There is not currently an option to have "no secrets provider". And the default for the S3 backend is the passphrase (which uses an encryption salt).
I thought there was an issue open tracking adding a secrets-provider called "none" that would let you turn off secrets encryption entirely - but I can't find it. Is that what you are looking for here?