{
  "openapi": "3.0.3",
  "info": {
    "title": "sondahub AWS Secrets Manager sandbox",
    "version": "0.14.2",
    "description": "An independent imitation of AWS Secrets Manager for testing, run by sondahub — not affiliated with or endorsed by Amazon Web Services. No AWS account is involved and nothing is encrypted with a real key.\n\nAuth: AWS Signature Version 4 for the service \"secretsmanager\" in any region. Any access key works and is taken on trust; the published key AKIASONDAHUB000001 / probe-secret has its signature checked, so a signing mistake shows up as InvalidSignatureException. Requests older than 15 minutes are refused, as AWS refuses them.\n\nThe SDKs POST every action to https://api.sondahub.com/sandbox/aws-secrets-manager with X-Amz-Target: secretsmanager.<Action> — set it as the endpoint URL. Each region has its own secrets: the seed account’s answer in every region; what you create lives where you created it.\n\nWrites live in the X-Sondahub-Session token each answer carries: send the newest one back as a header and the next request sees what you made; without it every request starts from the seed account. More at https://sondahub.com/sandboxes/aws-secrets-manager/",
    "contact": {
      "name": "sondahub",
      "url": "https://sondahub.com/sandboxes/aws-secrets-manager/"
    }
  },
  "externalDocs": {
    "description": "The sandbox, in full",
    "url": "https://sondahub.com/sandboxes/aws-secrets-manager/"
  },
  "servers": [
    {
      "url": "https://api.sondahub.com"
    }
  ],
  "security": [
    {
      "awsSigV4": []
    }
  ],
  "tags": [
    {
      "name": "Secrets",
      "description": "Create, read, change, list and delete secrets."
    },
    {
      "name": "Versions",
      "description": "The versions of a secret and their staging labels."
    },
    {
      "name": "Rotation",
      "description": "Rotation: the sandbox plays the rotation function."
    },
    {
      "name": "Policies",
      "description": "Resource policies."
    },
    {
      "name": "Tags",
      "description": "Tags on a secret."
    },
    {
      "name": "Replication",
      "description": "Replicas in other regions: read-only there, in sync with the primary."
    },
    {
      "name": "Passwords",
      "description": "Random passwords."
    }
  ],
  "paths": {
    "/sandbox/aws-secrets-manager/CreateSecret": {
      "post": {
        "tags": [
          "Secrets"
        ],
        "summary": "Create a secret",
        "operationId": "CreateSecret",
        "description": "ResourceExistsException when the name is taken in this region; InvalidRequestException when a secret with this name is scheduled for deletion.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.CreateSecret"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "Name": {
                    "type": "string",
                    "description": "Up to 512 characters: letters, digits and /_+=.@-",
                    "example": "dev/myapp/api-key"
                  },
                  "SecretString": {
                    "type": "string",
                    "description": "The value: text, often JSON. Or SecretBinary (base64), not both.",
                    "example": "{\"api_key\":\"abc123\",\"region\":\"us-east-1\"}"
                  },
                  "SecretBinary": {
                    "type": "string",
                    "description": "A binary value, base64."
                  },
                  "Description": {
                    "type": "string",
                    "description": "Up to 2048 characters.",
                    "example": "An API key for myapp"
                  },
                  "KmsKeyId": {
                    "type": "string",
                    "description": "A KMS key ARN or alias; aws/secretsmanager when left out."
                  },
                  "ClientRequestToken": {
                    "type": "string",
                    "description": "Idempotency token (32–64 characters) and the first version’s id. SDKs fill it in."
                  },
                  "Tags": {
                    "type": "array",
                    "description": "Up to 50 {Key, Value}.",
                    "items": {},
                    "example": [
                      {
                        "Key": "env",
                        "Value": "dev"
                      }
                    ]
                  },
                  "AddReplicaRegions": {
                    "type": "array",
                    "description": "{Region, KmsKeyId} to replicate to.",
                    "items": {}
                  },
                  "ForceOverwriteReplicaSecret": {
                    "type": "boolean",
                    "description": "Overwrite a secret of the same name in a replica region."
                  }
                },
                "required": [
                  "Name"
                ],
                "example": {
                  "Name": "dev/myapp/api-key",
                  "Description": "An API key for myapp",
                  "SecretString": "{\"api_key\":\"abc123\",\"region\":\"us-east-1\"}",
                  "Tags": [
                    {
                      "Key": "env",
                      "Value": "dev"
                    }
                  ]
                }
              },
              "example": {
                "Name": "dev/myapp/api-key",
                "Description": "An API key for myapp",
                "SecretString": "{\"api_key\":\"abc123\",\"region\":\"us-east-1\"}",
                "Tags": [
                  {
                    "Key": "env",
                    "Value": "dev"
                  }
                ]
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/GetSecretValue": {
      "post": {
        "tags": [
          "Secrets"
        ],
        "summary": "Read a secret’s value",
        "operationId": "GetSecretValue",
        "description": "The AWSCURRENT version unless VersionId or VersionStage says otherwise. A secret scheduled for deletion answers InvalidRequestException.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.GetSecretValue"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "SecretId": {
                    "type": "string",
                    "description": "Name, ARN, or ARN without the six-character suffix.",
                    "example": "prod/payments/stripe"
                  },
                  "VersionId": {
                    "type": "string",
                    "description": "One version, by id."
                  },
                  "VersionStage": {
                    "type": "string",
                    "description": "One version, by label: AWSCURRENT (the default), AWSPREVIOUS, AWSPENDING or yours."
                  }
                },
                "required": [
                  "SecretId"
                ],
                "example": {
                  "SecretId": "prod/payments/stripe"
                }
              },
              "example": {
                "SecretId": "prod/payments/stripe"
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/BatchGetSecretValue": {
      "post": {
        "tags": [
          "Secrets"
        ],
        "summary": "Read several secrets at once",
        "operationId": "BatchGetSecretValue",
        "description": "The AWSCURRENT value of each; the ones that can’t be read come back in Errors instead of failing the call.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.BatchGetSecretValue"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": false,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "SecretIdList": {
                    "type": "array",
                    "description": "Up to 20 names or ARNs — or Filters, not both.",
                    "items": {},
                    "example": [
                      "prod/payments/stripe",
                      "dev/app/feature-flags"
                    ]
                  },
                  "Filters": {
                    "type": "array",
                    "description": "As ListSecrets; then MaxResults and NextToken page.",
                    "items": {}
                  },
                  "MaxResults": {
                    "type": "integer",
                    "description": "1–20, with Filters."
                  },
                  "NextToken": {
                    "type": "string",
                    "description": "From the previous page."
                  }
                },
                "example": {
                  "SecretIdList": [
                    "prod/payments/stripe",
                    "dev/app/feature-flags",
                    "no/such/secret"
                  ]
                }
              },
              "example": {
                "SecretIdList": [
                  "prod/payments/stripe",
                  "dev/app/feature-flags",
                  "no/such/secret"
                ]
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/DescribeSecret": {
      "post": {
        "tags": [
          "Secrets"
        ],
        "summary": "Describe a secret",
        "operationId": "DescribeSecret",
        "description": "Everything but the value: rotation, versions and their labels, tags, dates, replication.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.DescribeSecret"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "SecretId": {
                    "type": "string",
                    "description": "Name or ARN.",
                    "example": "prod/db/orders-postgres"
                  }
                },
                "required": [
                  "SecretId"
                ],
                "example": {
                  "SecretId": "prod/db/orders-postgres"
                }
              },
              "example": {
                "SecretId": "prod/db/orders-postgres"
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/ListSecrets": {
      "post": {
        "tags": [
          "Secrets"
        ],
        "summary": "List secrets",
        "operationId": "ListSecrets",
        "description": "The secrets in the region you signed for: the seed account’s (in every region) and the ones you made there.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.ListSecrets"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": false,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "Filters": {
                    "type": "array",
                    "description": "Key (name, description, tag-key, tag-value, primary-region, owning-service, all) and up to 10 Values — prefix matches; a value starting with ! excludes.",
                    "items": {},
                    "example": [
                      {
                        "Key": "tag-key",
                        "Values": [
                          "env"
                        ]
                      }
                    ]
                  },
                  "IncludePlannedDeletion": {
                    "type": "boolean",
                    "description": "Include secrets scheduled for deletion."
                  },
                  "SortOrder": {
                    "type": "string",
                    "description": "asc or desc, by creation."
                  },
                  "MaxResults": {
                    "type": "integer",
                    "description": "1–100."
                  },
                  "NextToken": {
                    "type": "string",
                    "description": "From the previous page."
                  }
                },
                "example": {
                  "Filters": [
                    {
                      "Key": "name",
                      "Values": [
                        "prod/"
                      ]
                    }
                  ],
                  "MaxResults": 10
                }
              },
              "example": {
                "Filters": [
                  {
                    "Key": "name",
                    "Values": [
                      "prod/"
                    ]
                  }
                ],
                "MaxResults": 10
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/PutSecretValue": {
      "post": {
        "tags": [
          "Secrets"
        ],
        "summary": "Add a new version",
        "operationId": "PutSecretValue",
        "description": "A new version, labeled AWSCURRENT unless VersionStages says otherwise.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.PutSecretValue"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "SecretId": {
                    "type": "string",
                    "description": "Name or ARN.",
                    "example": "dev/app/feature-flags"
                  },
                  "SecretString": {
                    "type": "string",
                    "description": "The new value (or SecretBinary).",
                    "example": "{\"new_checkout\":true,\"dark_mode\":true}"
                  },
                  "ClientRequestToken": {
                    "type": "string",
                    "description": "The new version’s id; the same token with the same value is the same version, with another value a ResourceExistsException."
                  },
                  "VersionStages": {
                    "type": "array",
                    "description": "Labels for the new version; AWSCURRENT when left out — the old AWSCURRENT becomes AWSPREVIOUS.",
                    "items": {}
                  }
                },
                "required": [
                  "SecretId"
                ],
                "example": {
                  "SecretId": "dev/app/feature-flags",
                  "SecretString": "{\"new_checkout\":true,\"dark_mode\":true,\"search_v2\":\"ga\",\"max_cart_items\":50}"
                }
              },
              "example": {
                "SecretId": "dev/app/feature-flags",
                "SecretString": "{\"new_checkout\":true,\"dark_mode\":true,\"search_v2\":\"ga\",\"max_cart_items\":50}"
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/UpdateSecret": {
      "post": {
        "tags": [
          "Secrets"
        ],
        "summary": "Change a secret",
        "operationId": "UpdateSecret",
        "description": "Description and KMS key; a value makes a new AWSCURRENT version, like PutSecretValue.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.UpdateSecret"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "SecretId": {
                    "type": "string",
                    "description": "Name or ARN.",
                    "example": "dev/app/feature-flags"
                  },
                  "Description": {
                    "type": "string",
                    "description": "A new description."
                  },
                  "KmsKeyId": {
                    "type": "string",
                    "description": "Another KMS key for new versions."
                  },
                  "SecretString": {
                    "type": "string",
                    "description": "A new value: a new AWSCURRENT version."
                  },
                  "ClientRequestToken": {
                    "type": "string",
                    "description": "The new version’s id."
                  }
                },
                "required": [
                  "SecretId"
                ],
                "example": {
                  "SecretId": "dev/app/feature-flags",
                  "Description": "Feature flags read at boot (owned by the web team)"
                }
              },
              "example": {
                "SecretId": "dev/app/feature-flags",
                "Description": "Feature flags read at boot (owned by the web team)"
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/DeleteSecret": {
      "post": {
        "tags": [
          "Secrets"
        ],
        "summary": "Delete a secret",
        "operationId": "DeleteSecret",
        "description": "Scheduled for deletion: GetSecretValue refuses it, ListSecrets hides it (IncludePlannedDeletion shows it), and its name can’t be reused until the window ends.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.DeleteSecret"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "SecretId": {
                    "type": "string",
                    "description": "Name or ARN.",
                    "example": "dev/app/feature-flags"
                  },
                  "RecoveryWindowInDays": {
                    "type": "integer",
                    "description": "7–30 (30 when left out): until then RestoreSecret brings it back.",
                    "example": 7
                  },
                  "ForceDeleteWithoutRecovery": {
                    "type": "boolean",
                    "description": "Delete now, no recovery — not with RecoveryWindowInDays."
                  }
                },
                "required": [
                  "SecretId"
                ],
                "example": {
                  "SecretId": "dev/app/feature-flags",
                  "RecoveryWindowInDays": 7
                }
              },
              "example": {
                "SecretId": "dev/app/feature-flags",
                "RecoveryWindowInDays": 7
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/RestoreSecret": {
      "post": {
        "tags": [
          "Secrets"
        ],
        "summary": "Cancel a scheduled deletion",
        "operationId": "RestoreSecret",
        "description": "The seed’s legacy/ftp-password is three days into its 30-day window.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.RestoreSecret"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "SecretId": {
                    "type": "string",
                    "description": "Name or ARN.",
                    "example": "legacy/ftp-password"
                  }
                },
                "required": [
                  "SecretId"
                ],
                "example": {
                  "SecretId": "legacy/ftp-password"
                }
              },
              "example": {
                "SecretId": "legacy/ftp-password"
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/ListSecretVersionIds": {
      "post": {
        "tags": [
          "Versions"
        ],
        "summary": "List a secret’s versions",
        "operationId": "ListSecretVersionIds",
        "description": "Newest first, with their labels.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.ListSecretVersionIds"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "SecretId": {
                    "type": "string",
                    "description": "Name or ARN.",
                    "example": "prod/payments/stripe"
                  },
                  "IncludeDeprecated": {
                    "type": "boolean",
                    "description": "Include versions with no label.",
                    "example": true
                  },
                  "MaxResults": {
                    "type": "integer",
                    "description": "1–100."
                  },
                  "NextToken": {
                    "type": "string",
                    "description": "From the previous page."
                  }
                },
                "required": [
                  "SecretId"
                ],
                "example": {
                  "SecretId": "prod/payments/stripe",
                  "IncludeDeprecated": true
                }
              },
              "example": {
                "SecretId": "prod/payments/stripe",
                "IncludeDeprecated": true
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/UpdateSecretVersionStage": {
      "post": {
        "tags": [
          "Versions"
        ],
        "summary": "Move a staging label",
        "operationId": "UpdateSecretVersionStage",
        "description": "Rolling back is moving AWSCURRENT to the AWSPREVIOUS version: the version that had AWSCURRENT takes AWSPREVIOUS. ListSecretVersionIds gives the ids.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.UpdateSecretVersionStage"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "SecretId": {
                    "type": "string",
                    "description": "Name or ARN.",
                    "example": "prod/payments/stripe"
                  },
                  "VersionStage": {
                    "type": "string",
                    "description": "The label.",
                    "example": "AWSCURRENT"
                  },
                  "RemoveFromVersionId": {
                    "type": "string",
                    "description": "The version that has it now (required when it is attached somewhere)."
                  },
                  "MoveToVersionId": {
                    "type": "string",
                    "description": "The version to put it on."
                  }
                },
                "required": [
                  "SecretId",
                  "VersionStage"
                ],
                "example": {
                  "SecretId": "prod/payments/stripe",
                  "VersionStage": "AWSCURRENT",
                  "RemoveFromVersionId": "<the AWSCURRENT version>",
                  "MoveToVersionId": "<the AWSPREVIOUS version>"
                }
              },
              "example": {
                "SecretId": "prod/payments/stripe",
                "VersionStage": "AWSCURRENT",
                "RemoveFromVersionId": "<the AWSCURRENT version>",
                "MoveToVersionId": "<the AWSPREVIOUS version>"
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/RotateSecret": {
      "post": {
        "tags": [
          "Rotation"
        ],
        "summary": "Rotate a secret",
        "operationId": "RotateSecret",
        "description": "The rotation function’s steps run at once: a new value (a fresh password where the old one was) is made at AWSPENDING, then becomes AWSCURRENT, and the old one AWSPREVIOUS. A schedule is kept and reported; it does not run on its own.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.RotateSecret"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "SecretId": {
                    "type": "string",
                    "description": "Name or ARN.",
                    "example": "prod/db/orders-postgres"
                  },
                  "RotationLambdaARN": {
                    "type": "string",
                    "description": "Any Lambda function ARN: the sandbox runs the four steps itself. A function name with \"fail\" in it stops after createSecret, leaving the new version at AWSPENDING.",
                    "example": "arn:aws:lambda:us-east-1:123456789012:function:my-rotator"
                  },
                  "RotationRules": {
                    "type": "object",
                    "description": "AutomaticallyAfterDays (1–1000) or ScheduleExpression (rate(…) or cron(…)), and Duration (1h–24h).",
                    "example": {
                      "AutomaticallyAfterDays": 30
                    }
                  },
                  "RotateImmediately": {
                    "type": "boolean",
                    "description": "Rotate now (true, the default) or only set the schedule."
                  },
                  "ClientRequestToken": {
                    "type": "string",
                    "description": "The new version’s id."
                  }
                },
                "required": [
                  "SecretId"
                ],
                "example": {
                  "SecretId": "prod/db/orders-postgres"
                }
              },
              "example": {
                "SecretId": "prod/db/orders-postgres"
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/CancelRotateSecret": {
      "post": {
        "tags": [
          "Rotation"
        ],
        "summary": "Turn rotation off",
        "operationId": "CancelRotateSecret",
        "description": "RotationEnabled becomes false; an AWSPENDING version is left where it is, as AWS leaves it.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.CancelRotateSecret"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "SecretId": {
                    "type": "string",
                    "description": "Name or ARN.",
                    "example": "prod/db/orders-postgres"
                  }
                },
                "required": [
                  "SecretId"
                ],
                "example": {
                  "SecretId": "prod/db/orders-postgres"
                }
              },
              "example": {
                "SecretId": "prod/db/orders-postgres"
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/GetResourcePolicy": {
      "post": {
        "tags": [
          "Policies"
        ],
        "summary": "Read a secret’s resource policy",
        "operationId": "GetResourcePolicy",
        "description": "ResourcePolicy is left out when there is none.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.GetResourcePolicy"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "SecretId": {
                    "type": "string",
                    "description": "Name or ARN.",
                    "example": "prod/oauth/google-client"
                  }
                },
                "required": [
                  "SecretId"
                ],
                "example": {
                  "SecretId": "prod/oauth/google-client"
                }
              },
              "example": {
                "SecretId": "prod/oauth/google-client"
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/PutResourcePolicy": {
      "post": {
        "tags": [
          "Policies"
        ],
        "summary": "Attach a resource policy",
        "operationId": "PutResourcePolicy",
        "description": "MalformedPolicyDocumentException for a policy that is not valid.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.PutResourcePolicy"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "SecretId": {
                    "type": "string",
                    "description": "Name or ARN.",
                    "example": "dev/app/feature-flags"
                  },
                  "ResourcePolicy": {
                    "type": "string",
                    "description": "The policy, as JSON text.",
                    "example": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Principal\":{\"AWS\":\"arn:aws:iam::123456789012:role/worker\"},\"Action\":\"secretsmanager:GetSecretValue\",\"Resource\":\"*\"}]}"
                  },
                  "BlockPublicPolicy": {
                    "type": "boolean",
                    "description": "Refuse a policy that grants everyone access (PublicPolicyException)."
                  }
                },
                "required": [
                  "SecretId",
                  "ResourcePolicy"
                ],
                "example": {
                  "SecretId": "dev/app/feature-flags",
                  "ResourcePolicy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Principal\":{\"AWS\":\"arn:aws:iam::123456789012:role/worker\"},\"Action\":\"secretsmanager:GetSecretValue\",\"Resource\":\"*\"}]}",
                  "BlockPublicPolicy": true
                }
              },
              "example": {
                "SecretId": "dev/app/feature-flags",
                "ResourcePolicy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Principal\":{\"AWS\":\"arn:aws:iam::123456789012:role/worker\"},\"Action\":\"secretsmanager:GetSecretValue\",\"Resource\":\"*\"}]}",
                "BlockPublicPolicy": true
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/DeleteResourcePolicy": {
      "post": {
        "tags": [
          "Policies"
        ],
        "summary": "Remove the resource policy",
        "operationId": "DeleteResourcePolicy",
        "description": "Idempotent.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.DeleteResourcePolicy"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "SecretId": {
                    "type": "string",
                    "description": "Name or ARN.",
                    "example": "dev/app/feature-flags"
                  }
                },
                "required": [
                  "SecretId"
                ],
                "example": {
                  "SecretId": "dev/app/feature-flags"
                }
              },
              "example": {
                "SecretId": "dev/app/feature-flags"
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/ValidateResourcePolicy": {
      "post": {
        "tags": [
          "Policies"
        ],
        "summary": "Check a policy without attaching it",
        "operationId": "ValidateResourcePolicy",
        "description": "PolicyValidationPassed and ValidationErrors: syntax, structure, and whether it grants everyone access.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.ValidateResourcePolicy"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "ResourcePolicy": {
                    "type": "string",
                    "description": "The policy, as JSON text.",
                    "example": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Principal\":{\"AWS\":\"arn:aws:iam::123456789012:role/worker\"},\"Action\":\"secretsmanager:GetSecretValue\",\"Resource\":\"*\"}]}"
                  },
                  "SecretId": {
                    "type": "string",
                    "description": "Optionally, the secret it is for."
                  }
                },
                "required": [
                  "ResourcePolicy"
                ],
                "example": {
                  "ResourcePolicy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Principal\":\"*\",\"Action\":\"secretsmanager:GetSecretValue\",\"Resource\":\"*\"}]}"
                }
              },
              "example": {
                "ResourcePolicy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Principal\":\"*\",\"Action\":\"secretsmanager:GetSecretValue\",\"Resource\":\"*\"}]}"
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/TagResource": {
      "post": {
        "tags": [
          "Tags"
        ],
        "summary": "Add or change tags",
        "operationId": "TagResource",
        "description": "An empty answer.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.TagResource"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "SecretId": {
                    "type": "string",
                    "description": "Name or ARN.",
                    "example": "dev/app/feature-flags"
                  },
                  "Tags": {
                    "type": "array",
                    "description": "{Key, Value}; at most 50 on a secret.",
                    "items": {},
                    "example": [
                      {
                        "Key": "owner",
                        "Value": "web-team"
                      }
                    ]
                  }
                },
                "required": [
                  "SecretId",
                  "Tags"
                ],
                "example": {
                  "SecretId": "dev/app/feature-flags",
                  "Tags": [
                    {
                      "Key": "owner",
                      "Value": "web-team"
                    }
                  ]
                }
              },
              "example": {
                "SecretId": "dev/app/feature-flags",
                "Tags": [
                  {
                    "Key": "owner",
                    "Value": "web-team"
                  }
                ]
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/UntagResource": {
      "post": {
        "tags": [
          "Tags"
        ],
        "summary": "Remove tags",
        "operationId": "UntagResource",
        "description": "An empty answer.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.UntagResource"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "SecretId": {
                    "type": "string",
                    "description": "Name or ARN.",
                    "example": "dev/app/feature-flags"
                  },
                  "TagKeys": {
                    "type": "array",
                    "description": "The keys.",
                    "items": {},
                    "example": [
                      "owner"
                    ]
                  }
                },
                "required": [
                  "SecretId",
                  "TagKeys"
                ],
                "example": {
                  "SecretId": "dev/app/feature-flags",
                  "TagKeys": [
                    "owner"
                  ]
                }
              },
              "example": {
                "SecretId": "dev/app/feature-flags",
                "TagKeys": [
                  "owner"
                ]
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/ReplicateSecretToRegions": {
      "post": {
        "tags": [
          "Replication"
        ],
        "summary": "Replicate to other regions",
        "operationId": "ReplicateSecretToRegions",
        "description": "Sign a request for that region and the secret is there, read-only: writes answer InvalidRequestException.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.ReplicateSecretToRegions"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "SecretId": {
                    "type": "string",
                    "description": "Name or ARN.",
                    "example": "dev/app/feature-flags"
                  },
                  "AddReplicaRegions": {
                    "type": "array",
                    "description": "{Region, KmsKeyId}.",
                    "items": {},
                    "example": [
                      {
                        "Region": "eu-west-1"
                      }
                    ]
                  },
                  "ForceOverwriteReplicaSecret": {
                    "type": "boolean",
                    "description": "Overwrite a secret of the same name there."
                  }
                },
                "required": [
                  "SecretId",
                  "AddReplicaRegions"
                ],
                "example": {
                  "SecretId": "dev/app/feature-flags",
                  "AddReplicaRegions": [
                    {
                      "Region": "eu-west-1"
                    }
                  ]
                }
              },
              "example": {
                "SecretId": "dev/app/feature-flags",
                "AddReplicaRegions": [
                  {
                    "Region": "eu-west-1"
                  }
                ]
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/RemoveRegionsFromReplication": {
      "post": {
        "tags": [
          "Replication"
        ],
        "summary": "Stop replicating to regions",
        "operationId": "RemoveRegionsFromReplication",
        "description": "The replicas are deleted.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.RemoveRegionsFromReplication"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "SecretId": {
                    "type": "string",
                    "description": "Name or ARN.",
                    "example": "shared/github/deploy-token"
                  },
                  "RemoveReplicaRegions": {
                    "type": "array",
                    "description": "The regions.",
                    "items": {},
                    "example": [
                      "eu-west-1"
                    ]
                  }
                },
                "required": [
                  "SecretId",
                  "RemoveReplicaRegions"
                ],
                "example": {
                  "SecretId": "shared/github/deploy-token",
                  "RemoveReplicaRegions": [
                    "eu-west-1"
                  ]
                }
              },
              "example": {
                "SecretId": "shared/github/deploy-token",
                "RemoveReplicaRegions": [
                  "eu-west-1"
                ]
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/StopReplicationToReplica": {
      "post": {
        "tags": [
          "Replication"
        ],
        "summary": "Promote a replica",
        "operationId": "StopReplicationToReplica",
        "description": "The replica becomes a standalone secret in its region. Sign this one for eu-west-1.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.StopReplicationToReplica"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": true,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "SecretId": {
                    "type": "string",
                    "description": "The replica’s ARN — call it signed for the replica’s region.",
                    "example": "arn:aws:secretsmanager:eu-west-1:123456789012:secret:shared/github/deploy-token-B38la1"
                  }
                },
                "required": [
                  "SecretId"
                ],
                "example": {
                  "SecretId": "arn:aws:secretsmanager:eu-west-1:123456789012:secret:shared/github/deploy-token-B38la1"
                }
              },
              "example": {
                "SecretId": "arn:aws:secretsmanager:eu-west-1:123456789012:secret:shared/github/deploy-token-B38la1"
              }
            }
          }
        }
      }
    },
    "/sandbox/aws-secrets-manager/GetRandomPassword": {
      "post": {
        "tags": [
          "Passwords"
        ],
        "summary": "Generate a password",
        "operationId": "GetRandomPassword",
        "description": "Random, every time.\n\nThe path's last part is sondahub's label for importing: the sandbox reads X-Amz-Target when it is there, the label when it is not. SDKs POST to /sandbox/aws-secrets-manager itself.",
        "parameters": [
          {
            "name": "X-Amz-Target",
            "in": "header",
            "required": false,
            "description": "The action.",
            "schema": {
              "type": "string"
            },
            "example": "secretsmanager.GetRandomPassword"
          }
        ],
        "responses": {
          "200": {
            "description": "The object.",
            "content": {
              "application/json": {
                "schema": {
                  "type": "object"
                }
              }
            }
          },
          "400": {
            "$ref": "#/components/responses/E400"
          }
        },
        "requestBody": {
          "required": false,
          "content": {
            "application/x-amz-json-1.1": {
              "schema": {
                "type": "object",
                "properties": {
                  "PasswordLength": {
                    "type": "integer",
                    "description": "1–4096 (32 when left out).",
                    "example": 24
                  },
                  "ExcludeCharacters": {
                    "type": "string",
                    "description": "Characters never to use.",
                    "example": "/@\"'\\"
                  },
                  "ExcludeNumbers": {
                    "type": "boolean",
                    "description": ""
                  },
                  "ExcludePunctuation": {
                    "type": "boolean",
                    "description": ""
                  },
                  "ExcludeUppercase": {
                    "type": "boolean",
                    "description": ""
                  },
                  "ExcludeLowercase": {
                    "type": "boolean",
                    "description": ""
                  },
                  "IncludeSpace": {
                    "type": "boolean",
                    "description": ""
                  },
                  "RequireEachIncludedType": {
                    "type": "boolean",
                    "description": "At least one of each type (true when left out)."
                  }
                },
                "example": {
                  "PasswordLength": 24,
                  "ExcludeCharacters": "/@\"'\\"
                }
              },
              "example": {
                "PasswordLength": 24,
                "ExcludeCharacters": "/@\"'\\"
              }
            }
          }
        }
      }
    }
  },
  "components": {
    "securitySchemes": {
      "awsSigV4": {
        "type": "apiKey",
        "in": "header",
        "name": "Authorization",
        "description": "AWS Signature Version 4, service secretsmanager. Access key AKIASONDAHUB000001, secret probe-secret (checked); any other key is accepted unchecked.",
        "x-amazon-apigateway-authtype": "awsSigv4"
      }
    },
    "responses": {
      "E400": {
        "description": "An AWS error: {\"__type\": \"<Exception>\", \"Message\": \"…\"}, with the type in x-amzn-ErrorType.",
        "content": {
          "application/x-amz-json-1.1": {
            "schema": {
              "type": "object",
              "properties": {
                "__type": {
                  "type": "string"
                },
                "Message": {
                  "type": "string"
                }
              }
            }
          }
        }
      }
    }
  }
}