Secrets Manager

Use dataikuapi.DSSClient.get_secrets_manager() to obtain a Secrets Manager handle. Secrets are identified by their identifier. A returned dataikuapi.secretsmanager.secretsmanager.DSSSecret exposes its metadata as properties and persists editable properties with dataikuapi.secretsmanager.secretsmanager.DSSSecret.save().

For example, to create and share a local secret:

secrets_manager = client.get_secrets_manager()

secret = secrets_manager.create_local_secret(
    identifier="snowflake-password",
    secret_value="initial-value",
    description="Password used by the Snowflake connection",
)
secret.share_with_user(
    "alice",
    can_use=True,
    can_read=False,
    can_write=True,
).save()

The capability attributes are properties. They indicate what the current authentication context can do with the secret:

secret = secrets_manager.get_secret("snowflake-password")
print(secret.can_use)
print(secret.can_read)
print(secret.can_write)
print(secret.can_admin)

To update metadata, modify the corresponding properties on the secret handle and save it. There is no separate metadata object.

secret.description = "Rotated Snowflake password"
secret.save()

Reading a secret value

Use dataikuapi.secretsmanager.secretsmanager.DSSSecret.get_value() on the generic secret handle to read a value. This is the expected way to access a secret value: it works for both local and vault-backed secrets, and remains valid if the secret has a different backing type on another DSS instance. The caller needs Reveal permission. The optional context is included in the audit event.

secret = secrets_manager.get_secret("snowflake-password")
value = secret.get_value(context={"operation": "connection-test"})

Typed handles are only needed for operations specific to a secret type. For example, use a local-secret handle to rotate a locally stored value:

local_secret = secret.get_as_local_secret()
local_secret.update_value(
    "rotated-value",
    context={"operation": "credential-rotation"},
)

Use a vault-secret handle only when you need to inspect or edit its vault ID, remote secret identifier, or pinned version. Calling a typed-handle method for the wrong backing type raises an error.

If saving metadata or sharing changes would remove the current caller’s effective Admin permission, pass confirm_losing_admin_access=True to dataikuapi.secretsmanager.secretsmanager.DSSSecret.save().

Manager and secret handles

Secret types