AWS Secrets Manager
Identity & securityAWS IAM keys
Store, read, rotate and manage secrets in AWS Secrets Manager.
13 actions
| Action | Effect | Data handled | Scope |
|---|---|---|---|
| secrets_manager_list_secretsLists secrets in the region with their names, descriptions, tags and rotation settings, never their values | read | General | |
| secrets_manager_describe_secretGets a secret's details without its value: ARN, KMS key, rotation, versions, tags and dates | read | General | |
| secrets_manager_get_secret_valueReads the value of a secret (AWSCURRENT unless a version or stage is given) | read | Health data | |
| secrets_manager_create_secretCreates a secret with a text value (often JSON), optionally encrypted with a given KMS key and tagged | write | Health data | |
| secrets_manager_put_secret_valueStores a new value for a secret as a new version, which becomes AWSCURRENT unless other stages are given | write | Health data | |
| secrets_manager_update_secretChanges a secret's description or KMS key, and optionally stores a new value | write | Health data | |
| secrets_manager_delete_secretSchedules a secret for deletion after a recovery window (default 30 days), or deletes it at once without recovery | destructive | General | |
| secrets_manager_restore_secretCancels the scheduled deletion of a secret | write | General | |
| secrets_manager_rotate_secretRotates a secret now with its rotation function, or sets up rotation with a Lambda function and schedule | write | General | |
| secrets_manager_list_secret_versionsLists the versions of a secret with their stage labels and dates, never their values | read | General | |
| secrets_manager_tag_secretAdds or overwrites tags on a secret | write | General | |
| secrets_manager_untag_secretRemoves tags from a secret by key | write | General | |
| secrets_manager_get_random_passwordGenerates a random password with the given length and character rules | read | Health data |