Security · Concept · 11 min read

KMS vs Secrets Manager, and Why Every Secret Already Uses KMS

KMS vs Secrets Manager reads like a choice between two services. For credentials it is not one: Secrets Manager encrypts every secret with a KMS key, and the real question is whether what you are storing is a key or a password.

Written by Marko Ristic, Editor Updated Sep 17, 2026
256bit AES data key that KMS issues for each change of a secret value
$1a month per KMS key, and AWS managed keys are free
$0.40a month per secret in US East (N. Virginia)
365days, the default period for automatic KMS key rotation
Short answer

AWS KMS holds encryption and signing keys; Secrets Manager holds credentials, and it uses KMS on every secret. KMS keeps keys in FIPS 140-3 Level 3 validated HSMs and never lets them leave unencrypted.

Secrets Manager stores and rotates database credentials, API keys and tokens, and AWS recommends KMS rather than Secrets Manager for encryption keys. Each secret is sealed by envelope encryption: KMS issues a 256-bit AES data key, the secret is encrypted with it, and the encrypted data key is stored beside the secret.

  • KMS holds encryption and signing keys; Secrets Manager holds credentials
  • Every Secrets Manager secret is encrypted through a KMS key
  • Secrets Manager rotates the credential; KMS rotates key material
  • KMS keys cost $1 a month; a secret costs $0.40 a month in US East
  • AWS recommends Secrets Manager, not Parameter Store, for credentials
On this page

What each holdsWhat each service actually holds

The confusion comes from the word secret. An encryption key is secret, and so is a database password, but AWS treats key management and secrets management as different jobs for different AWS services.

AWS KMS holds keys that do cryptographic work. In AWS's own description, AWS Key Management Service makes it easy to create and control the keys used to encrypt and sign your data.

The keys are protected by FIPS 140-3 Security Level 3 validated hardware security modules, and they never leave AWS KMS unencrypted: to use a key, your applications call AWS KMS and the service does the operation. You do not retrieve the key.

AWS Secrets Manager holds values your applications need to read. AWS describes it as helping you manage, retrieve and rotate database credentials, application credentials, OAuth tokens, API keys and other sensitive secrets throughout their lifecycles. The point is centralized secrets management: replace a credential hard-coded in application source with a runtime call that fetches it when needed.

Here the application does retrieve the value, because a database driver needs the actual password. AWS also notes that Secrets Manager has undergone auditing for multiple standards and can be part of a solution when you need compliance certification.

AWS draws the line itself. The AWS Secrets Manager documentation sends other kinds of sensitive data to other AWS services: AWS credentials to IAM, encryption keys to KMS, SSH keys to EC2 Instance Connect, and private keys and certificates to AWS Certificate Manager. If what you have is a key your code encrypts with, AWS's own answer is AWS KMS.

The test is what the value does. If your application sends it to another system to prove who it is, it is a credential and belongs in Secrets Manager. If your application uses it to encrypt, decrypt or sign, it is a key and belongs in AWS KMS, where it never has to leave the key management service at all.

How they connectHow Secrets Manager uses KMS on every secret

This is why kms vs secrets manager is not an either-or decision for anything stored in Secrets Manager.

Envelope encryption, per secret value. AWS Secrets Manager documents that it uses envelope encryption with AWS KMS keys and data keys to protect each secret value. Whenever the value of a secret changes, it requests a new data key from KMS.

The KMS key never touches the secret directly. Secrets Manager uses the KMS key to generate and encrypt a 256-bit AES symmetric data key, and uses that data key to encrypt the secret value.

It encrypts the secret outside KMS with the plaintext data key, removes the plaintext data key from memory, and stores the encrypted copy of the data key in the secret's metadata.

Reading a secret calls KMS. To decrypt, Secrets Manager first sends the encrypted data key to KMS to be decrypted with the KMS key, then uses it to decrypt the secret.

That is why access to a secret is not enough on its own when a customer managed key is involved: the caller also needs access to use the key in AWS KMS.

You choose which KMS key. A secret can use any symmetric encryption customer managed key in the account and Region, or the AWS managed key for Secrets Manager, aws/secretsmanager, which Secrets Manager creates on first use if it does not exist. Secrets Manager supports only symmetric encryption KMS keys.

Different keys for different groups of secrets. AWS notes you might use different KMS keys to set custom permissions for a group of secrets or to audit operations on them separately. That is the practical reason to use a customer managed key for access management: the AWS managed key cannot have its permissions changed.

RotationRotation means two different things

Both services rotate, and the word describes two unrelated operations.

Secrets Manager rotates the credential. AWS defines rotation as periodically updating a secret, in both the secret and the database or service it belongs to.

There are managed rotation, where the service configures and runs rotation for most managed secrets without a Lambda function, managed external secret rotation for secrets held by Secrets Manager partners, and rotation by a Lambda function for other types of secret.

AWS KMS rotates key material, not the key. When automatic rotation is enabled on a customer managed key, AWS KMS generates new cryptographic material, every year by default. The rotation period can be set, and if no value is given the default is 365 days. On-demand rotation is also available and does not change the automatic schedule.

Old data stays readable after KMS rotation. Key rotation changes only the current key material. When you decrypt with a rotated key, KMS automatically uses the material that encrypted that ciphertext, so applications keep working without code changes. The KMS key is the same logical resource however many times its material changes.

Only customer managed keys rotate on your schedule. KMS supports optional automatic and on-demand rotation only for customer managed keys, and automatic rotation only for symmetric encryption keys with key material KMS generated.

Parameter StoreWhere Parameter Store fits

The third service in this conversation is AWS Systems Manager Parameter Store, and AWS's own guidance places it clearly.

SecureString is encrypted with KMS. Parameter Store has String, StringList and SecureString parameter types, and it encrypts SecureString values using KMS.

AWS does not recommend it for credentials. The Parameter Store documentation says to use SecureString for configuration values that need encryption, and for database credentials, API keys or tokens it recommends Secrets Manager instead, citing automatic rotation and cross-Region replication as the reasons.

The practical split across AWS services. Configuration that should not be plain text, such as an endpoint or an account identifier, fits Parameter Store. A credential that should rotate belongs in Secrets Manager. A key that encrypts data belongs in AWS KMS. All three end up relying on AWS KMS for encryption of sensitive values in the cloud.

CostWhat they cost

The prices are simple once you separate what each one charges for. The figures below are AWS's published prices, and the Secrets Manager ones are for US East (N. Virginia).

AWS KMS charges per key and per request. Each KMS key costs $1 a month, prorated hourly, whether symmetric, asymmetric, HMAC or multi-Region. For a key that is rotated automatically or on demand, the first and second rotations each add $1 a month, and the increase stops at the second rotation.

AWS managed keys, such as aws/secretsmanager, cost nothing to create and store. KMS also has a free tier of 20,000 requests a month across all Regions, with some asymmetric operations excluded.

AWS Secrets Manager charges per secret and per call. In US East (N. Virginia) a secret costs $0.40 a month and API calls cost $0.05 per 10,000.

A replica secret in another Region is billed as a distinct secret, secrets stored for less than a month are prorated, and there is no charge for secrets marked for deletion. Rotating a secret creates a new version, and AWS does not charge for new versions.

A secret with a customer managed key pays for both. The secret is billed by Secrets Manager, the key by KMS, and each decryption of the secret makes a KMS request. With the AWS managed key there is no key charge.

PitfallsWhere people go wrong

Storing encryption keys in Secrets Manager. It works, and it means the key leaves protected hardware every time an application reads it. AWS's own guidance sends encryption keys to AWS KMS, where applications ask the key management service to do the operation instead.

Treating KMS as a credential store. KMS does not hand back a stored password. Putting a credential into KMS means encrypting it and storing the ciphertext somewhere else, which rebuilds Secrets Manager badly and without rotation.

Expecting KMS rotation to rotate a password. KMS rotation changes key material that data is encrypted with. It does nothing to a database password, which only changes when Secrets Manager rotation or someone updates it in both places.

Using the AWS managed key and then needing cross-account access. The key policy of an AWS managed key cannot be changed, so a design that later needs another account to read a secret has to move to a customer managed key.

Granting access to the secret but not the key. With a customer managed key, reading a secret needs access to the secret in AWS Secrets Manager and access to use the key for decryption in AWS KMS. Missing the second produces an access error that looks like a Secrets Manager problem.

Hard-coding the credential anyway. The benefit AWS describes is removing credentials from application source. Copying a secret into an environment file at deploy time keeps the storage cost and loses the benefit.

Putting credentials in Parameter Store to save money. AWS's own Parameter Store documentation recommends Secrets Manager for credentials because of rotation and replication. The saving is the cost of not rotating.

EVERY SECRET IN SECRETS MANAGER IS SEALED BY A KMS KEYAWS KMSKMS KEYnever leaves KMS unencryptedNEW DATA KEY, AES-256one per change of secret valueAWS SECRETS MANAGERplaintextSECRET VALUEENCRYPT, THEN WIPE KEYENCRYPTED SECRETENCRYPTED DATA KEYstored in the secret metadatato read a secret, the encrypted data key goes back to KMS to be decrypted
The key never touches the secret. KMS issues a data key, the data key seals the secret outside KMS, and only the sealed data key is kept, which is why reading a secret is also a call to KMS.

ComparisonWhich AWS service holds what

CriterionAWS KMSSecrets ManagerParameter Store
HoldsEncryption and signing keysCredentials and secretsConfiguration values
Returns the stored valueNo, performs the operationYesYes
Uses KMSIs KMSEvery secretSecureString parameters
Built-in rotationKey material, customer managed keysThe credential itselfAWS points to Secrets Manager
Replication across RegionsMulti-Region keysReplica secretsAWS points to Secrets Manager
AWS's own recommendationEncryption keysDatabase credentials, API keys, tokensEncrypted configuration
Price$1 per key per month$0.40 per secret per month, US EastNot covered here

The Returns row is the one that decides most cases: if the application needs the value itself, it is not a KMS key.

FAQFrequently asked questions

What is the difference between AWS KMS and Secrets Manager?

AWS KMS is a key management service: it creates and controls encryption and signing keys and performs cryptographic operations with them without letting the keys leave the service unencrypted. AWS Secrets Manager is a secrets management service: it stores and rotates credentials such as database passwords, API keys and OAuth tokens, and returns them to applications at runtime.

Does Secrets Manager use KMS?

Yes, for every secret. It uses envelope encryption: KMS generates and encrypts a 256-bit AES data key, Secrets Manager encrypts the secret with it, and the encrypted data key is stored in the secret's metadata. A new data key is requested whenever the secret value changes.

Should I store encryption keys in Secrets Manager?

AWS's own documentation recommends KMS for encryption keys. With KMS the application asks the service to encrypt or decrypt and the key never leaves protected hardware unencrypted.

Can I use my own KMS key with Secrets Manager?

Yes. A secret can use any symmetric encryption customer managed key in the same account and Region, or the AWS managed key aws/secretsmanager. Secrets Manager supports only symmetric encryption KMS keys.

How does KMS key rotation work?

For customer managed keys with automatic rotation enabled, KMS generates new key material every 365 days by default or on a period you set, and on demand if you ask. Existing ciphertext still decrypts, because KMS uses the material that encrypted it.

How does Secrets Manager rotation work?

It updates the credential in both the secret and the database or service. Most managed secrets use managed rotation without a Lambda function; other secret types rotate through a Lambda function.

How much does AWS KMS cost?

$1 a month per key, prorated hourly, plus request charges beyond a free tier of 20,000 requests a month. The first and second rotations of a key each add $1 a month, capped at the second. AWS managed keys are free to create and store.

How much does Secrets Manager cost?

In US East (N. Virginia), $0.40 per secret per month and $0.05 per 10,000 API calls. Replica secrets are billed as distinct secrets, and secrets marked for deletion are not charged.

What about Parameter Store SecureString?

It stores configuration values encrypted with KMS. AWS recommends Secrets Manager rather than Parameter Store for database credentials, API keys and tokens, because of rotation and cross-Region replication.

Why do I get access denied reading a secret I have permission to?

If the secret uses a customer managed KMS key, reading it also requires permission to use that key for decryption, because Secrets Manager has to call KMS to decrypt the data key.

Is AWS Secrets Manager the same as HashiCorp Vault?

They overlap on storing and rotating secrets. The broader comparison between a dedicated secrets platform and privileged access management is covered in CyberArk vs HashiCorp Vault.

Which should an MSP use for a client on AWS?

Credentials in AWS Secrets Manager with rotation turned on, encryption keys in AWS KMS, configuration in Parameter Store, and customer managed KMS keys wherever access has to be separated between teams or accounts, which also makes compliance evidence easier to produce. What each encryption algorithm does underneath is the same regardless of which service holds the key.

How do KMS pricing and Secrets Manager pricing differ?

KMS pricing is a monthly charge for each customer managed key plus a charge per batch of API requests, and keys that AWS manages for its own services carry no monthly fee. Secrets Manager pricing is a monthly charge for each stored secret plus a charge per batch of API calls. Check the AWS pricing pages for the current amounts.

Read next · Cryptography Encryption Algorithms, and the Two Families They Fall Into What AES-256, the data key algorithm here, actually does. Open this next11 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.