Reveal the private storage key
get_storage_key
Returns a site's private storage key in plain text, minting one if the site never had one.
A site that never had a key gets one minted and stored as the locked CDN_PRIVATE_KEY environment variable. This is the server-only credential the site uses to read and write its own storage at runtime, injected into the site as CDN_PRIVATE_KEY, and also what the published site presents to fetch its own build when it starts.
Anyone holding it can read, overwrite and delete every file in the bucket, private ones included, so a leaked key exposes the compiled site as well as the files. It is returned in full and lands wherever the response goes, an AI client's transcript included, which is why this tool sits behind the credentials:reveal scope, unticked by default.
The tool tells the client to reach for it only when you explicitly ask to see or move your key, never to print it, never to put it in a page, a client component or a committed file, and never to send it anywhere you did not ask for. See The CDN link and the storage key.
Request
Call it with a POST to https://api.modulify.ai/v1/get_storage_key, sending the inputs below as a JSON object. The token needs the credentials:reveal scope.
It makes changes, so send an Idempotency-Key header whenever you might retry it. A retry with the same key gets the first answer back instead of running again.
curl -X POST https://api.modulify.ai/v1/get_storage_key \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"projectId":"PROJECT_ID"}'Over MCP, the same method is the get_storage_key tool.
Inputs
| Input | Type | Required | Description |
|---|---|---|---|
projectId |
string | Yes | The site id. |
Response
Every call answers with the JSON envelope of success, message, data, code and version. data holds the result described above, and on a method that returns a total, count carries it. The response headers carry the call's X-Request-Id and what is left of your per-minute budget in X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset. Errors explains every status code a call can answer with.