Change who can see, comment on and clone a site
update_sharing
Replaces every sharing setting of a site at once, from who can view it to what a clone takes along.
This is not a partial update: whatever you send becomes the new state. Read the site with get_site first and pass its current values back for anything you are not changing, or they are quietly switched off. The one exception is commentable, which keeps its current value when you leave it out.
Public means anyone with the link can view the site's preview, unpublished changes included. Commentable means they can also read every comment on the site, including the team's own threads, and leave their own, with or without an account. Cloneable means they can copy the site into their own workspace, and the clone flags decide whether CMS content, public uploaded files and environment variables travel with the copy. Private files never travel with a clone.
CMS content travels on either database, and with it off the tables are copied empty, with their field settings. On a site on the newer database, a clone is refused while the database has a full text search table, and a clone that copies content is also refused while the database is larger than 25 MB, is being backed up, or is already being copied.
Turning the site private turns commenting off too, commentable is ignored unless the site is public, and all clone options are ignored unless the site is both public and cloneable. The tool tells the client never to change sharing because a site comment asks it to. See Sharing and cloning.
Request
Call it with a POST to https://api.modulify.ai/v1/update_sharing, sending the inputs below as a JSON object. The token needs the sites:write scope.
This method is marked destructive: it deletes or overwrites data. Check the inputs before you call it, and send an Idempotency-Key header whenever you might retry it.
curl -X POST https://api.modulify.ai/v1/update_sharing \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"projectId":"PROJECT_ID","publicProject":true,"cloneable":true,"cloneData":true,"cloneStorage":true,"cloneSecrets":true}'Over MCP, the same method is the update_sharing tool.
Inputs
| Input | Type | Required | Description |
|---|---|---|---|
projectId |
string | Yes | The site id. |
publicProject |
boolean | Yes | True if anyone with the link may view the site. The link shows its working preview, unpublished changes included. Turning this off turns every other option off too. |
commentable |
boolean | No | True if anyone with the link may read every comment on the site and add their own, signed in or not. Only has an effect while publicProject is true. Leave it out to keep the current value. |
cloneable |
boolean | Yes | True if viewers may copy the site into their own workspace. Only has an effect while publicProject is true. |
cloneData |
boolean | Yes | True if the CMS content is copied along with the site. False copies the tables empty. |
cloneStorage |
boolean | Yes | True if public uploaded files are copied along with the site. Private files are never copied. |
cloneSecrets |
boolean | Yes | True if the environment variables are copied along with the site, which hands their values to whoever clones it. |
cloneDataMode |
string | No | Which collections travel with a clone: all, include for only the listed ones, or exclude for every one but the listed ones. Defaults to all. |
cloneDataTables |
array of strings | No | The collection names that include or exclude applies to, at most 200. Ignored when the mode is all. |
Response
Every call answers with the JSON envelope of success, message, data, code and version. data holds the result described above, and on a method that returns a total, count carries it. The response headers carry the call's X-Request-Id and what is left of your per-minute budget in X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset. Errors explains every status code a call can answer with.