# list_secrets

Source: https://modulify.ai/docs/api/secrets/list-secrets

Lists the environment variables configured for a site, the same set the Secrets tab shows.

- Title: List environment variable names
- Scope: `config:read`
- Access: Read only
- Endpoint: `POST /v1/list_secrets`

Only the names and flags come back, never the values. Each variable comes with its `_id` and `Key`, the `IsSecret` flag for a value stored encrypted, the `IsLocked` flag for a platform-managed variable, and when it was created and last updated. Reading a value back needs `get_secret` or `get_all_secrets` and the separate `credentials:reveal` scope.

It is how a client checks whether a site already has a key such as `STRIPE_SECRET_KEY` before asking you for one. The `_id` is the `secretId` that `get_secret`, `delete_secret` and `rename_secret` take. See [Secrets](https://modulify.ai/docs/data/secrets).

## Request

Call it with a `POST` to `https://api.modulify.ai/v1/list_secrets`, sending the inputs below as a JSON object. The token needs the `config:read` scope.

It only reads and changes nothing, so retrying it is safe.

```bash
curl -X POST https://api.modulify.ai/v1/list_secrets \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"projectId":"PROJECT_ID"}'
```

Over MCP, the same method is the [list_secrets tool](https://modulify.ai/docs/mcp/secrets/list-secrets).

## Inputs

| Input | Type | Required | Description |
| --- | --- | --- | --- |
| `projectId` | string | Yes | The site id. |

## Response

Every call answers with the [JSON envelope](https://modulify.ai/docs/api/requests-and-responses#the-response) of `success`, `message`, `data`, `code` and `version`. `data` holds the result described above, and on a method that returns a total, `count` carries it. The [response headers](https://modulify.ai/docs/api/requests-and-responses#headers-on-every-method-call) carry the call's `X-Request-Id` and what is left of your per-minute budget in `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset`. [Errors](https://modulify.ai/docs/api/errors) explains every status code a call can answer with.