Estimating AWS Secrets Manager Cost: A Worksheet
AWS Secrets Manager cost has two main parts: a monthly charge per stored secret and a charge per batch of API calls, with extras for rotation functions, customer-managed encryption keys and cross-region replicas. Multiply your counts by the current rates on the AWS pricing page.
This article doesn't quote rates, since they change. It gives you the formula, the levers that move it, and a worked example with placeholder numbers.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
What goes into the monthly bill?
Build the estimate from five inputs and look up each rate yourself:
- Secrets stored: count every secret in every environment. Development, staging and production copies each count.
- API calls: each retrieval is a call. Multiply calls per service instance by instances by how often each one fetches.
- Rotation: automatic rotation runs a function you pay for separately, and rotation frequency changes how often it runs.
- Encryption keys: secrets are encrypted with a key. The default AWS-managed key is simplest; a customer-managed key in KMS adds its own monthly and request charges.
- Replication: replicating secrets to another region counts as additional stored secrets.
Write the formula in a spreadsheet: (secrets × monthly secret price) + (API calls ÷ 10,000 × price per 10,000 calls) + rotation and key costs.
A worked example with placeholder rates
Say the monthly price is $1 per secret and $0.10 per 10,000 calls. These are round placeholder figures for illustration only, not AWS's real rates, so swap in the current ones.
Suppose you run 20 services in three environments, and each service has 2 secrets per environment. In this example that's 120 secrets, or $120 a month at the placeholder rate. Now the calls. If each of 20 services runs 5 containers that fetch their secrets once at startup and restart 4 times a day in production, that's 400 calls a day, or about 12,000 a month, which is small. Suppose instead the code fetches the secret on every request and serves 10 million requests a month: that's 10 million calls, and at the placeholder rate about $100. The lesson is that call volume, not the number of secrets, usually explains surprises.
How do you lower the cost?
Levers, from easiest to most effort:
- Cache retrieved values in memory for minutes or hours, and fetch at startup instead of per request.
- Group related values into one secret as a JSON document, for example database host, user and password together, so you pay for one secret instead of three.
- Delete secrets for retired services and unused environments. Tag secrets with an owner to make cleanup possible.
- Store non-sensitive configuration in a cheaper parameter store instead of treating everything as a secret.
- Use the default encryption key unless a compliance requirement demands your own.
- Rotate only secrets that benefit from it, and check that the rotation function isn't running more often than needed.
Cost shouldn't override security. Caching is fine, but a cache with no expiry makes rotation ineffective, since running services keep the old value.
When does an outside secrets tool make sense instead?
Pricing models differ. AWS charges by secret and by call. A tool such as Doppler typically prices by users or seats and offers features like syncing secrets across environments and services outside AWS. Which is cheaper depends on how many people and secrets you have, so run your own numbers and confirm current plans in a demo.
Beyond price, ask where your workloads run. If everything is on AWS and you use IAM roles heavily, the native service integrates directly. If you span providers or want developers to manage secrets through a friendlier interface, a dedicated tool may cost less in time. The full comparison is in Doppler vs AWS Secrets Manager for B2B SaaS and HashiCorp Vault vs AWS Secrets Manager vs Doppler.
Which mistakes make the estimate wrong?
Watch for these:
- Counting only production secrets and forgetting that each environment and each region adds to the total.
- Ignoring retry loops. A service that crashes and restarts repeatedly can generate a large number of fetches.
- Forgetting key costs when a customer-managed key is required.
- Overlooking rotation function invocations and logging costs in the same account.
- Optimizing this line item while a single leaked hard-coded credential costs far more.
Review the estimate against the actual bill after a month, and tag secrets so the cost explorer can attribute spend by team.
What Good Looks Like
You can state your secret count, monthly retrievals and rotation schedule, and your estimate matches the bill within a small margin.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Frequently Asked Questions
How is AWS Secrets Manager priced?
It charges a monthly fee per stored secret plus a fee per set of API calls, with separate charges for rotation functions, encryption keys and replicas. Check the current AWS pricing page for exact rates.
What usually makes the bill higher than expected?
Call volume. Fetching a secret on every request, or restart loops that fetch repeatedly, can outweigh storage. Cache values in memory and fetch at startup to keep calls low.
Can I store several values in one secret?
Yes. A secret can hold a JSON document, so database host, user and password can share one secret. That reduces the per-secret charge and simplifies rotation and access policies.
Is Doppler cheaper than AWS Secrets Manager?
It depends. AWS prices by secret and call, while other tools often price by users. Compare with your real counts, and consider integration and workflow benefits along with the subscription cost.
About the numbers
This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.
Related Guides
Doppler or AWS Secrets Manager for a Multi-Cloud SaaS Stack
A criteria-based way for B2B SaaS teams to pick between Doppler and AWS Secrets Manager, based on where your deploys actually run and who audits you.
HashiCorp Vault vs AWS Secrets Manager vs Doppler: Secrets Platforms
Compare Vault, AWS Secrets Manager, and Doppler for secret sprawl prevention, dynamic credential rotation, Kubernetes injection, and SOC 2 audits.
Secrets Management for a Property Manager's Tenant Systems
A checklist for how a commercial or multifamily property manager should handle shared logins and tenant payment integrations before adding a secrets tool.
A Checklist for Secrets Rotation That Doesn't Break Production
A practical checklist for rotating API keys and credentials without downtime, including which secrets to automate and which to handle by hand.
Automating Secrets Rotation So a Leak Isn't a Fire Drill
How to build secrets rotation that runs on a schedule instead of only in response to a leak, and why manual rotation quietly never happens.
Why Secrets Rotation Breaks the Moment You Automate It
Why automated secrets and key rotation tends to fail in production, and the specific failure modes to design around before turning it on.