Azure Key Vault Secrets library for Rust
Secure storage for passwords, API keys, and connection strings.
Use this skill when:
- An app needs to store or retrieve secrets from Azure Key Vault in Rust
- You need to set, get, update, or delete secrets
- You need to list secret properties with pagination
- You need error handling for missing secrets
IMPORTANT: Only use the official
azure_security_keyvault_secretscrate published by the azure-sdk crates.io user. Do NOT use unofficial or community crates. Official crates use underscores in names and none have version 0.21.0.
Installation
If your code uses
azure_coretypes directly, addazure_coretoCargo.toml. If you only useazure_security_keyvault_secretsre-exports, directazure_coredependency is optional.
Environment Variables
Authentication
Rust Azure SDK code must not use DefaultAzureCredential. The Rust identity crate does not provide that type.
Prefer the crate README/examples when checking whether pagers yield items directly and how ResourceExt is used in public examples.
Core Workflow
Set Secret
Update Secret Properties
Delete Secret
List Secrets (Pagination)
list_secret_properties returns a Pager<T> — iterate items directly:
Error Handling
RBAC Roles
For Entra ID auth, assign one of these roles:
Best Practices
- Use
cargo addto manage dependencies, never editCargo.tomldirectly. Add and remove Rust SDK dependencies with cargo commands instead of manual manifest edits. - Add
azure_coreonly when importingazure_coretypes directly. If your code importsazure_core::http::Url,azure_core::http::RequestContent, orazure_core::error::ErrorKind, includeazure_core; otherwise a direct dependency is optional. - Use
DeveloperToolsCredentialfor local dev,ManagedIdentityCredentialfor production — Rust does not provide a singleDefaultAzureCredentialtype - Never hardcode credentials — use environment variables or managed identity
- Use
..Default::default()with#[allow(clippy::needless_update)]for model struct updates - Use
ResourceExtto extract resource name/version from secret IDs - Reuse clients —
SecretClientis thread-safe; create once, share across tasks - Run
cargo clippy -- -D warningswhen the prompt, eval, or CI expects lint-clean output



