Skip to content
Proud to collaborate with Microsoft for Startups

aws.secretsmanager.get_secret_value ​

Call AWS Secrets Manager GetSecretValue using a CloudConnection UUID.

Overview ​

PropertyValue
Workflow typeAtomic
LibraryBase-aws
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes—Authenticated organization UUID used for field resolution and connection scoping.
connection_uuiduuidYes—AWS CloudConnection UUID for the target CodeArtifact account, scoped to the caller organization.
workflow_run_idstringNo—Engine DAG run ID stamped onto child steps.
regionstringNo—AWS API endpoint region override; omit to use the connection or SDK default.
secret_idstringYes—<p>The ARN or name of the secret to retrieve. To retrieve a secret from another account, you must use an ARN.</p> <p>For an ARN, we recommend that you specify a complete ARN rather than a partial ARN. See <a href="https://docs.aws.amazon.com/secretsmanager/latest/userguide/troubleshoot.html#ARN_secretnamehyphen">Finding a secret from a partial ARN</a>.</p>
version_idstringNo—<p>The unique identifier of the version of the secret to retrieve. If you include both this parameter and <code>VersionStage</code>, the two parameters must refer to the same secret version. If you don't specify either a <code>VersionStage</code> or <code>VersionId</code>, then Secrets Manager returns the <code>AWSCURRENT</code> version.</p> <p>This value is typically a <a href="https://wikipedia.org/wiki/Universally_unique_identifier">UUID-type</a> value with 32 hexadecimal digits.</p>
version_stagestringNo—<p>The staging label of the version of the secret to retrieve. </p> <p>Secrets Manager uses staging labels to keep track of different versions during the rotation process. If you include both this parameter and <code>VersionId</code>, the two parameters must refer to the same secret version. If you don't specify either a <code>VersionStage</code> or <code>VersionId</code>, Secrets Manager returns the <code>AWSCURRENT</code> version.</p>
provider_native_requestjsonNo—Optional provider-native request overrides for AWS parameters not yet promoted to first-class fields.

Output Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidNo—Organization UUID echoed from input.
connection_uuiduuidNo—AWS CloudConnection UUID echoed from input.
regionstringNo—AWS API endpoint region used.
servicestringNo—AWS boto3 service/client name.
operationstringNo—AWS API operation invoked.
request_idstringNo—AWS request ID when available.
responsejsonNo—Sanitized provider response object.
itemslistNo—Primary response item list when the API returns a collection.
result_countintegerNo—Count of primary response items.
next_page_tokenstringNo—Pagination token for the next page.
failure_reasonstringNo—Human-readable failure reason.
failed_stepstringNo—Failed logical step.
failed_layerjsonNo—Failed DAG layer if engine supplies one.
failed_at_statestringNo—State where failure occurred.
errorstringNo—Error message.
error_typestringNo—Error class.
failed_atstringNo—ISO failure timestamp.

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "aws.secretsmanager.get_secret_value",
  "initial_data": {
    "organization_uuid": "value",
    "connection_uuid": "value",
    "secret_id": "value"
  }
}