Reveal the private storage key
get_storage_key
Returns a site's private storage key in plain text, minting one if the site never had one.
A site that never had a key gets one minted and stored as the locked CDN_PRIVATE_KEY environment variable. This is the server-only credential the site uses to read and write its own storage at runtime, injected into the site as CDN_PRIVATE_KEY, and also what the published site presents to fetch its own build when it starts.
Anyone holding it can read, overwrite and delete every file in the bucket, private ones included, so a leaked key exposes the compiled site as well as the files. It is returned in full and lands wherever the response goes, an AI client's transcript included, which is why this tool sits behind the credentials:reveal scope, unticked by default.
The tool tells the client to reach for it only when you explicitly ask to see or move your key, never to print it, never to put it in a page, a client component or a committed file, and never to send it anywhere you did not ask for. See The CDN link and the storage key.
Inputs
| Input | Type | Required | Description |
|---|---|---|---|
projectId |
string | Yes | The site id. |