All Products
Search
Document Center

CloudOps Orchestration Service:CreateSecretParameter

Last Updated:Aug 28, 2026

Creates an encryption parameter. Before you call this operation, make sure that you have the permissions to call the CreateSecret operation of Key Management Service (KMS).

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

oos:CreateSecretParameter

create

*secretparameter

acs:oos:{#regionId}:{#accountId}:secretparameter/{#secretparameterName}

  • oos:TLSVersion
None

Request parameters

Parameter

Type

Required

Description

Example

RegionId

string

No

The ID of the region.

cn-hangzhou

Name

string

Yes

The name of the parameter. The name must be 1 to 180 characters in length, and can contain letters, digits, hyphens (-), and underscores (_). It cannot start with ALIYUN, ACS, ALIBABA, ALICLOUD, or OOS.

MySecretParameter

Type

string

No

The type of the parameter. Set the value to Secret.

Secret

Value

string

Yes

The value of the encryption parameter. The value must be 1 to 4096 characters in length.

SecretParameter

Description

string

No

The description of the encryption parameter. The description must be 1 to 200 characters in length.

SecretParameter

KeyId

string

No

The KMS key ID used to encrypt the parameter.

80e9409f-78fa-42ab-84bd-83f40c******

ClientToken

string

No

The client token that is used to ensure the idempotence of the request. You can use the client to generate the token, but you must make sure that the token is unique among different requests. The token can be up to 64 characters in length and can contain letters, digits, hyphens (-), and underscores (_). For more information, see "How to ensure idempotence".

123e4567-e89b-12d3-a456-42665544****

Constraints

string

No

The constraints of the encryption parameter. Default value: null. Valid values:

  • AllowedValues: The value that is allowed for the encryption parameter. It must be an array string.

  • AllowedPattern: The pattern that is allowed for the encryption parameter. It must be a regular expression.

  • MinLength: The minimum length of the encryption parameter.

  • MaxLength: The maximum length of the encryption parameter.

'{''AllowedValues":["secretparameter"],"AllowedPattern":"secretparameter","MinLength":0,"MaxLength":20}'

Tags

object

No

The tags.

{"k1": "v1", "k2": "v2"}

ResourceGroupId

string

No

The ID of the resource group.

rg-acfmxsn4m4******

DKMSInstanceId

string

No

The ID of the KMS instance.

kst-hzz****

Response elements

Element

Type

Description

Example

object

RequestId

string

The ID of the request.

0B419FF3-ABC6-4DF0-95E5-636DC8CBB8AF

Parameter

object

The details of the encryption parameter.

Type

string

The type of the parameter.

Secret

UpdatedDate

string

The time when the encryption parameter was updated.

2020-09-01T09:30:36Z

UpdatedBy

string

The user who updated the encryption parameter.

root(130900000)

KeyId

string

The KMS key ID used to encrypt the parameter.

80e9409f-78fa-42ab-84bd-83f40c******

Tags

object

The tags.

{"k1": "v1", "k2": "v2"}

Description

string

The description of the encryption parameter.

SecretParameter

Constraints

string

The constraints of the encryption parameter.

'{ "AllowedValues": ["secretparameter"], "AllowedPattern": "secretparameter", "MinLength": 0, "MaxLength": 20 }'

ResourceGroupId

string

The ID of the resource group.

rg-acfmxsn4m4******

CreatedBy

string

The user who created the encryption parameter.

root(130900000)

CreatedDate

string

The time when the encryption parameter was created.

2020-09-01T09:30:36Z

ParameterVersion

integer

The version number of the encryption parameter.

1

Name

string

The name of the encryption parameter.

MyParameter

Id

string

The ID of the encryption parameter.

p-0b0fff9919c946xxxxxx

ShareType

string

The share type of the encryption parameter.

Private

DKMSInstanceId

string

The ID of the KMS instance.

kst-hzz****

Examples

Success response

JSON format

{
  "RequestId": "0B419FF3-ABC6-4DF0-95E5-636DC8CBB8AF",
  "Parameter": {
    "Type": "Secret",
    "UpdatedDate": "2020-09-01T09:30:36Z",
    "UpdatedBy": "root(130900000)",
    "KeyId": "80e9409f-78fa-42ab-84bd-83f40c******",
    "Tags": {
      "k1": "v1",
      "k2": "v2"
    },
    "Description": "SecretParameter",
    "Constraints": "'{ \t\"AllowedValues\": [\"secretparameter\"], \t\"AllowedPattern\": \"secretparameter\", \t\"MinLength\": 0, \t\"MaxLength\": 20 }'",
    "ResourceGroupId": "rg-acfmxsn4m4******",
    "CreatedBy": "root(130900000)",
    "CreatedDate": "2020-09-01T09:30:36Z",
    "ParameterVersion": 1,
    "Name": "MyParameter",
    "Id": "p-0b0fff9919c946xxxxxx",
    "ShareType": "Private",
    "DKMSInstanceId": "kst-hzz****"
  }
}

Error codes

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.