Skip to content
Roboto
Esc
↑↓navigate↵open⌘Jpreview
On this page

roboto.domain.secrets

Submodules

Package Contents

AwsSecretRetrievalLocation

class roboto.domain.secrets.AwsSecretRetrievalLocation(/, **data)#View Source

Bases: pydantic.BaseModel

Information required to retrieve a secret from AWS Secrets Manager.

Parameters

data Any

Attributes

AwsSecretRetrievalLocation.arn

arn str #

ARN of the secret.

AwsSecretRetrievalLocation.store_type

store_type Literal[SecretStoreType] #

Type of secret store. Referenced here explicitly to make deserialization work better.

AwsSecretsManagerAccessCreds

class roboto.domain.secrets.AwsSecretsManagerAccessCreds(/, **data)#View Source

Bases: pydantic.BaseModel

Context required to update a secret in AWS Secrets Manager.

Parameters

data Any

Attributes

AwsSecretsManagerAccessCreds.access_key_id

access_key_id str #

AWS access key ID.

AwsSecretsManagerAccessCreds.region

region str #

AWS region.

AwsSecretsManagerAccessCreds.secret_access_key

secret_access_key str #

AWS secret access key.

AwsSecretsManagerAccessCreds.session_token

session_token str #

AWS session token.

AwsSecretsManagerAccessCreds.store_type

store_type Literal[SecretStoreType] #

Type of secret store. Referenced here explicitly to make deserialization work better.

CreateSecretRequest

class roboto.domain.secrets.CreateSecretRequest(/, **data)#View Source

Bases: pydantic.BaseModel

Request payload for the Create Secret

Parameters

data Any

Attributes

CreateSecretRequest.name

name str #

Name of the secret.

GetSecretAccessCredsResponse

class roboto.domain.secrets.GetSecretAccessCredsResponse(/, **data)#View Source

Bases: pydantic.BaseModel

Response payload for the Update Secret

Parameters

data Any

Attributes

GetSecretAccessCredsResponse.creds

creds SecretAccessCreds = None #

Creds required to update the secret in its underlying data store.

GetSecretAccessCredsResponse.record

The secret whose value is going to be updated.

Secret

class roboto.domain.secrets.Secret(record, roboto_client)#View Source

A secret stored in the Roboto platform’s secret management system.

Secrets provide secure storage for sensitive information like API keys, passwords, and other credentials that can be used by actions during execution. Each secret is scoped to an organization and stored in a secure backend (currently AWS Secrets Manager). The secret’s value is never sent through Roboto’s APIs, providing an additional layer of security.

Secret names are unique within an organization, so a name + org_id combination provides a fully qualified reference to a specific secret.

Secrets cannot be instantiated directly through the constructor. Use the class methods create(), from_name(), or for_org() to create or retrieve secrets.

Secret.create()

classmethod create(name, caller_org_id=None, initial_value=None, roboto_client=None)#View Source

Create a new secret in the Roboto platform.

Creates a new secret with the specified name and optionally sets its initial value. The secret will be stored in the organization’s secure secret store (AWS Secrets Manager).

Parameters

name str

Name of the secret to create. Must be unique within the organization.

caller_org_id Optional[str]

Organization ID where the secret should be created. If not provided, creates the secret in the caller’s organization.

initial_value Optional[str]

Optional initial value to set for the secret. If provided, the secret’s value will be set immediately after creation.

roboto_client Optional[roboto.http.RobotoClient]

HTTP client for API communication. If not provided, uses the default client configuration.

Returns

A new Secret instance representing the created secret.

Raises

The caller is not authorized to create secrets in the specified organization.

A secret with the same name already exists in the organization.

Invalid parameters provided.

Usage

Create a secret without an initial value:

secret = Secret.create(name="api_key", caller_org_id="org_123")
print(secret.name)
# 'api_key'

Create a secret with an initial value:

secret = Secret.create(
    name="database_password", caller_org_id="org_123", initial_value="super_secure_password"
)
print(secret.name)
# 'database_password'

Secret.delete()

delete()#View Source

Delete this secret from the Roboto platform.

Permanently removes the secret and its value from the secure storage backend. This operation cannot be undone.

Raises

The caller is not authorized to delete this secret.

The secret no longer exists.

Return type

None

Usage

Delete a secret:

secret = Secret.from_name("old_api_key")
secret.delete()
# # Secret is now permanently deleted

Secret.for_org()

classmethod for_org(org_id, roboto_client=None)#View Source

Retrieve all secrets belonging to an organization.

Returns a generator that yields all secrets owned by the specified organization. Results are paginated automatically to handle large numbers of secrets efficiently.

Parameters

org_id str

Organization ID whose secrets should be retrieved.

roboto_client Optional[roboto.http.RobotoClient]

HTTP client for API communication. If not provided, uses the default client configuration.

Yields

Secret instances for each secret owned by the organization.

Raises

The caller is not authorized to list secrets in the specified organization.

The specified organization does not exist.

Return type

collections.abc.Generator[Secret, None, None]

Usage

List all secrets in an organization:

secrets = list(Secret.for_org(org_id="org_123"))
for secret in secrets:
    print(f"Secret: {secret.name}")
# Secret: api_key
# Secret: database_password

Process secrets one at a time without loading all into memory:

for secret in Secret.for_org(org_id="org_123"):
    print(f"Processing secret: {secret.name}")
    # Process each secret individually

Secret.from_name()

classmethod from_name(name, org_id=None, roboto_client=None)#View Source

Load an existing secret by name.

Secret names are unique within an organization, so a name + org_id combination provides a fully qualified reference to a specific secret.

Parameters

name str

Name of the secret to retrieve. Must be unique within the organization.

org_id Optional[str]

Organization ID that owns the secret. If not provided, searches in the caller’s organization.

roboto_client Optional[roboto.http.RobotoClient]

HTTP client for API communication. If not provided, uses the default client configuration.

Returns

A Secret instance representing the found secret.

Raises

The caller is not authorized to access the secret.

No secret with the specified name exists in the organization.

Usage

Load a secret from the caller’s organization:

secret = Secret.from_name(name="api_key")
print(secret.name)
# 'api_key'

Load a secret from a specific organization:

secret = Secret.from_name(name="database_password", org_id="org_123")
print(f"{secret.name} in {secret.org_id}")
# 'database_password in org_123'

Secret.from_uri()

classmethod from_uri(uri, roboto_client=None, fallback_org_id=None)#View Source

Load an existing secret by URI.

Parameters

uri str

URI of the secret to retrieve.

roboto_client Optional[roboto.http.RobotoClient]

HTTP client for API communication. If not provided, uses the default client configuration.

fallback_org_id Optional[str]

Default organization ID to use if not provided in the URI.

Returns

A Secret instance representing the found secret.

Raises

The caller is not authorized to access the secret.

No secret with the specified name exists in the organization.

ValueError

The provided URI is not a valid secret URI.

Usage

Load a secret from a URI:

secret = Secret.from_uri("roboto-secret://api_key@org_123")
print(f"{secret.name} in {secret.org_id}")
# 'api_key in org_123'

Load a secret from a URI with a default org ID:

secret = Secret.from_uri("roboto-secret://api_key", fallback_org_id="org_123")
print(f"{secret.name} in {secret.org_id}")
# 'api_key in org_123'

Properties

Secret.name

name str #

Name of the secret.

Secret names are unique within an organization.

Return type: str

Secret.org_id

org_id str #

Organization ID that owns this secret.

Return type: str

Secret.read_value()

read_value()#View Source

Read the value stored in this secret.

Securely retrieves the secret’s value from the underlying secret store (AWS Secrets Manager). The operation uses temporary, scoped credentials to ensure secure access to the secret store.

Returns

pydantic.SecretStr

The secret value as a pydantic.SecretStr.

Raises

The caller is not authorized to read this secret.

The secret no longer exists.

NotImplementedError

The secret uses an unsupported store type.

Usage

Read a secret’s value:

secret = Secret.from_name("api_key")
value = secret.read_value()
print(value.get_secret_value())
# 'super_secret_api_key_value'

Properties

Secret.record

The secret record containing metadata and configuration.

Secret.refresh()

refresh()#View Source

Refresh this secret’s metadata from the Roboto platform.

Updates the secret’s local metadata by fetching the latest information from the server. This is useful to get updated timestamps or other metadata that may have changed since the secret was last loaded.

Returns

This Secret instance with updated metadata.

Raises

The caller is not authorized to access this secret.

The secret no longer exists.

Usage

Refresh a secret’s metadata:

secret = Secret.from_name("api_key")
secret.refresh()
# Secret now has the latest metadata from the server

Properties

Secret.store_type

Type of secret store backend where this secret is stored.

Currently, all secrets are stored in AWS Secrets Manager.

Secret.update_value()

update_value(new_value)#View Source

Update the value stored in this secret.

Securely updates the secret’s value in the underlying secret store (AWS Secrets Manager). The operation uses temporary, scoped credentials to ensure secure access to the secret store.

Parameters

new_value str

The new value to store in the secret.

Returns

This Secret instance for method chaining.

Raises

The caller is not authorized to update this secret.

The secret no longer exists.

NotImplementedError

The secret uses an unsupported store type.

Usage

Update a secret’s value:

secret = Secret.from_name("api_key")
secret.update_value("new_secret_api_key_value")
# Secret value has been updated in the secure store

Chain method calls:

secret = Secret.create(name="temp_key").update_value("initial_value")
print(secret.name)
# 'temp_key'

Properties

Secret.uri

uri str #

URI for this secret.

This URI can be used to reference the secret in other API calls.

Return type: str

SecretAccessCreds

roboto.domain.secrets.SecretAccessCreds#View Source

Union type for all possible secret update contexts.

SecretRecord

class roboto.domain.secrets.SecretRecord(/, **data)#View Source

Bases: pydantic.BaseModel

A wire-transmissible representation of a secret.

Parameters

data Any

Attributes

SecretRecord.created

created datetime.datetime #

Timestamp when the secret was created.

SecretRecord.created_by

created_by str #

RobotoPrincipal which created the secret.

SecretRecord.last_used

last_used datetime.datetime | None = None #

Timestamp when the secret was last used in an action, or None if the secret has never been used.

SecretRecord.location

location SecretRetrievalLocation = None #

Information required to dereference the secret in its specific secret store. This is used in combination with temporary hyper-downscoped access creds to update or retrieve the secret’s value.

SecretRecord.modified

modified datetime.datetime #

Timestamp when the secret was last modified.

SecretRecord.modified_by

modified_by str #

RobotoPrincipal which last modified the secret.

SecretRecord.name

name str #

Name of the secret. Secret names must be unique within an organization.

SecretRecord.org_id

org_id str #

Organization ID that owns the secret.

SecretRecord.store_type

store_type SecretStoreType #

Type of secret store.

SecretStoreType

class roboto.domain.secrets.SecretStoreType#View Source

Bases: roboto.compat.StrEnum

Type of secret store.

Attributes

SecretStoreType.AWS

AWS = 'aws' #

AWS Secrets Manager.

is_secret_uri()

roboto.domain.secrets.is_secret_uri(uri)#View Source

Parameters

uri str

Return type

bool

Was this page helpful?