- Support
- Integrations
- Secrets Manager
Secrets Manager
AWS integration · 22 node(s).
00Overview
Store, retrieve and rotate application secrets in AWS Secrets Manager straight from a flow — read a secret value to feed a downstream step, create or update secrets and their versions, and generate a strong random password on demand. You can also schedule or restore deletions, configure rotation, replicate secrets across regions, and manage tags and resource-based access policies without leaving the editor.
Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.
01Connecting Secrets Manager
- Decide how the node authenticates using the Authentication dropdown, which offers three methods: Access Keys (your own IAM user keys), Assume Role (cross-account) (Flomation assumes a role in your account), and Managed Role (Credential) (a reusable AWS credential saved in Flomation).
- For Access Keys, open the AWS IAM console (console.aws.amazon.com/iam) → Users → your user → Security credentials → Create access key, then copy the values into the AWS Access Key and AWS Secret Key fields — add the Session Token too if you are using temporary STS credentials.
- For Assume Role (cross-account), create an IAM role in your account that trusts Flomation's AWS principal and grants the Secrets Manager permissions you need, then paste its ARN into Role ARN to Assume; if the role's trust policy sets an external ID, enter the same value in Assume Role External ID.
- For Managed Role (Credential), simply pick a pre-configured AWS credential in the AWS Role Credential field — ask your Flomation administrator to set one up if the list is empty.
- Set Region to the AWS region your secret lives in (for example
eu-west-2) — this is required for every authentication method. - Store your AWS keys as Flomation environment secrets (e.g.
secretsmanager_secret) rather than typing them inline, then select them in the node's matching AWS Secret Key and AWS Access Key fields.
| Field | Type | Details | |
|---|---|---|---|
| Authentication | string | Required | Access Keys, Assume Role (cross-account), Managed Role (Credential) |
| AWS Access Key | secret | Required | |
| AWS Secret Key | secret | Required | |
| Session Token (optional) | secret | ||
| AWS Role Credential | credential | Required |
Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.
02Batch
AWS Secrets Manager Batch Get Secret Value
aws/secretsmanager/batch_get_secret_value · Action
Retrieve the values of multiple secrets at once. Returns sensitive data.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Secret IDs (comma-separated or JSON array) | string | Required | prod/db, prod/api |
Returns: tool_result, secret_values, errors, count
03Cancel
AWS Secrets Manager Cancel Rotate Secret
aws/secretsmanager/cancel_rotate_secret · Action
Turn off automatic rotation and cancel an in-progress rotation.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Secret ID or ARN | string | Required | prod/db/password |
Returns: tool_result, arn
04Create
AWS Secrets Manager Create Secret
aws/secretsmanager/create_secret · Action
Create a new secret with an optional value, description and tags.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Secret Name | string | Required | prod/db/password |
| Secret Value | secret | ||
| Description | string | Optional | |
| KMS Key ID (optional) | string | ||
| Tags | key_value_array |
Returns: tool_result, arn, name, version_id
05Delete
AWS Secrets Manager Delete Resource Policy
aws/secretsmanager/delete_resource_policy · Action
Remove the resource-based policy attached to a secret.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Secret ID or ARN | string | Required | my-secret |
Returns: tool_result, arn
AWS Secrets Manager Delete Secret
aws/secretsmanager/delete_secret · Action
Schedule a secret for deletion, with an optional recovery window.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Secret ID or ARN | string | Required | prod/db/password |
| Recovery Window (days, optional) | integer | 30 | |
| Force Delete Without Recovery | boolean |
Returns: tool_result, arn, deletion_date
06Describe
AWS Secrets Manager Describe Secret
aws/secretsmanager/describe_secret · Action
Retrieve the metadata of a secret without exposing its value.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Secret ID or ARN | string | Required | prod/db/password |
Returns: tool_result, arn, name, description, rotation_enabled, last_changed_date, kms_key_id, tags
07Get
AWS Secrets Manager Get Random Password
aws/secretsmanager/get_random_password · Action
Generate a cryptographically random password. Returns sensitive data.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Password Length | integer | 32 | |
| Exclude Characters (optional) | string | ||
| Exclude Numbers | boolean | ||
| Exclude Punctuation | boolean | ||
| Exclude Uppercase | boolean | ||
| Exclude Lowercase | boolean | ||
| Include Space | boolean | ||
| Require Each Included Type | boolean |
Returns: tool_result, random_password
AWS Secrets Manager Get Resource Policy
aws/secretsmanager/get_resource_policy · Action
Retrieve the resource-based policy attached to a secret.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Secret ID or ARN | string | Required | my-secret |
Returns: tool_result, arn, resource_policy
AWS Secrets Manager Get Secret Value
aws/secretsmanager/get_secret_value · Action
Retrieve the value of a secret. Returns sensitive data.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Secret ID or ARN | string | Required | prod/db/password |
| Version ID (optional) | string | ||
| Version Stage (optional) | string | AWSCURRENT |
Returns: tool_result, secret_string, secret_binary, arn, version_id
08List
AWS Secrets Manager List Secret Version IDs
aws/secretsmanager/list_secret_version_ids · Action
List the version IDs and staging labels of a secret.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Secret ID or ARN | string | Required | prod/db/password |
| Include Deprecated Versions | boolean |
Returns: tool_result, versions, count
AWS Secrets Manager List Secrets
aws/secretsmanager/list_secrets · Action
List all secrets in the account, optionally filtered by name.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Name Filter (optional) | string | prod/ |
Returns: tool_result, secrets, count
09Put
AWS Secrets Manager Put Resource Policy
aws/secretsmanager/put_resource_policy · Action
Attach a JSON resource-based policy to a secret.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Secret ID or ARN | string | Required | my-secret |
| Resource Policy (JSON) | string | Required | {"Version":"2012-10-17","Statement":[...]} |
| Block Public Policy | boolean |
Returns: tool_result, arn
AWS Secrets Manager Put Secret Value
aws/secretsmanager/put_secret_value · Action
Store a new encrypted value as a new version of an existing secret.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Secret ID or ARN | string | Required | prod/db/password |
| Secret Value | secret | Required | |
| Version Stages (comma-separated, optional) | string | AWSCURRENT |
Returns: tool_result, arn, version_id
10Remove
AWS Secrets Manager Remove Regions From Replication
aws/secretsmanager/remove_regions_from_replication · Action
Remove one or more replica regions from a replicated secret.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Secret ID or ARN | string | Required | prod/db/password |
| Regions (comma-separated) | string | Required | us-east-1,eu-central-1 |
Returns: tool_result, arn, replication_status
11Replicate
AWS Secrets Manager Replicate Secret To Regions
aws/secretsmanager/replicate_secret_to_regions · Action
Replicate a secret to one or more additional AWS regions.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Secret ID or ARN | string | Required | prod/db/password |
| Regions (comma-separated) | string | Required | us-east-1,eu-central-1 |
| Force Overwrite Existing Secrets | boolean |
Returns: tool_result, arn, replication_status
12Restore
AWS Secrets Manager Restore Secret
aws/secretsmanager/restore_secret · Action
Cancel the scheduled deletion of a secret and restore it.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Secret ID or ARN | string | Required | prod/db/password |
Returns: tool_result, arn, name
13Rotate
AWS Secrets Manager Rotate Secret
aws/secretsmanager/rotate_secret · Action
Configure and optionally trigger rotation of a secret.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Secret ID or ARN | string | Required | prod/db/password |
| Rotation Lambda ARN (optional) | string | ||
| Rotate Immediately | boolean |
Returns: tool_result, arn, version_id
14Stop
AWS Secrets Manager Stop Replication to Replica
aws/secretsmanager/stop_replication_to_replica · Action
Promote a replica to a standalone secret. Run in the replica region.
| Field | Type | Details | |
|---|---|---|---|
| Replica Region | string | Required | us-east-1 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Secret Name or Replica ARN | string | Required | my-secret |
Returns: tool_result, arn
15Tag
AWS Secrets Manager Tag Resource
aws/secretsmanager/tag_resource · Action
Attach one or more tags to a secret.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Secret ID or ARN | string | Required | my-secret |
| Tags | key_value_array |
Returns: tool_result, arn
16Untag
AWS Secrets Manager Untag Resource
aws/secretsmanager/untag_resource · Action
Remove one or more tags from a secret by tag key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Secret ID or ARN | string | Required | prod/db/password |
| Tag Keys (comma-separated) | string | Required | environment,owner |
Returns: tool_result
17Update
AWS Secrets Manager Update Secret
aws/secretsmanager/update_secret · Action
Update a secret's value, description or KMS key.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Secret ID or ARN | string | Required | prod/db/password |
| Secret Value (optional) | secret | ||
| Description (optional) | string | ||
| KMS Key ID (optional) | string |
Returns: tool_result, arn, version_id
18Validate
AWS Secrets Manager Validate Resource Policy
aws/secretsmanager/validate_resource_policy · Action
Validate a JSON resource-based policy for a secret before attaching it.
| Field | Type | Details | |
|---|---|---|---|
| Region | string | Required | eu-west-2 |
| Role ARN to Assume | string | Required | arn:aws:iam::<your-account>:role/FlomationAccess |
| Assume Role External ID (optional) | string | Must match the External ID in the role's trust policy | |
| Resource Policy (JSON) | string | Required | {"Version":"2012-10-17","Statement":[...]} |
| Secret ID or ARN (optional) | string | my-secret |
Returns: tool_result, policy_validation_passed, validation_errors
19Notes & Limitations
Behaviours and constraints worth knowing before you build with these nodes.
- Region must be set for every action regardless of the authentication method chosen, and it must be the region the secret actually lives in — for a replicated copy, use that replica's own region.
- Deleting a secret only schedules it for removal after a recovery window of 7 to 30 days (30 by default), during which Restore Secret can reverse it, whereas Force Delete Without Recovery removes it immediately and permanently.
- A secret name cannot be reused while a secret of that name is still inside its deletion recovery window, so restore or force-delete the old one before recreating it.
- Binary secret values are returned base64-encoded in the Secret Binary output, while plain-text values come back unchanged in Secret Value.
- Secrets Manager is eventually consistent, so a newly created secret or freshly written version may not appear in List Secrets or Describe Secret for a short period after it is saved.