> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tracecat.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Aws Secret Reference

> Create a custom secret whose values live in AWS Secrets Manager.



## OpenAPI

````yaml https://platform.tracecat.com/api/openapi.json post /workspaces/{workspace_id}/secrets/aws
openapi: 3.1.0
info:
  title: Tracecat API
  summary: Tracecat API
  description: The open source AI automation platform for security teams and agents.
  termsOfService: >-
    https://docs.google.com/document/d/e/2PACX-1vQvDe3SoVAPoQc51MgfGCP71IqFYX_rMVEde8zC4qmBCec5f8PLKQRdxa6tsUABT8gWAR9J-EVs2CrQ/pub
  contact:
    name: Tracecat Founders
    email: founders@tracecat.com
  license:
    name: AGPL-3.0
    url: https://www.gnu.org/licenses/agpl-3.0.html
  version: '1'
servers:
  - url: /api
security: []
tags:
  - name: public
    description: Public facing endpoints
  - name: workflows
    description: Workflow management
  - name: actions
    description: Action management
  - name: triggers
    description: Workflow triggers
  - name: secrets
    description: Secret management
  - name: variables
    description: Workspace variable management
paths:
  /workspaces/{workspace_id}/secrets/aws:
    post:
      tags:
        - secrets
      summary: Create Aws Secret Reference
      description: Create a custom secret whose values live in AWS Secrets Manager.
      operationId: secrets-create_aws_secret_reference
      parameters:
        - name: workspace_id
          in: path
          required: true
          schema:
            type: string
            format: uuid
            title: Workspace Id
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AwsSecretReferenceCreate'
      responses:
        '201':
          description: Successful Response
          content:
            application/json:
              schema: {}
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
      security:
        - APIKeyCookie: []
        - ServiceAccountApiKeyBearer: []
components:
  schemas:
    AwsSecretReferenceCreate:
      properties:
        name:
          type: string
          maxLength: 100
          pattern: ^[a-z_][a-z0-9_]*$
          title: Name
        description:
          anyOf:
            - type: string
              maxLength: 255
              minLength: 0
            - type: 'null'
          title: Description
        environment:
          type: string
          maxLength: 100
          minLength: 1
          title: Environment
          default: default
        tags:
          anyOf:
            - additionalProperties:
                type: string
              type: object
            - type: 'null'
          title: Tags
        store_id:
          type: string
          format: uuid
          title: Store Id
        remote_reference:
          type: string
          maxLength: 2048
          pattern: >-
            ^(?:arn:aws(?:-[a-z]+)*:secretsmanager:[a-z0-9-]+:\d{12}:secret:[^\s]+|[A-Za-z0-9/_+=.@-]{1,512})$
          title: Remote Reference
        key_mapping:
          $ref: '#/components/schemas/AwsSecretKeyMapping'
      type: object
      required:
        - name
        - store_id
        - remote_reference
        - key_mapping
      title: AwsSecretReferenceCreate
      description: Create a workspace custom secret backed by AWS Secrets Manager.
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    AwsSecretKeyMapping:
      properties:
        mode:
          $ref: '#/components/schemas/AwsSecretMappingMode'
        keys:
          items:
            type: string
            pattern: ^[a-zA-Z_][a-zA-Z0-9_]*$
          type: array
          maxItems: 100
          title: Keys
        fields:
          items:
            $ref: '#/components/schemas/AwsSecretJsonField'
          type: array
          maxItems: 100
          title: Fields
      type: object
      required:
        - mode
      title: AwsSecretKeyMapping
      description: |-
        Declares how a remote AWS secret value maps onto output keys.

        ``whole_string`` maps the entire ``SecretString`` onto exactly one key.
        ``json`` maps selected top-level string fields onto declared keys.
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
        input:
          title: Input
        ctx:
          type: object
          title: Context
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError
    AwsSecretMappingMode:
      type: string
      enum:
        - whole_string
        - json
      title: AwsSecretMappingMode
      description: How an AWS Secrets Manager value maps onto declared secret keys.
    AwsSecretJsonField:
      properties:
        key:
          type: string
          maxLength: 255
          minLength: 1
          pattern: ^[a-zA-Z_][a-zA-Z0-9_]*$
          title: Key
        field:
          type: string
          maxLength: 255
          minLength: 1
          title: Field
      type: object
      required:
        - key
        - field
      title: AwsSecretJsonField
      description: One declared output key sourced from a top-level JSON field.
  securitySchemes:
    APIKeyCookie:
      type: apiKey
      in: cookie
      name: fastapiusersauth
    ServiceAccountApiKeyBearer:
      type: http
      description: Tracecat service account API key.
      scheme: bearer

````