Modulify

List environment variable names

list_secrets

Lists the environment variables configured for a site, the same set the Secrets tab shows.

POST /v1/list_secretsScopeconfig:readRead only

Only the names and flags come back, never the values. Each variable comes with its _id and Key, the IsSecret flag for a value stored encrypted, the IsLocked flag for a platform-managed variable, and when it was created and last updated. Reading a value back needs get_secret or get_all_secrets and the separate credentials:reveal scope.

It is how a client checks whether a site already has a key such as STRIPE_SECRET_KEY before asking you for one. The _id is the secretId that get_secret, delete_secret and rename_secret take. See Secrets.

Request

Call it with a POST to https://api.modulify.ai/v1/list_secrets, sending the inputs below as a JSON object. The token needs the config:read scope.

It only reads and changes nothing, so retrying it is safe.

curl -X POST https://api.modulify.ai/v1/list_secrets \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"projectId":"PROJECT_ID"}'

Over MCP, the same method is the list_secrets tool.

Inputs

Input Type Required Description
projectId string Yes The site id.

Response

Every call answers with the JSON envelope of success, message, data, code and version. data holds the result described above, and on a method that returns a total, count carries it. The response headers carry the call's X-Request-Id and what is left of your per-minute budget in X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset. Errors explains every status code a call can answer with.