## TL;DR

Pull a secret with `aws secretsmanager get-secret-value` naming the secret and the region explicitly, then extract the field you need from the returned JSON. Most failures are a wrong region, a missing IAM permission, or a KMS key the caller cannot use, and each one has a distinct error you can fix directly.

## Error

```text
aws secretsmanager cli
```

## Steps

1. Set the region explicitly on every call: `aws secretsmanager get-secret-value --secret-id [secret name] --region [region]`. Expected: JSON containing `SecretString` or `SecretBinary`.
2. Extract one field without printing the whole secret - pipe through a JSON query for the key you need, e.g. `--query SecretString --output text | jq -r '.[field name]'`. Expected: only the single value is printed.
3. If you get `ResourceNotFoundException`, list secrets in that region to check the name: `aws secretsmanager list-secrets --region [region]`. Expected: you see whether the secret lives in a different region or under a different name.
4. If you get `AccessDeniedException`, the caller needs the `secretsmanager:GetSecretValue` action on that secret's ARN. Expected: after the policy update, the call succeeds.
5. If you get `DecryptionFailure`, the caller also needs permission to use the KMS key that encrypts the secret. Expected: adding KMS decrypt rights clears the error.

## When to use

- You need a secret value in a shell script, CI job, or debugging session.
- You are triaging `ResourceNotFoundException`, `AccessDeniedException`, or `DecryptionFailure` from the CLI.

## When not to use

- Application code should use the SDK or an injector (external-secrets, Vault agent), not shell out to the CLI.
- For rotating a secret, use the rotation workflow, not repeated reads.

## Tool compatibility

- AWS CLI v2; Secrets Manager in any commercial region; `jq` for JSON parsing.

## Variant phrasings

### aws secretsmanager get-secret-value AccessDeniedException

Missing IAM permission on the secret or its KMS key.

### aws secretsmanager list-secrets returns nothing

Wrong region or the caller cannot list; check both.

## Why it happens

The CLI is region-scoped and the secret may live elsewhere, and Secrets Manager separates the read permission from the KMS decrypt permission, so partial access fails late with a decryption error.

## Edge cases

- Binary secrets come back base64-encoded in `SecretBinary`; decode them before use.
- Cross-account access needs a resource policy on the secret, not just identity policy on the caller.
- `--query` with `--output text` still prints the value to the terminal; avoid it on shared screens.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_Z1hQSJjcN3N5q9GqqZtBVg
