vocabulary: "1.0.0" info: provider: "Amazon Secrets Manager" description: "Unified taxonomy mapping operational and capability dimensions of the Amazon Secrets Manager API for secure secrets lifecycle management." created: "2026-04-19" modified: "2026-04-19" operational: apis: - namespace: amazon-secrets-manager version: "2017-10-17" baseUrl: https://secretsmanager.{region}.amazonaws.com status: active resources: - name: Secrets api: amazon-secrets-manager actions: [Create, Get, Put, Update, Delete, List, Describe, Rotate, Restore, Tag, Untag] - name: SecretVersions api: amazon-secrets-manager actions: [List, Get, Put] - name: RotationConfiguration api: amazon-secrets-manager actions: [Configure, Cancel] - name: RandomPasswords api: amazon-secrets-manager actions: [Generate] actions: - name: Create httpMethods: [POST] pattern: write - name: Get httpMethods: [POST] pattern: read - name: Put httpMethods: [POST] pattern: write - name: Update httpMethods: [POST] pattern: write - name: Delete httpMethods: [POST] pattern: destructive - name: List httpMethods: [POST] pattern: read - name: Describe httpMethods: [POST] pattern: read - name: Rotate httpMethods: [POST] pattern: write - name: Restore httpMethods: [POST] pattern: write - name: Generate httpMethods: [POST] pattern: read schemas: core: - name: Secret description: A secret managed by Amazon Secrets Manager with metadata and version tracking - name: SecretValue description: The plaintext or binary value stored in a secret version - name: RotationRules description: Configuration rules governing automatic secret rotation schedule data: - name: Tag description: Key-value metadata tag applied to a secret resource parameters: pagination: - name: NextToken description: Token for paginating through lists of secrets - name: MaxResults description: Maximum number of secrets to return per page identifiers: - name: SecretId description: Name or ARN identifying a secret - name: VersionId description: Unique identifier for a specific version of a secret - name: VersionStage description: Staging label attached to a version (e.g., AWSCURRENT, AWSPREVIOUS) filters: - name: Filters description: Key-value filter criteria for listing secrets enums: rotationStatus: - Enabled - Disabled versionStages: - AWSCURRENT - AWSPREVIOUS - AWSPENDING authentication: schemes: - type: AWS Signature V4 description: AWS IAM-based request signing apis: [all] capability: workflows: - name: Secrets Management file: capabilities/secrets-management.yaml description: End-to-end secrets lifecycle management including creation, retrieval, rotation, and deletion apisConsumed: [amazon-secrets-manager] toolCount: 9 personas: [DevOps Engineer, Application Developer] domains: [Security, Secrets Management] personas: - id: devops-engineer name: DevOps Engineer description: Engineers who manage application infrastructure and configure secrets rotation and access policies workflows: [Secrets Management] - id: application-developer name: Application Developer description: Developers who integrate applications with Secrets Manager to retrieve credentials at runtime workflows: [Secrets Management] domains: - name: Security description: Secure storage and access control for sensitive credentials and configuration resources: [Secrets, SecretVersions] - name: Secrets Management description: Lifecycle management of secrets including rotation, versioning, and audit resources: [Secrets, RotationConfiguration] namespaces: consumed: - amazon-secrets-manager rest: - secrets-management-api (port 8080) mcp: - secrets-management-mcp (port 9090) binds: - name: AWS_ACCESS_KEY_ID workflows: [Secrets Management] - name: AWS_SECRET_ACCESS_KEY workflows: [Secrets Management] - name: AWS_REGION workflows: [Secrets Management] crossReference: - resource: Secrets operations: [CreateSecret, GetSecretValue, PutSecretValue, UpdateSecret, DeleteSecret, ListSecrets, DescribeSecret, RotateSecret, RestoreSecret] workflows: [Secrets Management] personas: [DevOps Engineer, Application Developer] - resource: RandomPasswords operations: [GetRandomPassword] workflows: [Secrets Management] personas: [DevOps Engineer]