Modulify

Rotate the private storage key

rotate_storage_key

Replaces a site's private storage key with a freshly generated one and returns it in plain text.

POST /v1/rotate_storage_keyScopecredentials:revealDestructive

The old key stops working immediately and everywhere. Only the preview is pushed the new value, and only while its container is running: a published site keeps the key it was baked with at publish time, so its own storage calls start failing until it is published again.

Anything outside the site that used the old key, a script, a CI job or another service, also breaks until the new one is pasted in. The tool tells the client to tell you both of those things when it rotates. Rotate when a key has leaked, not as routine maintenance.

The new key comes back in plain text and lands wherever the response goes, an AI client's transcript included, so the tool tells the client never to print it, put it in a page, a client component or a committed file, or send it anywhere you did not ask for. Without the Delete projects permission in the workspace, the call is refused with a 403 and You are not allowed to rotate the storage key for this site! See Rotating the key.

Request

Call it with a POST to https://api.modulify.ai/v1/rotate_storage_key, sending the inputs below as a JSON object. The token needs the credentials:reveal scope.

This method is marked destructive: it deletes or overwrites data. Check the inputs before you call it, and send an Idempotency-Key header whenever you might retry it.

curl -X POST https://api.modulify.ai/v1/rotate_storage_key \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"projectId":"PROJECT_ID"}'

Over MCP, the same method is the rotate_storage_key tool.

Inputs

Input Type Required Description
projectId string Yes The site id.

Response

Every call answers with the JSON envelope of success, message, data, code and version. data holds the result described above, and on a method that returns a total, count carries it. The response headers carry the call's X-Request-Id and what is left of your per-minute budget in X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset. Errors explains every status code a call can answer with.