method is the [get_secret tool](https://modulify.ai/docs/mcp/secrets/get-secret).

## Inputs

| Input | Type | Required | Description |
| --- | --- | --- | --- |
| `projectId` | string | Yes | The site id. |
| `secretId` | string | Yes | The variable id from `list_secrets`. |

## Response

Every call answers with the [JSON envelope](https://modulify.ai/docs/api/requests-and-responses#the-response) of `success`, `message`, `data`, `code` and `version`. `data` holds the result described above, and on a method that returns a total, `count` carries it. The [response headers](https://modulify.ai/docs/api/requests-and-responses#headers-on-every-method-call) carry the call's `X-Request-Id` and what is left of your per-minute budget in `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset`. [Errors](https://modulify.ai/docs/api/errors) explains every status code a call can answer with.