Amazon Secrets Manager · Arazzo Workflow

Amazon Secrets Manager Update Metadata and Verify

Version 1.0.0

Update a secret's description and KMS key with UpdateSecret, then describe it to confirm the new metadata was applied.

1 workflow 1 source API 1 provider
View Spec View on GitHub ConfigurationCredentialsRotationSecretsSecurityArazzoWorkflows

Provider

amazon-secrets-manager

Workflows

update-metadata-and-verify
Update a secret's description and KMS key, then confirm via DescribeSecret.
Calls UpdateSecret to change the description and KMS key of an existing secret, then calls DescribeSecret to verify the new metadata was applied.
2 steps inputs: Description, KmsKeyId, SecretId outputs: description, kmsKeyId, secretArn
1
updateSecret
Modify the secret's description and KMS key without changing the secret value.
2
describeSecret
Read the secret metadata back to confirm the description and KMS key changes were applied.

Source API Descriptions

Arazzo Workflow Specification

Raw ↑
arazzo: 1.0.1
info:
  title: Amazon Secrets Manager Update Metadata and Verify
  summary: Update a secret's description and KMS key with UpdateSecret, then describe it to confirm the new metadata was applied.
  description: >-
    The metadata maintenance pattern. The workflow modifies an existing secret's
    description and the KMS key used to encrypt it with UpdateSecret, then calls
    DescribeSecret to read the metadata back and confirm the changes were
    applied without touching the secret value itself. Every step inlines the AWS
    JSON 1.1 X-Amz-Target header and request payload so the flow is
    self-describing.
  version: 1.0.0
  x-realizes-capability-ids:
  - BC-620.20
  x-capability-derivation:
    method: 'deterministic join: sourceDescriptions -> per-tag OpenAPI -> tag/capability edge. No classification at this step.'
    min_confidence: 0.7
    sources:
    - capability_id: BC-620.20
      capability_name: Identity & Access Management
      spec: amazon-secrets-manager-secrets-api-openapi.yml
      confidence: 0.8
    model: Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0
sourceDescriptions:
- name: secretsApi
  url: ../openapi/amazon-secrets-manager-secrets-api-openapi.yml
  type: openapi
workflows:
- workflowId: update-metadata-and-verify
  summary: Update a secret's description and KMS key, then confirm via DescribeSecret.
  description: >-
    Calls UpdateSecret to change the description and KMS key of an existing
    secret, then calls DescribeSecret to verify the new metadata was applied.
  inputs:
    type: object
    required:
    - SecretId
    - Description
    properties:
      SecretId:
        type: string
        description: The ARN or name of the secret to update.
      Description:
        type: string
        description: The new description to set on the secret.
      KmsKeyId:
        type: string
        description: The ARN, key ID, or alias of the KMS key to encrypt the secret.
  steps:
  - stepId: updateSecret
    description: >-
      Modify the secret's description and KMS key without changing the secret
      value.
    operationId: UpdateSecret
    parameters:
    - name: X-Amz-Target
      in: header
      value: secretsmanager.UpdateSecret
    requestBody:
      contentType: application/x-amz-json-1.1
      payload:
        SecretId: $inputs.SecretId
        Description: $inputs.Description
        KmsKeyId: $inputs.KmsKeyId
    successCriteria:
    - condition: $statusCode == 200
    outputs:
      secretArn: $response.body#/ARN
      versionId: $response.body#/VersionId
  - stepId: describeSecret
    description: >-
      Read the secret metadata back to confirm the description and KMS key
      changes were applied.
    operationId: DescribeSecret
    parameters:
    - name: X-Amz-Target
      in: header
      value: secretsmanager.DescribeSecret
    requestBody:
      contentType: application/x-amz-json-1.1
      payload:
        SecretId: $steps.updateSecret.outputs.secretArn
    successCriteria:
    - condition: $statusCode == 200
    outputs:
      description: $response.body#/Description
      kmsKeyId: $response.body#/KmsKeyId
      lastChangedDate: $response.body#/LastChangedDate
  outputs:
    secretArn: $steps.updateSecret.outputs.secretArn
    description: $steps.describeSecret.outputs.description
    kmsKeyId: $steps.describeSecret.outputs.kmsKeyId

Work with this as data

Every workflow here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for arazzo workflows

4 MCP tools reach this
  • find_arazzoBrowse and filter every workflow in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This workflow
curl "https://apis.io/api/v1/arazzo/amazon-secrets-manager-update-metadata-and-verify-workflow"
All arazzo workflows
curl "https://apis.io/api/v1/arazzo?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.