Skip to content

Secrets Manager

Client

AsyncSecretsManagerClient

AsyncSecretsManagerClient(config: AsyncSecretsManagerConfig | None = None, plugins: list[Plugin] | None = None)

Amazon Web Services Secrets Manager provides a service to enable you to store, manage, and retrieve, secrets.

This guide provides descriptions of the Secrets Manager API. For more information about using this service, see the Amazon Web Services Secrets Manager User Guide.

API Version

This version of the Secrets Manager API Reference documents the Secrets Manager API version 2017-10-17.

For a list of endpoints, see Amazon Web Services Secrets Manager endpoints.

Support and Feedback for Amazon Web Services Secrets Manager

We welcome your feedback. Send your comments to awssecretsmanager-feedback@amazon.com, or post your feedback and questions in the Amazon Web Services Secrets Manager Discussion Forum. For more information about the Amazon Web Services Discussion Forums, see Forums Help.

Logging API Requests

Amazon Web Services Secrets Manager supports Amazon Web Services CloudTrail, a service that records Amazon Web Services API calls for your Amazon Web Services account and delivers log files to an Amazon S3 bucket. By using information that's collected by Amazon Web Services CloudTrail, you can determine the requests successfully made to Secrets Manager, who made the request, when it was made, and so on. For more about Amazon Web Services Secrets Manager and support for Amazon Web Services CloudTrail, see Logging Amazon Web Services Secrets Manager Events with Amazon Web Services CloudTrail in the Amazon Web Services Secrets Manager User Guide. To learn more about CloudTrail, including enabling it and find your log files, see the Amazon Web Services CloudTrail User Guide.

Parameters:

Name Type Description Default
config AsyncSecretsManagerConfig | None

Optional configuration for the client. Here you can set things like the endpoint for HTTP services or auth credentials.

None
plugins list[Plugin] | None

A list of callables applied once to the client's base configuration. Their changes are inherited by every operation invocation.

None

Operations

Configuration

AsyncSecretsManagerConfig dataclass

AsyncSecretsManagerConfig()

Bases: AsyncAwsConfig

Secrets Manager configuration (async-resolved).

Attributes

auth_scheme_resolver class-attribute instance-attribute
auth_scheme_resolver: HTTPAuthSchemeResolver | None = None

An auth scheme resolver that determines the auth scheme for each operation.

auth_schemes class-attribute instance-attribute
auth_schemes: dict[ShapeID, AuthScheme[Any, Any, Any, Any]] | None = None

A map of auth scheme ids to auth schemes.

aws_access_key_id class-attribute instance-attribute
aws_access_key_id: str | None = None

The identifier for a secret access key.

aws_credentials_identity_resolver class-attribute instance-attribute
aws_credentials_identity_resolver: IdentityResolver[AWSCredentialsIdentity, AWSIdentityProperties] | None = None

Resolves AWS Credentials. Required for operations that use Sigv4 Auth.

aws_secret_access_key class-attribute instance-attribute
aws_secret_access_key: str | None = None

A secret access key that can be used to sign requests.

aws_session_token class-attribute instance-attribute
aws_session_token: str | None = None

The session token used with temporary AWS credentials.

endpoint_resolver class-attribute instance-attribute
endpoint_resolver: EndpointResolver | None = None

The endpoint resolver used to resolve the final endpoint per-operation based on the configuration.

interceptors class-attribute instance-attribute
interceptors: list[_ServiceInterceptor] = field(default_factory=lambda: [])

The list of interceptors, which are hooks that are called during the execution of a request.

protocol class-attribute instance-attribute
protocol: ClientProtocol[Any, Any] | None = None

The protocol to serialize and deserialize requests with.

region class-attribute instance-attribute
region: str | None = None

The AWS region to connect to. The configured region is used to determine the service endpoint.

sdk_ua_app_id class-attribute instance-attribute
sdk_ua_app_id: str | None = None

A unique and opaque application ID that is appended to the User-Agent header.

user_agent_extra class-attribute instance-attribute
user_agent_extra: str | None = None

Additional suffix to be added to the User-Agent header.

Methods:

resolve async classmethod
resolve(*, profile: str | None = None, fs: FileSystem | None = None, config_file_path: str | None = None, credentials_file_path: str | None = None, **overrides: Unpack[_AsyncSecretsManagerConfigOverrides]) -> Self

Resolve config from environment, config files, defaults, and explicit overrides.

set_auth_scheme
set_auth_scheme(scheme: AuthScheme[Any, Any, Any, Any]) -> None

Set an auth scheme implementation using its scheme ID. :param scheme: The auth scheme to add or replace.

Plugin module-attribute

A callable that customizes a client configuration. Service-level plugins are applied once to the base configuration inherited by every operation. Operation-level plugins apply only to a single operation invocation.

Structures

Errors

Enums