overlay: 1.0.0 info: title: API Evangelist enhancements for Amazon Secrets Manager API version: 1.0.0 extends: openapi/amazon-secrets-manager-openapi.yml actions: - target: $.info update: x-apievangelist-provider: amazon-secrets-manager x-apievangelist-artifacts: authentication: authentication/amazon-secrets-manager-authentication.yml conventions: conventions/amazon-secrets-manager-conventions.yml errors: errors/amazon-secrets-manager-problem-types.yml lifecycle: lifecycle/amazon-secrets-manager-lifecycle.yml data-model: data-model/amazon-secrets-manager-data-model.yml conformance: conformance/amazon-secrets-manager-conformance.yml x-apievangelist-auth: aws-sigv4 x-apievangelist-protocol: aws-json-1.1 - target: $.info update: x-agentic-access-profile: agentic-access/amazon-secrets-manager-agentic-access.yml - target: $.paths['/#GetSecretValue'].post update: x-apievangelist-consequence: >- Reads decrypted secret material — treat as a sensitive read; requires secretsmanager:GetSecretValue and kms:Decrypt. - target: $.paths['/'].post update: x-apievangelist-idempotency: ClientRequestToken