Skip to main content

AWS Secrets Manager Python caching client

Build codecov

The AWS Secrets Manager Python caching client enables in-process caching of secrets for Python applications.

Getting Started

Required Prerequisites

To use this client you must have:

  • Python 3.8 or newer. Use of Python versions 3.7 or older are not supported.

  • An Amazon Web Services (AWS) account to access secrets stored in AWS Secrets Manager.

    • To create an AWS account, go to Sign In or Create an AWS Account and then choose I am a new user. Follow the instructions to create an AWS account.

    • To create a secret in AWS Secrets Manager, go to Creating Secrets and follow the instructions on that page.

    • This library makes use of botocore, the low-level core functionality of the boto3 SDK. For more information on boto3 and botocore, please review the AWS SDK for Python and Botocore documentation.

  • For Post-Quantum TLS support, use OpenSSL 3.5 or newer (system-level dependency).

Dependencies

This library requires the following standard dependencies:

  • botocore
  • setuptools_scm
  • setuptools

For development and testing purposes, this library requires the following additional dependencies:

  • pytest
  • pytest-cov
  • pytest-sugar
  • codecov
  • pylint
  • sphinx
  • flake8
  • tox

Please review the requirements.txt and dev-requirements.txt file for specific version requirements.

Installation

Installing the latest release via pip:

$ pip install aws-secretsmanager-caching

Installing the latest development release:

$ git clone https://github.com/aws/aws-secretsmanager-caching-python.git
$ cd aws-secretsmanager-caching-python
$ python setup.py install

Development

Getting Started

Assuming that you have Python and virtualenv installed, set up your environment and install the required dependencies like this instead of the pip install aws_secretsmanager_caching defined above:

$ git clone https://github.com/aws/aws-secretsmanager-caching-python.git
$ cd aws-secretsmanager-caching-python
$ virtualenv venv
...
$ . venv/bin/activate
$ pip install -r requirements.txt -r dev-requirements.txt
$ pip install -e .

NOTE: Please use Ruff for formatting.

Running Tests

You can run tests in all supported Python versions using tox. By default, it will run all of the unit and integration tests, but you can also specify your own arguments to past to pytest.

$ tox # runs integ/unit tests, flake8 tests and pylint tests
$ tox -- test/unit/test_decorators.py # runs specific test file
$ tox -e py37 -- test/integ/ # runs specific test directory

Documentation

You can locally-generate the Sphinx-based documentation via:

$ tox -e docs

Which will subsequently be viewable at file://${CLONE_DIR}/.tox/docs_out/index.html

Usage

Using the client consists of the following steps:

  1. Instantiate the client while optionally passing in a SecretCacheConfig() object to the config parameter. You can also pass in an existing botocore.client.BaseClient client to the client parameter.
  2. Request the secret from the client instance.
import botocore
import botocore.session
from aws_secretsmanager_caching import SecretCache, SecretCacheConfig

client = botocore.session.get_session().create_client('secretsmanager')
cache_config = SecretCacheConfig() # See below for defaults
cache = SecretCache(config=cache_config, client=client)

secret = cache.get_secret_string('mysecret')

Forcing a Refresh

The cache normally refreshes a secret only once secret_refresh_interval seconds have passed since the last refresh (1 hour by default). Within that window get_secret_string() returns the cached value without calling Secrets Manager, so a secret rotated in the meantime will not be picked up until the interval elapses.

refresh_secret_now() fetches the secret from Secrets Manager immediately instead of waiting for that interval, and stores the retrieved value in the cache so subsequent retrievals return it. It returns True if the refresh succeeded, or False if it failed, in which case the previously cached value is kept.

refreshed = cache.refresh_secret_now('mysecret')  # bool
secret = cache.get_secret_string('mysecret')

This call blocks for a few seconds before it retrieves the secret. If a recent refresh failed, the call also waits for the pending retry delay, up to a maximum of 10 seconds.

Cache Configuration

You can configure the cache config object with the following parameters:

  • max_cache_size - The maximum number of secrets to cache. The default value is 1024.
  • exception_retry_delay_base - The number of seconds to wait after an exception is encountered and before retrying the request. The default value is 1.
  • exception_retry_growth_factor - The growth factor to use for calculating the wait time between retries of failed requests. The default value is 2.
  • exception_retry_delay_max - The maximum amount of time in seconds to wait between failed requests. The default value is 3600.
  • default_version_stage - The default version stage to request. The default value is 'AWSCURRENT'
  • secret_refresh_interval - The number of seconds to wait between refreshing cached secret information. The default value is 3600.0.
  • secret_cache_hook - An implementation of the SecretCacheHook abstract class. The default value is None.

Decorators

The library also includes several decorator functions to wrap existing function calls with SecretString-based secrets:

  • @InjectedKeywordedSecretString - This decorator expects the secret id and cache as the first and second arguments, with subsequent arguments mapping a parameter key from the function that is being wrapped to a key in the secret. The secret being retrieved from the cache must contain a SecretString and that string must be JSON-based.
  • @InjectSecretString - This decorator also expects the secret id and cache as the first and second arguments. However, this decorator simply returns the result of the cache lookup directly to the first argument of the wrapped function. The secret does not need to be JSON-based but it must contain a SecretString.
from aws_secretsmanager_caching import SecretCache
from aws_secretsmanager_caching import InjectKeywordedSecretString, InjectSecretString

cache = SecretCache()

@InjectKeywordedSecretString(secret_id='mysecret', cache=cache, func_username='username', func_password='password')
def function_to_be_decorated(func_username, func_password):
    print('Something cool is being done with the func_username and func_password arguments here')
    ...

@InjectSecretString('mysimplesecret', cache)
def function_to_be_decorated(arg1, arg2, arg3):
    # arg1 contains the cache lookup result of the 'mysimplesecret' secret.
    # arg2 and arg3, in this example, must still be passed when calling function_to_be_decorated().

Getting Help

Please use these community resources for getting help:

License

This library is licensed under the Apache 2.0 License.

Metadata

Release files for aws-secretsmanager-caching 1.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for aws-secretsmanager-caching 1.2.0
File Size Uploaded
aws_secretsmanager_caching-1.2.0.tar.gz 31.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for aws-secretsmanager-caching 1.2.0
File Interpreter ABI Platform
aws_secretsmanager_caching-1.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 51.0 kB

Release files / aws_secretsmanager_caching-1.2.0.tar.gz

Download URL aws_secretsmanager_caching-1.2.0.tar.gz
Size 31.8 kB
Tags Source
SHA-256 checksum
How to use checksums
b034ba7154a0b7d975fd25e1bb9805922494b6fd0632e9e117e1abb868f3a06b
BLAKE2b-256 checksum
How to use checksums
5b6ee4613cbb1c4a63e3a373131cc34dc52917dbb6d5bea06ad6214bc2f75b85
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 23, 2026.

Transparency log

Release files / aws_secretsmanager_caching-1.2.0-py3-none-any.whl

Download URL aws_secretsmanager_caching-1.2.0-py3-none-any.whl
Size 19.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c0953195050c9796af1df98e5a629512bcfdd301443bf4c853256c3a827c6e87
BLAKE2b-256 checksum
How to use checksums
f2e0e4844b15a4a969420ed9abe8fbbefd2ea9be144ec2803ccf426e1a6a0e8c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 23, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.2.0 This release

2 release files

1.1.3

2 release files

1.1.2

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page