AWS Secrets Manager
Secrets Manager
You need to store, retrieve, and automatically rotate database credentials, API keys, and private tokens securely.
Reach for it when
- Retrieving database passwords at application runtime rather than hardcoding them in configuration files.
- Automatically rotating RDS database credentials every 30 days using built-in integration templates.
- Sharing API tokens securely across multiple ECS containers and Lambda functions.
Do not reach for it when
- Storing simple, non-sensitive configuration parameters like environment names — use Systems Manager Parameter Store instead.
- Managing the cryptographic master keys used for low-level data encryption — use KMS instead.
- Hosting a runtime configuration database that requires frequent sub-millisecond writes — use DynamoDB instead.
Alternatives, and how to choose
| Service | Pick it instead when |
|---|---|
| Parameter Store | Choose it when you need a low-cost or free service to store non-sensitive configuration settings. |
| KMS | Choose it when you need to manage cryptographic keys rather than plaintext secret strings. |
How you pay
- The model
- Pay a flat monthly fee per secret stored, plus fees per 10,000 secret API retrieval requests.
- The line item that surprises people
- Storing hundreds of individual microservice configurations as separate secrets will run up a high flat-rate monthly bill.
What trips people up
- Retrieving secrets on every application request causes latency; you must implement local caching of secret values.
- Deleting a secret immediately defaults to a recovery window; you cannot recreate a secret with the same name during this time.
- Automatic rotation requires a Lambda function; if the Lambda fails or lacks network paths, rotation will silently fail.
Verify the live service
This page is a concept reference. Cost models are qualitative; confirm the current offering, Region and pricing before deploying.