#AwsSecretsManager
Compare AWS Parameter Store and Secrets Manager, including SecureString encryption, retrieval costs, rotation, and the trade-offs of bundling secrets. #awssecretsmanager
Choosing Between AWS Secrets Manager and Parameter Store
hackernoon.com
September 22, 2026 at 4:33 PM
AWS Secrets Manager expands AWS PrivateLink support to FIPS endpoints

AWS Secrets Manager now supports AWS PrivateLink with all Secrets Manager Federal Information Processing Standard (FIPS) endpoints that are available in commercial AWS Regions and the AWS GovCloud (U...

#AWS #AwsSecretsManager
AWS Secrets Manager expands AWS PrivateLink support to FIPS endpoints
AWS Secrets Manager now supports AWS PrivateLink with all Secrets Manager Federal Information Processing Standard (FIPS) endpoints that are available in commercial AWS Regions and the AWS GovCloud (US) Regions. With this launch, you can establish a private connection between your virtual private cloud (VPC) and Secrets Manager FIPS endpoints instead of connecting over the public internet, helping you meet your organization's business, compliance, and regulatory requirements to limit public internet connectivity. To learn more about AWS Secrets Manager support for AWS PrivateLink, visit the https://docs.aws.amazon.com/secretsmanager/latest/userguide/vpc-endpoint-overview.html. For more information about AWS PrivateLink and its benefits, visit the https://aws.amazon.com/privatelink/. 
aws.amazon.com
October 2, 2025 at 8:05 PM
Secret rotation doesn’t have to be complex.

Brien Posey walks through how to connect EC2 to RDS and prepare for automatic key rotation in @awscloud.bsky.social’s Secrets Manager with no heavy coding required.

Read more: awsinsider.net/articles/202...

#AWS #CloudSecurity #AWSSecretsManager
Automatically Rotating AWS Secrets, Part 1 -- AWSInsider
Brien Posey walks through a practical setup for secure, automatic AWS secret rotation: create an IAM role, spin up EC2, connect to RDS SQL Server, store creds in AWS Secrets Manager, and prep rotation...
awsinsider.net
November 18, 2025 at 3:33 PM
🆕 AWS Secrets Manager now supports managed external secrets for Paddle API keys and GitLab access tokens, enabling automatic rotation and seamless credential management for third-party services in all supported AWS Regions.

#AWS #AwsSecretsManager #AwsGovcloudUs
AWS Secrets Manager adds managed external secrets support for Paddle and GitLab
AWS Secrets Manager now extends its managed external secrets capability to include Paddle API Keys and GitLab Access Tokens. Managed external secrets enable customers to automatically rotate third-party credentials directly from AWS Secrets Manager by offering first-class integration with supported third-party services. With this launch, you can manage rotation for Paddle API keys using Paddle's native rotation API, which provides a configurable grace period that allows applications to seamlessly transition to new keys without interruption. For GitLab, you can now rotate three types of access tokens — Personal Access Tokens, Group Access Tokens, and Project Access Tokens — using GitLab's atomic rotation mechanism. These new integrations join existing managed external secrets integrations with BigID, Confluent Cloud, Datadog, MongoDB Atlas, Salesforce, and Snowflake, enabling customers to manage third-party software vended secrets. Paddle and GitLab managed external secrets are available in all AWS Regions where AWS Secrets Manager managed external secrets is supported. To learn more, visit the AWS Secrets Manager managed external secrets documentation.
aws.amazon.com
July 6, 2026 at 5:10 PM
AWS Secrets Manager now supports hybrid post-quantum TLS to protect secrets from quantum threats

AWS Secrets Manager now supports hybrid post-quantum key exchange using ML-KEM (Module-Lattice-based Key-Encapsulation Mechanism) to secure TLS connections for retrieving...

#AWS #AwsSecretsManager
AWS Secrets Manager now supports hybrid post-quantum TLS to protect secrets from quantum threats
AWS Secrets Manager now supports hybrid post-quantum key exchange using ML-KEM (Module-Lattice-based Key-Encapsulation Mechanism) to secure TLS connections for retrieving and managing secrets. This protection is automatically enabled in Secrets Manager Agent (version 2.0.0+), AWS Lambda Extension (version 19+), and Secrets Manager CSI Driver (version 2.0.0+). For SDK-based clients, hybrid post-quantum key exchange is available in supported AWS SDKs including Rust, Go, Node.js, Kotlin, Python (with OpenSSL 3.5+), and Java v2 (v2.35.11+). With this launch, your applications retrieve secrets over TLS connections that combine classical key exchange with post-quantum cryptography, helping protect against both traditional cryptographic attacks and future quantum computing threats known as "harvest now, decrypt later" (HNDL). No code changes, configuration updates, or migration effort are required for customers using the latest client versions except for Java v2. For example, a microservice requiring multiple secrets at startup can now retrieve them over quantum-resistant TLS connections by simply upgrading to the latest Secrets Manager Agent version. You can verify hybrid post-quantum key exchange is active by checking CloudTrail logs for the "X25519MLKEM768" key exchange algorithm in the tlsDetails field of GetSecretValue API calls. Hybrid post-quantum key exchange using ML-KEM for AWS Secrets Manager is available in all AWS Regions where AWS Secrets Manager is supported. To learn more, visit the https://docs.aws.amazon.com/secretsmanager/latest/userguide/intro.html and the https://aws.amazon.com/security/post-quantum-cryptography/migrating-to-post-quantum-cryptography/.
aws.amazon.com
April 14, 2026 at 9:05 PM
🆕 AWS Secrets Manager now supports AWS PrivateLink for all FIPS endpoints in commercial and GovCloud regions, enabling private VPC connections to meet compliance and regulatory needs. For details, see AWS Secrets Manager and AWS PrivateLink docs.

#AWS #AwsSecretsManager
AWS Secrets Manager expands AWS PrivateLink support to FIPS endpoints
AWS Secrets Manager now supports AWS PrivateLink with all Secrets Manager Federal Information Processing Standard (FIPS) endpoints that are available in commercial AWS Regions and the AWS GovCloud (US) Regions. With this launch, you can establish a private connection between your virtual private cloud (VPC) and Secrets Manager FIPS endpoints instead of connecting over the public internet, helping you meet your organization's business, compliance, and regulatory requirements to limit public internet connectivity. To learn more about AWS Secrets Manager support for AWS PrivateLink, visit the AWS Secrets Manager documentation. For more information about AWS PrivateLink and its benefits, visit the AWS PrivateLink product page.
aws.amazon.com
October 2, 2025 at 7:41 PM
🆕 AWS Secrets Manager now supports managed external secrets for Cisco Security Platform and Netskope, enabling automatic rotation of third-party credentials directly from the AWS console without custom code, available in all supported regions.

#AWS #AwsSecretsManager
AWS Secrets Manager adds managed external secrets support for Cisco Security Platform and Netskope
AWS Secrets Manager now extends its managed external secrets capability to include Cisco Security Platform API keys and Netskope API tokens, enabling you to automatically rotate these third-party credentials directly from the AWS console without writing any custom rotation code. For Cisco Security Platform (Security Cloud Control), Secrets Manager rotates the API key's refresh token on your schedule, keeping the credential active and capturing the new refresh token Cisco periodically reissues. Following Cisco's standard OAuth pattern, your applications exchange the stored refresh token for short-lived access tokens on demand. For Netskope, Secrets Manager rotates RBACv3 service-account REST API tokens through Netskope's SCIM API and validates the newly generated token before completing rotation. Both integrations are self-authenticating — the stored credential authorizes its own rotation — so no separate administrator credential is required. These integrations join existing managed external secrets support for BigID, Confluent Cloud, Datadog, GitLab, Jenkins, MongoDB Atlas, Okta, Paddle, Salesforce, Snowflake, and SonarQube. Cisco Security Platform and Netskope managed external secrets are available in all AWS Regions where AWS Secrets Manager managed external secrets is supported. To learn more, visit the  AWS Secrets Manager managed external secrets documentation .
aws.amazon.com
August 25, 2026 at 8:10 PM
🆕 AWS Secrets Manager Agent now pre-fetches secrets at startup and supports IAM role assumption for cross-account access, cutting startup latency and operational overhead while boosting security via role-based access. Available globally.

#AWS #AwsSecretsManager
Introducing pre-fetching and IAM role assumption for AWS Secrets Manager Agent
AWS Secrets Manager Agent now supports two new capabilities: pre-fetching secrets at startup and assuming an IAM role to retrieve secrets. With pre-fetching, you can specify a list of secrets or a tag value to retrieve and cache at agent startup, reducing application startup latency and optimizing cost through the BatchGetSecretValue API. With IAM role assumption, you can pass a role ARN in your pre-fetch configuration or HTTP requests for secret retrieval. The agent assumes the specified role to retrieve secrets, enabling cross-account secret retrieval by assuming a role in a different account. Together, these enhancements strengthen your security posture through role-based secret access and reduce operational overhead by eliminating custom pre-loading logic. For example, a microservice that requires 20 secrets at startup can now pre-fetch them in a single batch operation, cutting startup latency by avoiding sequential GetSecretValue calls. IAM role assumption also simplifies multi-account architectures by enabling you to specify a different IAM role per secret. AWS Secrets Manager Agent with pre-fetching and IAM role assumption is supported in all AWS Regions where AWS Secrets Manager is offered. To learn more, visit the AWS Secrets Manager Agent documentation.
aws.amazon.com
May 19, 2026 at 8:10 PM
IPv6 compatibility for AWS Secrets Manager VPC Endpoints

AWS Secrets Manager now supports Internet Protocol version 6 (IPv6), Dualstack compatibility for Virtual Private Cloud through https://aws.amazon.com/privatelink/. With this, Secrets Manager is now...

#AWS #AwsGovcloudUs #AwsSecretsManager
IPv6 compatibility for AWS Secrets Manager VPC Endpoints
AWS Secrets Manager now supports Internet Protocol version 6 (IPv6), Dualstack compatibility for Virtual Private Cloud through https://aws.amazon.com/privatelink/. With this, Secrets Manager is now fully compatible for IPv6 connectivity in all commercial regions via PrivateLink networking. IPv6 addresses global increase in the demand for internet connected devices, without the need for NAT and is largely scalable. With simultaneous support for both IPv4 and IPv6 clients on Secrets Manager endpoints, you are able to gradually transition from IPv4 to IPv6 based systems and applications, without needing to switch all over at once. This also enables you to meet IPv6 compliance requirements. With this launch, you can choose to connect using the new protocol over both the public internet and via PrivateLink. IPv6 support for Secrets Manager is available for PrivateLink endpoints in all commercial regions, China regions, and the AWS GovCloud (US) Regions. Refer to Secrets Manager https://docs.aws.amazon.com/secretsmanager/latest/userguide/ip-access.html for more details.
aws.amazon.com
December 27, 2024 at 8:05 PM
AWS Secrets Manager introduces safe secrets handling in the Agent Toolkit for AWS

AWS Secrets Manager now offers a secret safety skill as part of the aws-core plugin in the https://github.com/aws/agent-toolkit-for-aws, an open-source repository that equips AI coding agen...

#AWS #AwsSecretsManager
AWS Secrets Manager introduces safe secrets handling in the Agent Toolkit for AWS
AWS Secrets Manager now offers a secret safety skill as part of the aws-core plugin in the https://github.com/aws/agent-toolkit-for-aws, an open-source repository that equips AI coding agents with tools, knowledge, and guardrails for building on AWS. The skill lets developers use secrets within agentic workflows without ever exposing secret values to the underlying model or session logs. Until now, developers using AI coding agents could retrieve secrets as plain text without any guardrails, bringing sensitive values into agent context. With this skill, agents can securely retrieve and consume secrets without passing secret values through the context window, adding a layer of protection. To achieve this, the skill uses a two-layer approach. First, it steers the agent so the model never requests or receives a raw secret value—instead prompting the developer to clarify intent and constructing a command that uses the secret rather than retrieving it. Second, a child process resolves secret references to actual values only at execution time, outside the agent process. Together, these layers ensure plaintext secrets never appear in model context, session logs, or agent memory—without disrupting the developer's workflow. The secret safety skill is available today for all agent harnesses supported by the Agent Toolkit for AWS—including Claude Code, Codex, and Cursor—and in all AWS Regions where Secrets Manager is available. To get started, visit the https://github.com/aws/agent-toolkit-for-aws and install the aws-core plugin for your preferred coding agent. For details, refer to the https://docs.aws.amazon.com/secretsmanager/latest/userguide/retrieving-secrets-ai-agents.html.
aws.amazon.com
June 17, 2026 at 10:05 PM
Hand-built Python tooling exploited CVE-2026-39987 in marimo, turning pre-auth WebSocket access into SSH on a bastion in 8 seconds, with AWS credential harvesting and EC2 enumeration. #marimo #AWS #Linode
Machine Speed, Hold The AI: Hand-rolled Marimo CVE-2026-39987 Exploit
Sysdig TRT observed a skilled threat actor exploit CVE-2026-39987 in marimo to move from an unauthenticated WebSocket terminal to SSH access on a bastion host in eight seconds, using hand-built Python tooling rather than LLM-generated scripts. The campaign involved AWS credential harvesting, Secrets Manager access, EC2 enumeration, and direct SSH pivoting, with infrastructure tied to Akamai Connected Cloud/Linode. #CVE-2026-39987 #marimo #AWSSecretsManager #Linode
www.hendryadrian.com
September 12, 2026 at 12:45 AM
Static .env files do not scale safely. AWS teams need cross-account secrets management, KMS policies, rotation, and leak detection. #awssecretsmanager
Beyond .env: Hardening Cross-Account Secrets Governance in AWS
hackernoon.com
September 1, 2026 at 1:01 PM
🆕 AWS Secrets Manager now lets you install AWS Workload Credentials Provider in one click on Linux and Windows, reducing setup from 6 steps to a single command. Available in Amazon Linux repo and via public URL, it caches secrets locally and supports AWS Certificate Manage…

#AWS #AwsSecretsManager
AWS Workload Credentials Provider is now available as a one-click install for Linux and Windows
Today, AWS Secrets Manager announces one-click installation for the AWS Workload Credentials Provider (AWCP) on Amazon Linux and Windows, reducing setup from a multi-step build-from-source process to a single command.    AWCP resolves secrets from AWS Secrets Manager and caches them locally, enabling applications to retrieve secrets over a local HTTP endpoint. AWCP also enables you to pull your certificates from AWS Certificate Manager. Previously, customers who wanted to use AWCP on Amazon EC2 instances had approximately 6 steps, starting from cloning the Github repository to compiling the binary and setting up configurations. This multi-step process required every developer to learn Rust expertise and build infrastructure.    Now, customers can download pre-built, signed binaries for Linux (x86_64 and ARM64) and Windows (x64) directly from a public download URL. Along with this, AWCP is now available in the Amazon Linux repository. Amazon Linux EC2 customers can install it in one command. All binaries are code-signed to ensure integrity and authenticity, and deliver a ready-to-run agent with in-memory secret caching.    AWS Workload Credentials Provider one-click install is available on Amazon Linux 2023 (x86_64 and ARM64) and Windows Server (x64) in all AWS Regions where AWS Secrets Manager is available, at no additional cost beyond standard Secrets Manager pricing. To get started, see the following resources - AWS Workload Credentials Provider documentation , ACM documentation, and AWCP on GitHub.
aws.amazon.com
August 31, 2026 at 10:10 PM
AWS Workload Credentials Provider is now available as a one-click install for Linux and Windows

Today, AWS Secrets Manager announces one-click installation for the AWS Workload Credentials Provider (AWCP) on Amazon Linux and Windows, reducing setup from a multi-step buil...

#AWS #AwsSecretsManager
AWS Workload Credentials Provider is now available as a one-click install for Linux and Windows
Today, AWS Secrets Manager announces one-click installation for the AWS Workload Credentials Provider (AWCP) on Amazon Linux and Windows, reducing setup from a multi-step build-from-source process to a single command.    AWCP resolves secrets from AWS Secrets Manager and caches them locally, enabling applications to retrieve secrets over a local HTTP endpoint. AWCP also enables you to pull your certificates from AWS Certificate Manager. Previously, customers who wanted to use AWCP on Amazon EC2 instances had approximately 6 steps, starting from cloning the Github repository to compiling the binary and setting up configurations. This multi-step process required every developer to learn Rust expertise and build infrastructure.    Now, customers can download pre-built, signed binaries for Linux (x86_64 and ARM64) and Windows (x64) directly from a public download URL. Along with this, AWCP is now available in the Amazon Linux repository. Amazon Linux EC2 customers can install it in one command. All binaries are code-signed to ensure integrity and authenticity, and deliver a ready-to-run agent with in-memory secret caching.    AWS Workload Credentials Provider one-click install is available on Amazon Linux 2023 (x86_64 and ARM64) and Windows Server (x64) in all AWS Regions where AWS Secrets Manager is available, at no additional cost beyond standard Secrets Manager pricing. To get started, see the following resources - AWS Workload Credentials Provider https://docs.aws.amazon.com/secretsmanager/latest/userguide/workload-credentials-provider.html , ACM https://docs.aws.amazon.com/acm/latest/userguide/acm-certificate-automation.html, and AWCP on https://github.com/aws/aws-workload-credentials-provider.
aws.amazon.com
August 31, 2026 at 10:05 PM
AWS Secrets Manager adds managed external secrets support for Cisco Security Platform and Netskope

AWS Secrets Manager now extends its managed external secrets capability to include Cisco Security Platform API keys and Netskope API tokens, enabling you to automatically r...

#AWS #AwsSecretsManager
AWS Secrets Manager adds managed external secrets support for Cisco Security Platform and Netskope
AWS Secrets Manager now extends its managed external secrets capability to include Cisco Security Platform API keys and Netskope API tokens, enabling you to automatically rotate these third-party credentials directly from the AWS console without writing any custom rotation code. For Cisco Security Platform (Security Cloud Control), Secrets Manager rotates the API key's refresh token on your schedule, keeping the credential active and capturing the new refresh token Cisco periodically reissues. Following Cisco's standard OAuth pattern, your applications exchange the stored refresh token for short-lived access tokens on demand. For Netskope, Secrets Manager rotates RBACv3 service-account REST API tokens through Netskope's SCIM API and validates the newly generated token before completing rotation. Both integrations are self-authenticating — the stored credential authorizes its own rotation — so no separate administrator credential is required. These integrations join existing managed external secrets support for BigID, Confluent Cloud, Datadog, GitLab, Jenkins, MongoDB Atlas, Okta, Paddle, Salesforce, Snowflake, and SonarQube. Cisco Security Platform and Netskope managed external secrets are available in all AWS Regions where AWS Secrets Manager managed external secrets is supported. To learn more, visit the  https://docs.aws.amazon.com/secretsmanager/latest/userguide/managed-external-secrets.html .
aws.amazon.com
August 25, 2026 at 8:05 PM
🆕 AWS Secrets Manager adds managed external secrets support for Jenkins and SonarQube

#AWS #AWSSecretsManager #Serverless #CloudComputing #CloudNative #s3rv3rl3ss
AWS Secrets Manager adds managed external secrets support for Jenkins and SonarQube - AWS
Discover more about what's new at AWS with AWS Secrets Manager adds managed external secrets support for Jenkins and SonarQube
aws.amazon.com
August 12, 2026 at 8:20 AM
🆕 AWS Secrets Manager now supports Jenkins API Tokens and SonarQube Tokens rotation, enabling seamless credential management for CI/CD and analysis without custom code, available in all supported regions.

#AWS #AwsSecretsManager
AWS Secrets Manager adds managed external secrets support for Jenkins and SonarQube
AWS Secrets Manager now extends its managed external secrets capability to include Jenkins API Tokens and SonarQube Tokens, enabling you to automatically rotate these third-party credentials directly from the AWS console without writing any custom rotation code. For Jenkins, Secrets Manager mints a new token and revokes the old one only after the replacement is verified active, so your continuous integration and continuous delivery (CI/CD) jobs transition without interruption. Rotation supports both self-rotation, where the token being rotated authenticates its own replacement, and admin-assisted rotation, where a separate admin token performs the generate and revoke operations. For SonarQube, you can rotate three types of tokens — User Tokens, Global Analysis Tokens, and Project Analysis Tokens — via SonarQube's Web API. User Tokens support self-rotation, while analysis tokens are rotated using an admin token. These integrations join existing managed external secrets support for BigID, Confluent Cloud, Datadog, GitLab, MongoDB Atlas, Okta, Paddle, Salesforce, and Snowflake. Jenkins and SonarQube managed external secrets are available in all AWS Regions where AWS Secrets Manager managed external secrets is supported. To learn more, visit the  AWS Secrets Manager managed external secrets documentation .
aws.amazon.com
August 11, 2026 at 8:10 PM
AWS Secrets Manager adds managed external secrets support for Jenkins and SonarQube

AWS Secrets Manager now extends its managed external secrets capability to include Jenkins API Tokens and SonarQube Tokens, enabling you to automatically rotate these third-party credenti...

#AWS #AwsSecretsManager
AWS Secrets Manager adds managed external secrets support for Jenkins and SonarQube
AWS Secrets Manager now extends its managed external secrets capability to include Jenkins API Tokens and SonarQube Tokens, enabling you to automatically rotate these third-party credentials directly from the AWS console without writing any custom rotation code. For Jenkins, Secrets Manager mints a new token and revokes the old one only after the replacement is verified active, so your continuous integration and continuous delivery (CI/CD) jobs transition without interruption. Rotation supports both self-rotation, where the token being rotated authenticates its own replacement, and admin-assisted rotation, where a separate admin token performs the generate and revoke operations. For SonarQube, you can rotate three types of tokens — User Tokens, Global Analysis Tokens, and Project Analysis Tokens — via SonarQube's Web API. User Tokens support self-rotation, while analysis tokens are rotated using an admin token. These integrations join existing managed external secrets support for BigID, Confluent Cloud, Datadog, GitLab, MongoDB Atlas, Okta, Paddle, Salesforce, and Snowflake. Jenkins and SonarQube managed external secrets are available in all AWS Regions where AWS Secrets Manager managed external secrets is supported. To learn more, visit the  https://docs.aws.amazon.com/secretsmanager/latest/userguide/managed-external-secrets.html .
aws.amazon.com
August 11, 2026 at 8:05 PM
🆕 AWS Secrets Manager now sends secret update alerts to Amazon EventBridge for real-time workflows. No extra setup; available in all Secrets Manager regions, free of charge.

#AWS #AwsGovcloudUs #AwsSecretsManager
AWS Secrets Manager now publishes secret update notifications to Amazon EventBridge
AWS Secrets Manager now automatically publishes events to Amazon EventBridge whenever your secret values change, enabling you to build event-driven workflows that respond in real time to secret updates. Until now, you had to rely on AWS CloudTrail events parsed into EventBridge to know when a secret value changed — requiring you to match multiple API events such as rotation success, PutSecretValue, and UpdateSecretValue. With this launch, Secrets Manager publishes events directly into EventBridge whenever your secret value changes. You can use EventBridge rules to detect when the active secret value changes — such as during rotation — and route notifications to targets like AWS Lambda, Amazon SNS, Amazon SQS, or Amazon Step Functions. This enables you to proactively refresh cached credentials in your applications, restart dependent services, or update compliance reports for secret rotation. Secret update notifications are published to your default event bus automatically with no additional configuration or opt-in required. This feature is available in all AWS Regions where AWS Secrets Manager is available at no additional cost. To get started, see secret event notifications in the AWS Secrets Manager User Guide.
aws.amazon.com
July 22, 2026 at 6:10 PM
AWS Secrets Manager now publishes secret update notifications to Amazon EventBridge

AWS Secrets Manager now automatically publishes events to Amazon EventBridge whenever your secret values change, enabling you to build event-driven workflows that respond i...

#AWS #AwsGovcloudUs #AwsSecretsManager
AWS Secrets Manager now publishes secret update notifications to Amazon EventBridge
AWS Secrets Manager now automatically publishes events to Amazon EventBridge whenever your secret values change, enabling you to build event-driven workflows that respond in real time to secret updates. Until now, you had to rely on AWS CloudTrail events parsed into EventBridge to know when a secret value changed — requiring you to match multiple API events such as rotation success, PutSecretValue, and UpdateSecretValue. With this launch, Secrets Manager publishes events directly into EventBridge whenever your secret value changes. You can use EventBridge rules to detect when the active secret value changes — such as during rotation — and route notifications to targets like AWS Lambda, Amazon SNS, Amazon SQS, or Amazon Step Functions. This enables you to proactively refresh cached credentials in your applications, restart dependent services, or update compliance reports for secret rotation. Secret update notifications are published to your default event bus automatically with no additional configuration or opt-in required. This feature is available in all AWS Regions where AWS Secrets Manager is available at no additional cost. To get started, see https://docs.aws.amazon.com/secretsmanager/latest/userguide/secret-event-notifications.html in the AWS Secrets Manager User Guide.
aws.amazon.com
July 22, 2026 at 6:05 PM
AWS Secrets Manager adds managed external secrets support for Paddle and GitLab

AWS Secrets Manager now extends its managed external secrets capability to include Paddle API Keys and GitLab Access Tokens. Managed external secrets enable customers to automa...

#AWS #AwsSecretsManager #AwsGovcloudUs
AWS Secrets Manager adds managed external secrets support for Paddle and GitLab
AWS Secrets Manager now extends its managed external secrets capability to include Paddle API Keys and GitLab Access Tokens. Managed external secrets enable customers to automatically rotate third-party credentials directly from AWS Secrets Manager by offering first-class integration with supported third-party services. With this launch, you can manage rotation for Paddle API keys using Paddle's native rotation API, which provides a configurable grace period that allows applications to seamlessly transition to new keys without interruption. For GitLab, you can now rotate three types of access tokens — Personal Access Tokens, Group Access Tokens, and Project Access Tokens — using GitLab's atomic rotation mechanism. These new integrations join existing managed external secrets integrations with BigID, Confluent Cloud, Datadog, MongoDB Atlas, Salesforce, and Snowflake, enabling customers to manage third-party software vended secrets. Paddle and GitLab managed external secrets are available in all AWS Regions where AWS Secrets Manager managed external secrets is supported. To learn more, visit the .
aws.amazon.com
July 6, 2026 at 5:05 PM