# get_storage_key

Source: https://modulify.ai/docs/mcp/storage/get-storage-key

Returns a site's private storage key in plain text, minting one if the site never had one.

- Title: Reveal the private storage key
- Scope: `credentials:reveal`
- Access: Makes changes

A site that never had a key gets one minted and stored as the locked `CDN_PRIVATE_KEY` environment variable. This is the server-only credential the site uses to read and write its own storage at runtime, injected into the site as `CDN_PRIVATE_KEY`, and also what the published site presents to fetch its own build when it starts.

Anyone holding it can read, overwrite and delete every file in the bucket, private ones included, so a leaked key exposes the compiled site as well as the files. It is returned in full and lands wherever the response goes, an AI client's transcript included, which is why this tool sits behind the `credentials:reveal` scope, unticked by default.

The tool tells the client to reach for it only when you explicitly ask to see or move your key, never to print it, never to put it in a page, a client component or a committed file, and never to send it anywhere you did not ask for. See [The CDN link and the storage key](https://modulify.ai/docs/data/storage#the-cdn-link-and-the-storage-key).

## Inputs

| Input | Type | Required | Description |
| --- | --- | --- | --- |
| `projectId` | string | Yes | The site id. |