---
name: secrets-manager-integrations
title: Integrations for Secrets Manager
description: With IBM Cloud&reg; Secrets Manager, you can save time with platform integrations that help you to dynamically create and retrieve secrets while you work with supported IBM Cloud services.
last-updated: 2026-06-29
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/secrets-manager?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

{:codeblock: .codeblock}
{:screen: .screen}
{:download: .download}
{:external: target="_blank" .external}
{:faq: data-hd-content-type='faq'}
{:gif: data-image-type='gif'}
{:important: .important}
{:note: .note}
{:pre: .pre}
{:tip: .tip}
{:preview: .preview}
{:deprecated: .deprecated}
{:beta: .beta}
{:term: .term}
{:shortdesc: .shortdesc}
{:script: data-hd-video='script'}
{:support: data-reuse='support'}
{:table: .aria-labeledby="caption"}
{:troubleshoot: data-hd-content-type='troubleshoot'}
{:help: data-hd-content-type='help'}
{:tsCauses: .tsCauses}
{:tsResolve: .tsResolve}
{:tsSymptoms: .tsSymptoms}
{:video: .video}
{:step: data-tutorial-type='step'}
{:tutorial: data-hd-content-type='tutorial'}
{:api: .ph data-hd-interface='api'}
{:cli: .ph data-hd-interface='cli'}
{:ui: .ph data-hd-interface='ui'}
{:terraform: .ph data-hd-interface="terraform"}
{:curl: .ph data-hd-programlang='curl'}
{:java: .ph data-hd-programlang='java'}
{:ruby: .ph data-hd-programlang='ruby'}
{:c#: .ph data-hd-programlang='c#'}
{:objectc: .ph data-hd-programlang='Objective C'}
{:python: .ph data-hd-programlang='python'}
{:javascript: .ph data-hd-programlang='javascript'}
{:php: .ph data-hd-programlang='PHP'}
{:swift: .ph data-hd-programlang='swift'}
{:curl: .ph data-hd-programlang='curl'}
{:dotnet-standard: .ph data-hd-programlang='dotnet-standard'}
{:go: .ph data-hd-programlang='go'}
{:unity: .ph data-hd-programlang='unity'}
{:release-note: data-hd-content-type='release-note'}

# Integrations for Secrets Manager
{: #integrations}

With IBM Cloud&reg; Secrets Manager, you can save time with platform integrations that help you to dynamically create and retrieve secrets while you work with supported IBM Cloud services.
{: shortdesc}

## Available integrations
{: #available-integrations}

The following table lists the services that can be authorized to work with Secrets Manager.

| Service | Supports | Description |
| ------------------ | ----------- | ----------- |
| [Application Load Balancer for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-load-balancers&format=markdown)  | Certificates | Centrally manage the SSL/TLS certificates that are required for load balancers to perform SSL offloading tasks. Create an authorization between **VPC Infrastructure Services** and Secrets Manager to give a load balancer access to your certificates. [Learn more about this integration](https://cloud.ibm.com/docs/vpc?topic=vpc-load-balancers&format=markdown). |
| [App Configuration](https://cloud.ibm.com/docs/app-configuration?format=markdown) | All secret types | A property value can be imported from Secrets Manager into the App Configuration service. [Learn more](https://cloud.ibm.com/docs/app-configuration?topic=app-configuration-ac-properties&format=markdown#property-type-secret-reference). |
| [API Connect](https://cloud.ibm.com/docs/apiconnect?topic=apiconnect-getting-started&format=markdown) | Certificates | Store your custom domain certificates in Secrets Manager, then use certificate CRNs to bind with custom domains in API Gateway. |    
| [Catalog management](https://cloud.ibm.com/docs/account?topic=account-create-private-catalog&format=markdown) | Arbitrary secrets | Centrally manage the credentials for software in your private catalogs. [Learn more about this integration](https://cloud.ibm.com/docs/account?topic=account-create-private-catalog&format=markdown). |
| [Continuous Delivery](https://cloud.ibm.com/docs/ContinuousDelivery?topic=ContinuousDelivery-secretsmanager&format=markdown) | Arbitrary secrets  \n IAM credentials | Centrally manage the credentials for your Continuous Delivery toolchain. Create an authorization between **Toolchain** and Secrets Manager to give a toolchain access to your secrets. [Learn more about this integration](https://cloud.ibm.com/docs/ContinuousDelivery?topic=ContinuousDelivery-secretsmanager&format=markdown).  |
| [Event Notifications](https://cloud.ibm.com/docs/event-notifications?format=markdown) | Arbitrary secrets  \n Certificates  \n IAM credentials  \nUser credentials| Send notifications of events in Secrets Manager to other users, or human destinations, by using email, SMS, or other supported delivery channels. [Learn more about this integration](https://cloud.ibm.com/docs/secrets-manager?topic=secrets-manager-event-notifications&format=markdown). |
| [Kubernetes Service](https://cloud.ibm.com/docs/containers?format=markdown) | Arbitrary secrets  \n Certificates  \n IAM credentials  \n Key-value secrets  \nUser credentials | Centrally manage Ingress subdomain certificates and other secrets for your Kubernetes clusters. [Learn more about this integration](https://cloud.ibm.com/docs/containers?topic=containers-secrets-mgr&format=markdown). |
| [Red Hat OpenShift on IBM Cloud](https://cloud.ibm.com/docs/openshift?format=markdown) | Arbitrary secrets  \n Certificates  \n IAM credentials  \n Key-value secrets  \nUser credentials | Centrally manage Ingress subdomain certificates and other secrets for your Red Hat OpenShift on IBM Cloud clusters. [Learn more about this integration](https://cloud.ibm.com/docs/openshift?topic=openshift-ingress-roks4&format=markdown). |
| [Red Hat AI Inference](https://cloud.ibm.com/docs/inference?topic=inference-getting-started&format=markdown) | Arbitrary secrets | Red Hat AI Inference is an open source project created by IBM and Red Hat to be a cost-effective entry point into the world of machine learning. |
| [Schematics](https://cloud.ibm.com/schematics?topic=schematics-getting-started) | Arbitrary secrets | Centrally manage secrets for use in Schematics workspaces. |
| [Direct Link](https://cloud.ibm.com/docs/dl?topic=dl-get-started-with-ibm-cloud-dl&format=markdown) | All secret types | seamlessly connect your on-premises resources to your cloud resources. |
{: caption="Available integrations" caption-side="top"}


## Authorizing an IBM Cloud service to access Secrets Manager
{: #create-authorization}

Typically to authorize a supported IBM Cloud service to access your Secrets Manager instance, you can [create an authorization between the services](https://cloud.ibm.com/docs/iam?topic=iam-serviceauth&format=markdown). Be sure that you have the [**SecretsReader** service role or higher](https://cloud.ibm.com/docs/secrets-manager?topic=secrets-manager-iam&format=markdown) on your Secrets Manager instance.

Be sure to review the documentation of the integrating service for specific instructions. If in doubt, open a support ticket for the integrating service.
{: important}

Follow these instructions when both the integrating service and Secrets Manager are in the same account.

When the integrating service is in another account, create the IAM authorization in the account where Secrets Manager is in, and provide the account ID and instance ID of the integrating service under Source.
{: tip}

1. In the console, click **Manage > Access (IAM)**, and select **Authorizations**.
2. Click **Create**.
3. Select a source account for the authorization.
4. From the **Source service** list, select the service that you want to integrate with Secrets Manager.
5. Specify whether you want the authorization for the source service to apply to all the instances that are associated with the account, only a specific instance, or instances that are only in a specific resource group.
2. From the **Target service** list, select Secrets Manager.
5. Specify whether you want the authorization for the target service to apply to all the instances that are associated with the account, only a specific instance, or instances that are only in a specific resource group.
6. Select the required service access role.

    Some integrations might require a specific role. To understand which service role is needed, see the documentation for the service that you want to integrate with Secrets Manager.
    {: note}

7. Click **Authorize**.

## Next steps
{: #next-steps-integration}

- Start integrating your services with Secrets Manager.
- [Check out this blog](https://www.ibm.com/products/tutorials/unleashing-terraform-for-kubernetes-secret-management-with-ibm-cloud-kubernetes-service-and-secrets-manager){: external} for details about to begin using Terraform for Kubernetes Service secret management with IBM Cloud&reg; Kubernetes Service and Secrets Manager.