Amazon Secrets Manager · Arazzo Workflow

Amazon Secrets Manager Generate Password and Store Secret

Version 1.0.0

Generate a random password, store it as a new secret, then read the secret value back to confirm it was saved.

1 workflow 2 source APIs 1 provider
View Spec View on GitHub ConfigurationCredentialsRotationSecretsSecurityArazzoWorkflows

Provider

amazon-secrets-manager

Workflows

generate-password-and-store-secret
Generate a random password and persist it as a new secret.
Calls GetRandomPassword to produce a strong credential, CreateSecret to store it under the supplied name, and GetSecretValue to confirm the stored value matches.
3 steps inputs: Description, ExcludePunctuation, Name, PasswordLength outputs: secretArn, storedSecretString, versionId
1
getRandomPassword
Generate a strong random password to the supplied length and complexity rules.
2
createSecret
Store the generated password as the SecretString of a new secret under the requested name.
3
getSecretValue
Retrieve the stored secret value to confirm the generated password was saved correctly.

Source API Descriptions

Arazzo Workflow Specification

Raw ↑
arazzo: 1.0.1
info:
  title: Amazon Secrets Manager Generate Password and Store Secret
  summary: Generate a random password, store it as a new secret, then read the secret value back to confirm it was saved.
  description: >-
    The credential bootstrap pattern. The workflow asks Secrets Manager to
    generate a strong random password to its complexity rules, stores that
    password as the SecretString of a brand new secret, and then retrieves the
    secret value to confirm the generated credential round-trips correctly.
    Every step inlines the AWS JSON 1.1 X-Amz-Target header and request payload
    so the flow is self-describing.
  version: 1.0.0
  x-realizes-capability-ids:
  - BC-620.20
  x-capability-derivation:
    method: 'deterministic join: sourceDescriptions -> per-tag OpenAPI -> tag/capability edge. No classification at this step.'
    min_confidence: 0.7
    sources:
    - capability_id: BC-620.20
      capability_name: Identity & Access Management
      spec: amazon-secrets-manager-secrets-api-openapi.yml
      confidence: 0.8
    model: Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0
sourceDescriptions:
- name: passwordsApi
  url: ../openapi/amazon-secrets-manager-passwords-api-openapi.yml
  type: openapi
- name: secretsApi
  url: ../openapi/amazon-secrets-manager-secrets-api-openapi.yml
  type: openapi
workflows:
- workflowId: generate-password-and-store-secret
  summary: Generate a random password and persist it as a new secret.
  description: >-
    Calls GetRandomPassword to produce a strong credential, CreateSecret to
    store it under the supplied name, and GetSecretValue to confirm the stored
    value matches.
  inputs:
    type: object
    required:
    - Name
    properties:
      Name:
        type: string
        description: The friendly name of the new secret to create.
      Description:
        type: string
        description: An optional description of the secret.
      PasswordLength:
        type: integer
        description: The length of the generated password.
        default: 32
      ExcludePunctuation:
        type: boolean
        description: Whether to exclude punctuation characters from the password.
        default: false
  steps:
  - stepId: getRandomPassword
    description: >-
      Generate a strong random password to the supplied length and complexity
      rules.
    operationId: GetRandomPassword
    parameters:
    - name: X-Amz-Target
      in: header
      value: secretsmanager.GetRandomPassword
    requestBody:
      contentType: application/x-amz-json-1.1
      payload:
        PasswordLength: $inputs.PasswordLength
        ExcludePunctuation: $inputs.ExcludePunctuation
    successCriteria:
    - condition: $statusCode == 200
    outputs:
      randomPassword: $response.body#/RandomPassword
  - stepId: createSecret
    description: >-
      Store the generated password as the SecretString of a new secret under
      the requested name.
    operationId: CreateSecret
    parameters:
    - name: X-Amz-Target
      in: header
      value: secretsmanager.CreateSecret
    requestBody:
      contentType: application/x-amz-json-1.1
      payload:
        Name: $inputs.Name
        Description: $inputs.Description
        SecretString: $steps.getRandomPassword.outputs.randomPassword
    successCriteria:
    - condition: $statusCode == 200
    outputs:
      secretArn: $response.body#/ARN
      versionId: $response.body#/VersionId
  - stepId: getSecretValue
    description: >-
      Retrieve the stored secret value to confirm the generated password was
      saved correctly.
    operationId: GetSecretValue
    parameters:
    - name: X-Amz-Target
      in: header
      value: secretsmanager.GetSecretValue
    requestBody:
      contentType: application/x-amz-json-1.1
      payload:
        SecretId: $steps.createSecret.outputs.secretArn
    successCriteria:
    - condition: $statusCode == 200
    outputs:
      storedSecretString: $response.body#/SecretString
      versionId: $response.body#/VersionId
  outputs:
    secretArn: $steps.createSecret.outputs.secretArn
    versionId: $steps.createSecret.outputs.versionId
    storedSecretString: $steps.getSecretValue.outputs.storedSecretString

Work with this as data

Every workflow here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for arazzo workflows

4 MCP tools reach this
  • find_arazzoBrowse and filter every workflow in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This workflow
curl "https://apis.io/api/v1/arazzo/amazon-secrets-manager-generate-password-and-store-secret-workflow"
All arazzo workflows
curl "https://apis.io/api/v1/arazzo?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.