> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tracecat.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get Secret Store

> Get a store, including its persisted trust-policy inputs.



## OpenAPI

````yaml https://platform.tracecat.com/api/openapi.json get /organization/secret-stores/{store_id}
openapi: 3.1.0
info:
  title: Tracecat API
  summary: Tracecat API
  description: The open source AI automation platform for security teams and agents.
  termsOfService: >-
    https://docs.google.com/document/d/e/2PACX-1vQvDe3SoVAPoQc51MgfGCP71IqFYX_rMVEde8zC4qmBCec5f8PLKQRdxa6tsUABT8gWAR9J-EVs2CrQ/pub
  contact:
    name: Tracecat Founders
    email: founders@tracecat.com
  license:
    name: AGPL-3.0
    url: https://www.gnu.org/licenses/agpl-3.0.html
  version: '1'
servers:
  - url: /api
security: []
tags:
  - name: public
    description: Public facing endpoints
  - name: workflows
    description: Workflow management
  - name: actions
    description: Action management
  - name: triggers
    description: Workflow triggers
  - name: secrets
    description: Secret management
  - name: variables
    description: Workspace variable management
paths:
  /organization/secret-stores/{store_id}:
    get:
      tags:
        - organization-secret-stores
      summary: Get Secret Store
      description: Get a store, including its persisted trust-policy inputs.
      operationId: organization-secret-stores-get_secret_store
      parameters:
        - name: store_id
          in: path
          required: true
          schema:
            type: string
            format: uuid
            title: Store Id
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecretStoreRead'
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
      security:
        - APIKeyCookie: []
        - ServiceAccountApiKeyBearer: []
components:
  schemas:
    SecretStoreRead:
      properties:
        id:
          type: string
          format: uuid
          title: Id
        organization_id:
          type: string
          format: uuid
          title: Organization Id
        name:
          type: string
          title: Name
        description:
          anyOf:
            - type: string
            - type: 'null'
          title: Description
        provider:
          $ref: '#/components/schemas/SecretStoreProvider'
        config:
          $ref: '#/components/schemas/AwsSecretsManagerStoreConfig'
        enabled:
          type: boolean
          title: Enabled
        all_workspaces:
          type: boolean
          title: All Workspaces
        tracecat_aws_account_id:
          anyOf:
            - type: string
            - type: 'null'
          title: Tracecat Aws Account Id
        tracecat_aws_principal_arn:
          anyOf:
            - type: string
            - type: 'null'
          title: Tracecat Aws Principal Arn
        authorized_workspace_ids:
          items:
            type: string
            format: uuid
          type: array
          title: Authorized Workspace Ids
        reference_count:
          type: integer
          title: Reference Count
          default: 0
        created_at:
          type: string
          format: date-time
          title: Created At
        updated_at:
          type: string
          format: date-time
          title: Updated At
      type: object
      required:
        - id
        - organization_id
        - name
        - provider
        - config
        - enabled
        - all_workspaces
        - created_at
        - updated_at
      title: SecretStoreRead
      description: Organization view of a secret store, including trust-policy inputs.
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    SecretStoreProvider:
      type: string
      enum:
        - aws_secrets_manager
      title: SecretStoreProvider
      description: Supported external secret store providers.
    AwsSecretsManagerStoreConfig:
      properties:
        provider:
          type: string
          const: aws_secrets_manager
          title: Provider
          default: aws_secrets_manager
        role_arn:
          type: string
          maxLength: 2048
          pattern: ^arn:aws(?:-[a-z]+)*:iam::\d{12}:role/[\w+=,.@/-]+$
          title: Role Arn
        region:
          type: string
          maxLength: 64
          pattern: ^[a-z]{2}(?:-[a-z]+)+-\d$
          title: Region
        external_id:
          type: string
          maxLength: 255
          minLength: 1
          title: External Id
      type: object
      required:
        - role_arn
        - region
        - external_id
      title: AwsSecretsManagerStoreConfig
      description: Persisted provider configuration for an AWS Secrets Manager store.
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
        input:
          title: Input
        ctx:
          type: object
          title: Context
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError
  securitySchemes:
    APIKeyCookie:
      type: apiKey
      in: cookie
      name: fastapiusersauth
    ServiceAccountApiKeyBearer:
      type: http
      description: Tracecat service account API key.
      scheme: bearer

````