This would be a great feature! Ref: https://www.vaultproject.io/api/secret/aws#generate-credentials Wiring into the createOrUpdateRole method in the Database class of the BetterCloud java driver might work: https://github.com/BetterCloud/vault-java-driver/blob/master/src/main/java/com/bettercloud/vault/api/database/Database.java#L86