generated: '2026-06-20' method: derived source: >- openapi/amazon-secrets-manager-openapi.yml plus the AWS Secrets Manager API reference. Cross-cutting standard conformance derived from the spec (protocol, auth, pagination, idempotency) and the documented AWS request/response model. standards: - id: aws-sigv4 conforms: true evidence: >- Requests are authenticated with AWS Signature Version 4; the service signing name is secretsmanager (see authentication/). - id: oauth2 conforms: false evidence: No oauth2 securityScheme; AWS uses SigV4 + IAM, not OAuth. - id: oidc conforms: false - id: rfc9457-problem-details conforms: false evidence: >- Errors use the AWS JSON 1.1 error envelope (__type + message over application/x-amz-json-1.1), not application/problem+json. - id: json-api conforms: false - id: pagination conforms: true evidence: >- ListSecrets uses NextToken (opaque cursor) + MaxResults; response returns NextToken for the next page. - id: idempotency conforms: true evidence: >- Write operations (CreateSecret, PutSecretValue, UpdateSecret, RotateSecret) accept a ClientRequestToken to make retries idempotent. - id: fhir conforms: false - id: fapi conforms: false - id: scim conforms: false - id: odata conforms: false - id: psd2 conforms: false