v1

latestOpenAPI 3.0.02026-07-246171,3332.1 MB
v2

post/rotated-secret-create-aws

Request body

api-idstring

API ID to rotate (relevant only for rotator-type=api-key)

api-keystring

API key to rotate (relevant only for rotator-type=api-key)

authentication-credentialsstring

The credentials to connect with use-user-creds/use-target-creds

auto-rotatestring

Whether to automatically rotate every --rotation-interval days, or disable existing automatic rotation [true/false]

aws-regionstring

Aws Region

delete_protectionstring

Protection from accidental deletion of this object [true/false]

descriptionstring

Description of the object

grace-rotationstring

Enable graceful rotation (keep both versions temporarily). When enabled, a new secret version is created while the previous version is kept for the grace period, so both versions exist for a limited time. [true/false]

grace-rotation-hourinteger

The Hour of the grace rotation in UTC

grace-rotation-intervalstring

The number of days to wait before deleting the old key (must be bigger than rotation-interval)

grace-rotation-timingstring

When to create the new version relative to the rotation date [after/before]

input-rulestring[]

Agentic input rule in name=...,rule=... format (e.g. name=rule1,rule=Sanitize input)

item-custom-fieldsobject

Additional custom fields to associate with the item

jsonboolean

Set output format to JSON

keystring

The name of a key that used to encrypt the secret value (if empty, the account default protectionKey key will be used)

lock-during-sra-sessionstring

Lock this secret for read/update while an SRA session is active

max-versionsstring

Set the maximum number of versions, limited by the account settings defaults.

namestring required

Rotated secret name

output-rulestring[]

Agentic output rule in name=...,rule=... format (e.g. name=rule1,rule=Mask secrets)

password-lengthstring

The length of the password to be generated

rotate-after-disconnectstring

StringOrBool accepts JSON strings, booleans, and numbers for backward compatibility with older SDK versions that send boolean values for rotate-after-disconnect.

rotation-event-instring[]

How many days before the rotation of the item would you like to be notified

rotation-hourinteger

The Hour of the rotation in UTC

rotation-intervalstring

The number of days to wait between every automatic key rotation (1-365)

rotator-typestring required

The rotator type. options: [target/api-key]

secure-access-aws-account-idstring

The AWS account id

secure-access-aws-native-cliboolean

The AWS native cli

secure-access-bastion-issuerstring

Deprecated. use secure-access-certificate-issuer

secure-access-certificate-issuerstring

Path to the SSH Certificate Issuer for your Akeyless Secure Access

secure-access-enablestring

Enable/Disable secure remote access [true/false]

tagsstring[]

Add tags attached to this object

target-namestring required

The target name to associate

tokenstring

Authentication token (see /auth and /configure)

uid-tokenstring

The universal identity token, Required only for universal_identity authentication

Response

rotatedSecretCreateAwsResponse wraps response body.

namestring