1. Support
  2. Integrations
  3. Secrets Manager
AWS 22 nodes

Secrets Manager

AWS integration · 22 node(s).

00Overview

Store, retrieve and rotate application secrets in AWS Secrets Manager straight from a flow — read a secret value to feed a downstream step, create or update secrets and their versions, and generate a strong random password on demand. You can also schedule or restore deletions, configure rotation, replicate secrets across regions, and manage tags and resource-based access policies without leaving the editor.

Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.

01Connecting Secrets Manager

  1. Decide how the node authenticates using the Authentication dropdown, which offers three methods: Access Keys (your own IAM user keys), Assume Role (cross-account) (Flomation assumes a role in your account), and Managed Role (Credential) (a reusable AWS credential saved in Flomation).
  2. For Access Keys, open the AWS IAM console (console.aws.amazon.com/iam) → Users → your user → Security credentials → Create access key, then copy the values into the AWS Access Key and AWS Secret Key fields — add the Session Token too if you are using temporary STS credentials.
  3. For Assume Role (cross-account), create an IAM role in your account that trusts Flomation's AWS principal and grants the Secrets Manager permissions you need, then paste its ARN into Role ARN to Assume; if the role's trust policy sets an external ID, enter the same value in Assume Role External ID.
  4. For Managed Role (Credential), simply pick a pre-configured AWS credential in the AWS Role Credential field — ask your Flomation administrator to set one up if the list is empty.
  5. Set Region to the AWS region your secret lives in (for example eu-west-2) — this is required for every authentication method.
  6. Store your AWS keys as Flomation environment secrets (e.g. secretsmanager_secret) rather than typing them inline, then select them in the node's matching AWS Secret Key and AWS Access Key fields.
FieldTypeDetails
AuthenticationstringRequiredAccess Keys, Assume Role (cross-account), Managed Role (Credential)
AWS Access KeysecretRequired
AWS Secret KeysecretRequired
Session Token (optional)secret
AWS Role CredentialcredentialRequired
Good to know

Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.

02Batch

AWS Secrets Manager Batch Get Secret Value

aws/secretsmanager/batch_get_secret_value · Action

Retrieve the values of multiple secrets at once. Returns sensitive data.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Secret IDs (comma-separated or JSON array)stringRequiredprod/db, prod/api

Returns: tool_result, secret_values, errors, count

03Cancel

AWS Secrets Manager Cancel Rotate Secret

aws/secretsmanager/cancel_rotate_secret · Action

Turn off automatic rotation and cancel an in-progress rotation.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Secret ID or ARNstringRequiredprod/db/password

Returns: tool_result, arn

04Create

AWS Secrets Manager Create Secret

aws/secretsmanager/create_secret · Action

Create a new secret with an optional value, description and tags.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Secret NamestringRequiredprod/db/password
Secret Valuesecret
DescriptionstringOptional
KMS Key ID (optional)string
Tagskey_value_array

Returns: tool_result, arn, name, version_id

05Delete

AWS Secrets Manager Delete Resource Policy

aws/secretsmanager/delete_resource_policy · Action

Remove the resource-based policy attached to a secret.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Secret ID or ARNstringRequiredmy-secret

Returns: tool_result, arn

AWS Secrets Manager Delete Secret

aws/secretsmanager/delete_secret · Action

Schedule a secret for deletion, with an optional recovery window.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Secret ID or ARNstringRequiredprod/db/password
Recovery Window (days, optional)integer30
Force Delete Without Recoveryboolean

Returns: tool_result, arn, deletion_date

06Describe

AWS Secrets Manager Describe Secret

aws/secretsmanager/describe_secret · Action

Retrieve the metadata of a secret without exposing its value.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Secret ID or ARNstringRequiredprod/db/password

Returns: tool_result, arn, name, description, rotation_enabled, last_changed_date, kms_key_id, tags

07Get

AWS Secrets Manager Get Random Password

aws/secretsmanager/get_random_password · Action

Generate a cryptographically random password. Returns sensitive data.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Password Lengthinteger32
Exclude Characters (optional)string
Exclude Numbersboolean
Exclude Punctuationboolean
Exclude Uppercaseboolean
Exclude Lowercaseboolean
Include Spaceboolean
Require Each Included Typeboolean

Returns: tool_result, random_password

AWS Secrets Manager Get Resource Policy

aws/secretsmanager/get_resource_policy · Action

Retrieve the resource-based policy attached to a secret.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Secret ID or ARNstringRequiredmy-secret

Returns: tool_result, arn, resource_policy

AWS Secrets Manager Get Secret Value

aws/secretsmanager/get_secret_value · Action

Retrieve the value of a secret. Returns sensitive data.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Secret ID or ARNstringRequiredprod/db/password
Version ID (optional)string
Version Stage (optional)stringAWSCURRENT

Returns: tool_result, secret_string, secret_binary, arn, version_id

08List

AWS Secrets Manager List Secret Version IDs

aws/secretsmanager/list_secret_version_ids · Action

List the version IDs and staging labels of a secret.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Secret ID or ARNstringRequiredprod/db/password
Include Deprecated Versionsboolean

Returns: tool_result, versions, count

AWS Secrets Manager List Secrets

aws/secretsmanager/list_secrets · Action

List all secrets in the account, optionally filtered by name.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Name Filter (optional)stringprod/

Returns: tool_result, secrets, count

09Put

AWS Secrets Manager Put Resource Policy

aws/secretsmanager/put_resource_policy · Action

Attach a JSON resource-based policy to a secret.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Secret ID or ARNstringRequiredmy-secret
Resource Policy (JSON)stringRequired{"Version":"2012-10-17","Statement":[...]}
Block Public Policyboolean

Returns: tool_result, arn

AWS Secrets Manager Put Secret Value

aws/secretsmanager/put_secret_value · Action

Store a new encrypted value as a new version of an existing secret.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Secret ID or ARNstringRequiredprod/db/password
Secret ValuesecretRequired
Version Stages (comma-separated, optional)stringAWSCURRENT

Returns: tool_result, arn, version_id

10Remove

AWS Secrets Manager Remove Regions From Replication

aws/secretsmanager/remove_regions_from_replication · Action

Remove one or more replica regions from a replicated secret.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Secret ID or ARNstringRequiredprod/db/password
Regions (comma-separated)stringRequiredus-east-1,eu-central-1

Returns: tool_result, arn, replication_status

11Replicate

AWS Secrets Manager Replicate Secret To Regions

aws/secretsmanager/replicate_secret_to_regions · Action

Replicate a secret to one or more additional AWS regions.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Secret ID or ARNstringRequiredprod/db/password
Regions (comma-separated)stringRequiredus-east-1,eu-central-1
Force Overwrite Existing Secretsboolean

Returns: tool_result, arn, replication_status

12Restore

AWS Secrets Manager Restore Secret

aws/secretsmanager/restore_secret · Action

Cancel the scheduled deletion of a secret and restore it.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Secret ID or ARNstringRequiredprod/db/password

Returns: tool_result, arn, name

13Rotate

AWS Secrets Manager Rotate Secret

aws/secretsmanager/rotate_secret · Action

Configure and optionally trigger rotation of a secret.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Secret ID or ARNstringRequiredprod/db/password
Rotation Lambda ARN (optional)string
Rotate Immediatelyboolean

Returns: tool_result, arn, version_id

14Stop

AWS Secrets Manager Stop Replication to Replica

aws/secretsmanager/stop_replication_to_replica · Action

Promote a replica to a standalone secret. Run in the replica region.

FieldTypeDetails
Replica RegionstringRequiredus-east-1
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Secret Name or Replica ARNstringRequiredmy-secret

Returns: tool_result, arn

15Tag

AWS Secrets Manager Tag Resource

aws/secretsmanager/tag_resource · Action

Attach one or more tags to a secret.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Secret ID or ARNstringRequiredmy-secret
Tagskey_value_array

Returns: tool_result, arn

16Untag

AWS Secrets Manager Untag Resource

aws/secretsmanager/untag_resource · Action

Remove one or more tags from a secret by tag key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Secret ID or ARNstringRequiredprod/db/password
Tag Keys (comma-separated)stringRequiredenvironment,owner

Returns: tool_result

17Update

AWS Secrets Manager Update Secret

aws/secretsmanager/update_secret · Action

Update a secret's value, description or KMS key.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Secret ID or ARNstringRequiredprod/db/password
Secret Value (optional)secret
Description (optional)string
KMS Key ID (optional)string

Returns: tool_result, arn, version_id

18Validate

AWS Secrets Manager Validate Resource Policy

aws/secretsmanager/validate_resource_policy · Action

Validate a JSON resource-based policy for a secret before attaching it.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Resource Policy (JSON)stringRequired{"Version":"2012-10-17","Statement":[...]}
Secret ID or ARN (optional)stringmy-secret

Returns: tool_result, policy_validation_passed, validation_errors

19Notes & Limitations

Behaviours and constraints worth knowing before you build with these nodes.

  • Region must be set for every action regardless of the authentication method chosen, and it must be the region the secret actually lives in — for a replicated copy, use that replica's own region.
  • Deleting a secret only schedules it for removal after a recovery window of 7 to 30 days (30 by default), during which Restore Secret can reverse it, whereas Force Delete Without Recovery removes it immediately and permanently.
  • A secret name cannot be reused while a secret of that name is still inside its deletion recovery window, so restore or force-delete the old one before recreating it.
  • Binary secret values are returned base64-encoded in the Secret Binary output, while plain-text values come back unchanged in Secret Value.
  • Secrets Manager is eventually consistent, so a newly created secret or freshly written version may not appear in List Secrets or Describe Secret for a short period after it is saved.