Doppler
Secrets management platform for environment variables, configs, branch configs, activity logs, webhooks, and config rollbacks.
Made for engineering teams that sync secrets across environments, audit config changes through logs, clone branch configs, and roll back to a prior version.
Use Doppler with Snow
Snow is a personal AI assistant that builds real apps for you, and they can put Doppler to work.
What Snow can do with Doppler
These are the Doppler operations Snow and the apps you build with it can run. Sign in to choose which ones Snow may run without asking.
Reads32
Look at your data without changing it.
- Download Secrets
Tool to download secrets from a Doppler config in various formats. Use when you need to retrieve all secrets or a subset of secrets from a specific project and config. Supports multiple output formats and name transformations.
- Get Authenticated User Info
Tool to retrieve information about the authenticated user or token. Use when you need to verify authentication status or get details about the current token's workplace and permissions.
- Get Config
Tool to retrieve a specific Doppler config by project and config name. Use when you need to get configuration details for a specific project environment.
- Get Project Details
Tool to retrieve details of a specific Doppler project by its identifier. Use when you need to get project metadata including ID, slug, name, description, and creation timestamp.
- Get Secret
Tool to retrieve a specific secret from a Doppler project config. Use when you need to get the value of a specific secret including its raw and computed values.
- List Doppler Configs
Tool to list configurations from a Doppler project. Use when you need to retrieve all configs or filter by environment. Supports pagination for large result sets.
- List Doppler Projects
Tool to list all Doppler projects in your workspace. Use when you need to retrieve available projects for configuration management or to get project details.
- List Doppler Secrets
Tool to list all secrets for a specific Doppler config within a project. Use when you need to retrieve secret values and metadata. Returns both raw and computed values for each secret, along with visibility settings and optional notes.
- List Environments
Tool to list all environments in a Doppler project. Use when you need to retrieve the environments available in a specific project.
- List Secret Names
Tool to retrieve the list of secret names from a specific Doppler config. Use when you need to list available secret names without their values.
Creates8
Add something new to your account.
- Create Service Token
Tool to create a new service token for a Doppler config. Use when you need to generate API credentials for services to access secrets programmatically. The token grants either read-only or read/write access to the specified config. Store the returned token key securely as it cannot be retrieved later.
- Add Webhook
Tool to create a new webhook for a Doppler project. Use when you need to configure webhook notifications for secret changes or other events in a project. The webhook URL must use HTTPS. Optionally configure authentication, specific configs to monitor, custom payload templates, or request signing secrets.
- Clone Config
Tool to clone a branch config including all its secrets. Use after confirming the source config details.
- Create Config
Tool to create a branch config. Use when you need to programmatically establish a new branch-based configuration for a specified project and environment. The config name MUST start with the environment identifier followed by an underscore (e.g., 'dev_feature' for dev environment). Use after selecting the target project and environment.
- Create Encrypted Share Link
Create a Doppler Share link for an end-to-end encrypted secret. This tool generates a secure, shareable link where the secret is encrypted client-side and decrypted in the recipient's browser, ensuring Doppler never has access to the plaintext. Use this when you need to securely share sensitive information (API keys, passwords, credentials) with controlled expiration. The secret must be pre-encrypted using AES-256-GCM with PBKDF2-SHA256 key derivation before calling this tool. Security features: - End-to-end encryption: Secret is never exposed to Doppler's servers - Configurable expiration: Set limits on views (1-50 or unlimited) and days (1-90) - Password-protected: Recipients must enter the correct password to decrypt
- Create Environment
Create a new environment in a Doppler project. Environments (like dev, staging, prod) organize different configurations within a project. Use this when you need to set up a new deployment environment for secrets management. Each environment requires a unique slug within the project.
- Create Plain Text Share Link
Tool to generate a Doppler Share link by sending a plain text secret. Use when you need to securely share secrets with expiration controls. The secret is not stored in plain text by Doppler; the receive flow is end-to-end encrypted where the encrypted secret is decrypted in the browser.
- Create Project
Tool to create a project. Use when you need to programmatically initialize a new Doppler project after authentication.
Updates13
Change something that is already there.
- Update Doppler Secrets
Tool to update secrets in a Doppler config. Use when you need to create or update secret values in a specific project and config.
- Disable Webhook
Tool to disable an existing Doppler webhook. Use when you need to temporarily stop a webhook from receiving notifications without deleting it.
- Enable Webhook
Tool to enable a previously disabled webhook. Use when you need to reactivate a webhook that was temporarily disabled.
- Lock Config
Lock a Doppler config to prevent it from being renamed or deleted. Locking provides protection against accidental modifications to critical configurations. Use this after confirming the correct project and config identifiers.
- Rename Environment
Rename an environment's display name within a Doppler project. This updates only the human-readable name; the environment slug remains unchanged. Use this when you need to update how an environment appears in the UI without affecting its identifier.
- Rollback Config Log
Tool to rollback a config to a selected log version. Use when needing to undo a specific change by its log ID, after confirming project, config, and log ID.
- Unlock Config
Tool to unlock a config. Use when you need to allow renaming or deletion of a previously locked config.
- Update Config
Rename an existing Doppler config within a project. This action modifies the config's name while preserving all secrets and settings. Before using this action: 1. Use DOPPLER_PROJECTS_LIST to get the project identifier 2. Use DOPPLER_CONFIGS_LIST to verify the config exists and get its current name 3. Ensure the new name is unique within the project Note: Root configs and locked configs cannot be renamed.
- Update Project
Tool to update an existing Doppler project's name or description. Use when you need to rename a project or modify its description after it has been created.
- Update Secret Note
Tool to update a note for a secret in Doppler. Use when you need to add or modify documentation for a specific secret. Notes are stored at the project level and apply across all environments, though a config parameter is required for the API call. Notes help document secret usage, provide context, or store reference links.
Deletes9
Remove something. This often cannot be undone.
- Delete Config
Tool to delete a config permanently. Use when you need to remove a config that is no longer needed.
- Delete Environment
Tool to delete an environment. Use when you need to remove an environment from a project after confirming it's no longer in use.
- Delete Project
Tool to delete a project permanently. Use after confirming irreversible removal.
- Delete Secret
Tool to delete a secret from a Doppler config. Use when you need to permanently remove a secret from a specific project and config.
- Delete Service Token
Tool to delete an existing service token from a Doppler config. Use when you need to revoke or remove a service token that is no longer needed.
- Delete Webhook
Tool to delete an existing webhook. Use when you need to permanently remove a webhook from a project.
- Remove Group Member
Remove a member from a Doppler group. This permanently removes the specified member (workplace_user, group, invite, or service_account) from the group. Requires valid group and member slugs. Returns 204 status code on success.
- Remove Project Member
Tool to remove a member from a project. Use after confirming project slug, member type, and slug.
- Revoke Dynamic Secret Lease
Revoke a dynamic secret lease immediately before its TTL expires. Use this tool when you need to terminate access to a dynamic secret (e.g., AWS IAM user, database credentials) by invalidating its active lease. This is useful for security purposes when access should be revoked before the natural expiration time. Prerequisites: The lease must have been previously issued via the secrets list or download endpoints with include_dynamic_secrets=true.
Related integrations
Ready to put Doppler to work?
Sign up free, build an app by chatting, and connect Doppler in minutes. No credit card required.