# get_secret

Source: https://modulify.ai/docs/mcp/secrets/get-secret

Returns the value of one environment variable in plain text, decrypting it when it is stored encrypted.

- Title: Reveal one environment variable
- Scope: `credentials:reveal`
- Access: Read only

This is the real credential the site runs with, so it lands wherever the response goes, an AI client's transcript included, the moment the tool is called. The tool tells the client never to print it, put it in a page or a committed file, or send it anywhere you did not ask for.

It also reveals a platform-managed variable such as `DATABASE_URL`, `DATABASE_TOKEN` or the CDN private key, the keys to the site's database and file storage, matching the eye icon on a managed row in the product. The tool tells the client to be certain you asked for that specific value, and to call it only when you explicitly ask to see or move a value, never to check what something is set to. See [Secrets](https://modulify.ai/docs/data/secrets#read-a-value-back).

## Inputs

| Input | Type | Required | Description |
| --- | --- | --- | --- |
| `projectId` | string | Yes | The site id. |
| `secretId` | string | Yes | The variable id from `list_secrets`. |