aws secretsmanager cli
Reads AWS Secrets Manager secrets from the CLI: the right get-secret-value flags and how to fix region, permission, and decryption errors. Use when you need a secret value in a script or terminal session. Not for rotating secrets or for application SDK usage.
TL;DR
Pull a secret with aws secretsmanager get-secret-value naming the secret and the region explicitly, then extract the field you need from the returned JSON. Most failures are a wrong region, a missing IAM permission, or a KMS key the caller cannot use, and each one has a distinct error you can fix directly.
Error
aws secretsmanager cliSteps
- Set the region explicitly on every call:
aws secretsmanager get-secret-value --secret-id [secret name] --region [region]. Expected: JSON containingSecretStringorSecretBinary. - Extract one field without printing the whole secret - pipe through a JSON query for the key you need, e.g.
--query SecretString --output text | jq -r '.[field name]'. Expected: only the single value is printed. - If you get
ResourceNotFoundException, list secrets in that region to check the name:aws secretsmanager list-secrets --region [region]. Expected: you see whether the secret lives in a different region or under a different name. - If you get
AccessDeniedException, the caller needs thesecretsmanager:GetSecretValueaction on that secret's ARN. Expected: after the policy update, the call succeeds. - If you get
DecryptionFailure, the caller also needs permission to use the KMS key that encrypts the secret. Expected: adding KMS decrypt rights clears the error.
When to use
- You need a secret value in a shell script, CI job, or debugging session.
- You are triaging
ResourceNotFoundException,AccessDeniedException, orDecryptionFailurefrom the CLI.
When not to use
- Application code should use the SDK or an injector (external-secrets, Vault agent), not shell out to the CLI.
- For rotating a secret, use the rotation workflow, not repeated reads.
Tool compatibility
- AWS CLI v2; Secrets Manager in any commercial region;
jqfor JSON parsing.
Variant phrasings
aws secretsmanager get-secret-value AccessDeniedException
Missing IAM permission on the secret or its KMS key.
aws secretsmanager list-secrets returns nothing
Wrong region or the caller cannot list; check both.
Why it happens
The CLI is region-scoped and the secret may live elsewhere, and Secrets Manager separates the read permission from the KMS decrypt permission, so partial access fails late with a decryption error.
Edge cases
- Binary secrets come back base64-encoded in
SecretBinary; decode them before use. - Cross-account access needs a resource policy on the secret, not just identity policy on the caller.
--querywith--output textstill prints the value to the terminal; avoid it on shared screens.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_Z1hQSJjcN3N5q9GqqZtBVg
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.