# rename_secret

Source: https://modulify.ai/docs/api/secrets/rename-secret

Renames one environment variable on a site and keeps its value, without reading the value.

- Title: Rename an environment variable
- Scope: `config:write`
- Access: Makes changes
- Endpoint: `POST /v1/rename_secret`

The new name follows the same rules as `set_secret` and must not already belong to another variable or be a reserved name. Locked variables cannot be renamed, and an encrypted variable cannot take a `NEXT_PUBLIC_` name here, because that name puts its value in the browser code. Rename that one in the Secrets tab instead, where its value is shown.

The site's code keeps reading the old name until it is changed too, so every place that reads it needs updating. The running preview gets the new name straight away, and the published site gets it on the next publish. See [Secrets](https://modulify.ai/docs/data/secrets#edit-and-rename).

## Request

Call it with a `POST` to `https://api.modulify.ai/v1/rename_secret`, sending the inputs below as a JSON object. The token needs the `config:write` scope.

It makes changes, so send an [Idempotency-Key](https://modulify.ai/docs/api/idempotency) header whenever you might retry it. A retry with the same key gets the first answer back instead of running again.

```bash
curl -X POST https://api.modulify.ai/v1/rename_secret \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"projectId":"PROJECT_ID","secretId":"SECRET_ID","key":"KEY"}'
```

Over MCP, the same method is the [rename_secret tool](https://modulify.ai/docs/mcp/secrets/rename-secret).

## Inputs

| Input | Type | Required | Description |
| --- | --- | --- | --- |
| `projectId` | string | Yes | The site id. |
| `secretId` | string | Yes | The variable id from `list_secrets`. |
| `key` | string | Yes | The new name. Use letters, digits and underscores only, starting with a letter or an underscore. |

## Response

Every call answers with the [JSON envelope](https://modulify.ai/docs/api/requests-and-responses#the-response) of `success`, `message`, `data`, `code` and `version`. `data` holds the result described above, and on a method that returns a total, `count` carries it. The [response headers](https://modulify.ai/docs/api/requests-and-responses#headers-on-every-method-call) carry the call's `X-Request-Id` and what is left of your per-minute budget in `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset`. [Errors](https://modulify.ai/docs/api/errors) explains every status code a call can answer with.