Resources · Make integration

AWS KMS/Secrets Make integrationAutomate AWS KMS/Secrets with Make.

Tired of copying secrets into AWS by hand every time another tool produces one? The AWS KMS/Secrets Make integration gives you 6 action modules to create, read, update and remove secrets, check a key and decrypt data. This guide walks you from the connection to a working first scenario.

Verified Trustpilot reviews · AI, automation & growth agency

What you can automate

What can the AWS KMS/Secrets Make integration do for you?

The AWS KMS/Secrets Make integration links your AWS account to Make so a scenario (the automation you build, a chain of modules) can manage secrets and keys without code. Each module is one brick of that chain, and this app brings 6 of them, all actions: they do something when the scenario reaches them.

A secret that lands in AWS instead of a spreadsheet. When another app hands Make a new credential, Create a Secret stores it on the AWS side, so nobody has to paste it into a shared file.

A rotation you can replay. Update a Secret replaces the value of an existing secret, and Remove a Secret retires one when a project closes. Pair them with Get Secrets to read what is there before you touch it.

Encrypted data made readable for the next step. Decrypt Data Using a Key turns encrypted content back into something the following module can use, and Get a Key Info lets you look at a key before relying on it.

What Make does not give you here: the app has no trigger, so something else has to start the scenario, and there is no Make an API Call module to reach features the 6 modules do not cover. Make's own documentation for this app is also limited. If you are still choosing a platform, the n8n vs Make comparison and the Make review set the context, and Make troubleshooting helps when a run fails.

Connect

How do you connect AWS KMS/Secrets to Make?

  1. 01

    Add a module and open the connection

    In your scenario, add any AWS KMS/Secrets module and click Create a connection. A connection is your AWS account linked to Make once, then reused by all 6 modules of the app.

  2. 02

    Name it so you can find it later

    Giving the connection a name is optional, but it pays off the day you link a second AWS account: a label such as the account or environment it points to keeps the list readable.

  3. 03

    Authorize and save

    Follow what Make asks for: either an authorization page, or a key you paste from the AWS side. Then click Save, and the connection appears in the module, ready to use.

First scenario

Your first scenario with AWS KMS/Secrets

GoalWhen another app hands Make a new credential, Make stores it in AWS KMS/Secrets with Create a Secret.

  1. 01

    Create the scenario

    From the Scenarios page, create a new scenario and click the + in the middle of the canvas to place the first module.

  2. 02

    Start from the app that produces the credential

    AWS KMS/Secrets has no trigger, so the first module comes from another app: the form, table or tool where new credentials show up. Pick its trigger and connect that account.

  3. 03

    Add Create a Secret

    Click the + on the right of the first module, search AWS KMS/Secrets and choose Create a Secret. Pick your connection, then map the value coming from the previous module into the fields.

  4. 04

    Test with Run once

    Click Run once. Make runs the scenario one time and shows the bundles each module received (a bundle is one item passed from a module to the next). Use a dummy credential here.

  5. 05

    Schedule and switch it on

    If the first module is a scheduled trigger, open its clock: a new scenario runs every 15 minutes by default. Adjust it if your plan allows, then switch the scenario on so it works without you.

Modules

The 6 AWS KMS/Secrets modules in Make

AWS KMS/Secrets gives you 6 modules. For each one: what it does for you, when to reach for it, and what to watch out for.

AWS KMS/Secrets1

Create a Secret

ActionIn the docs only

Stores a brand new secret in AWS from data your scenario already carries, so the value never has to pass through a chat or a shared document.

When to use it
right after the module of another app that produces a credential, such as a signup form or an onboarding table.
Watch out
Make's documentation does not list this module's fields, so run it once on a test value and read the result before you map real data.
AWS KMS/Secrets2

Decrypt Data Using a Key

ActionIn the docs only

Gives you back readable data from content that was encrypted, so the next module in the scenario can actually work with it.

When to use it
when an earlier step hands you an encrypted value and the following step, a message or a record update, needs the plain version.
Watch out
decrypted output travels on to every later module, so keep the chain short and avoid sending it to a tool where many people can read it.
AWS KMS/Secrets3

Get Secrets

ActionIn the docs only

Reads secrets back from AWS so your scenario can see what is already stored before it creates, changes or removes anything.

When to use it
as a safety check placed just before Update a Secret or Remove a Secret, to confirm you are about to act on the right entry.
Watch out
press Run once and open the bundles to see exactly what the module returns, because the documentation does not describe its output.
AWS KMS/Secrets4

Get a Key Info

ActionIn the docs only

Shows you the details AWS holds about one key, which is handy when you want to know what you are dealing with before a decryption step.

When to use it
in a scenario that decrypts data, to look at the key first and route the flow differently when it is not the one you expect.
Watch out
the documentation does not say which details come back, so check a test run before building filters on them.
AWS KMS/Secrets5

Remove a Secret

ActionIn the docs only

Takes a secret out of AWS once nothing needs it anymore, so the list of stored credentials you review stays short and clean.

When to use it
a contract ends or a tool gets retired in another app, and its credential should go with it.
Watch out
assume it cannot be undone. Put Get Secrets in front of it, so a wrong mapping never deletes an entry you still need.
AWS KMS/Secrets6

Update a Secret

ActionIn the docs only

Replaces the stored value of an existing secret, so a new password or token from another tool reaches AWS without anyone editing it by hand.

When to use it
when an app issues a fresh credential for a service you already keep in AWS, and the old value must be overwritten.
Watch out
the previous value is what your other systems may still use, so update them in the same scenario or right after it.
Need help

Need help automating AWS KMS/Secrets with Make?

A person reads every message.

FAQ

AWS KMS/Secrets and Make: frequent questions

01Is the AWS KMS/Secrets Make integration free?
Yes, AWS KMS/Secrets is a standard app, so it works on Make's Free plan. That plan has limits worth knowing: 2 active scenarios, at least 15 minutes between two scheduled runs, 5 minutes of execution per run, files up to 5 MB and 512 MB of data transfer. Every module that runs uses operations, which is how Make counts usage on your plan. Paid plans (Core, Pro, Teams, Enterprise) lower the interval to 1 minute, remove the cap on active scenarios and allow 40 minutes of execution. Your AWS costs are separate and not covered here.
02What do you need to connect AWS KMS/Secrets to Make?
You need an AWS account and a Make account. Make's documentation for this app lists no specific prerequisites, so the connection follows Make's usual path: add an AWS KMS/Secrets module, click Create a connection, optionally name it, then either authorize Make on a page or paste the key the app provides, and click Save. The connection is then shared by all 6 modules. Because the documentation is limited, test it on a secret that does not matter before you use it on production data.
03Does AWS KMS/Secrets have a real-time trigger in Make?
No, the app has no trigger at all, neither scheduled nor instant. Its 6 modules are all actions, so the scenario has to be started by something else. The usual option is to place a trigger from another app first, for example the tool where new credentials appear, and put the AWS modules after it. You can also start the scenario on Make's schedule, set on the clock of the first module, which runs every 15 minutes by default on a new scenario. Instant behavior then depends on that other app, not on AWS KMS/Secrets.
04What if the AWS KMS/Secrets module you need is missing in Make?
It depends on what you need, since the app offers exactly 6 modules and no Make an API Call module to reach the rest of the service. If your task fits creating, reading, updating or removing a secret, checking a key or decrypting data, those modules cover it. Outside that scope, Make has no generic module for this app, so the work has to go through another app or a different setup. Make's documentation for AWS KMS/Secrets is also limited, and the team at our agency can help you design the workaround.
05Should you use Make or n8n for AWS KMS/Secrets?
It depends on what your scenario needs. On Make, the app is available on every plan, including Free, with 6 action modules and no trigger or generic API module. Many apps also have an n8n node, so the fair test is to compare the operations each tool exposes for this app with the steps you plan to automate. Pick the platform where the modules you need already exist and where your team already builds its other automations. If you are unsure, list those steps first and check them against both catalogs before you build anything.