Rotate the private storage key
rotate_storage_key
Replaces a site's private storage key with a freshly generated one and returns it in plain text.
The old key stops working immediately and everywhere. Only the preview is pushed the new value, and only while its container is running: a published site keeps the key it was baked with at publish time, so its own storage calls start failing until it is published again.
Anything outside the site that used the old key, a script, a CI job or another service, also breaks until the new one is pasted in. The tool tells the client to tell you both of those things when it rotates. Rotate when a key has leaked, not as routine maintenance.
The new key comes back in plain text and lands wherever the response goes, an AI client's transcript included, so the tool tells the client never to print it, put it in a page, a client component or a committed file, or send it anywhere you did not ask for. Without the Delete projects permission in the workspace, the call is refused with a 403 and You are not allowed to rotate the storage key for this site! See Rotating the key.
Inputs
| Input | Type | Required | Description |
|---|---|---|---|
projectId |
string | Yes | The site id. |