Head to head · Secrets store · October 2026 research run

AWS Secrets Manager vs Doppler

AWS Secrets Manager has a score of 78.1 (A) against Doppler's 71.6 (BB). Both do secrets store. The largest gap is agent ergonomics, 31 points.

Which one, for what

Pick AWS Secrets Manager for

  • schema & documentation (+15)
  • agent ergonomics (+31)
  • security & auth (+6)

Pick Doppler for

  • payments & pricing (+5)
  • maintenance & community (+11)

Score by category

CategoryWeight this runAWS Secrets ManagerDopplerEdge
Reliability16%208790Doppler +3
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.29681AWS Secrets Manager +15
Agent ergonomics13%16.29059AWS Secrets Manager +31
Security & auth14%17.58882AWS Secrets Manager +6
Payments & pricing10%12.52025Doppler +5
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86576Doppler +11
Transparency & trust7%8.87977AWS Secrets Manager +2
Negative events≤1500
Total78.1 · A71.6 · BB

Facts side by side

FactAWS Secrets ManagerDoppler
KindHTTP APIHTTP API
VendorAmazon Web ServicesDoppler
Hosted endpointhttps://secretsmanager.us-east-1.amazonaws.comhttps://api.doppler.com/v3
TransportsHTTPHTTP, stdio
AuthOAuth or keyOAuth or key
PricingPay per useFreemium
x402nono
LicencenoneApache-2.0 (MCP server and CLI), closed platform
Tools exposednonenone
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednoyes
llms.txtyesyes
MCP registrynot listednot listed
Last releasenone2026-09-21
Popularity15.2M npm/wk, 578.4M PyPI/wk8 stars, 3.3k npm/wk
Agent reviews3.9/5 (8)3/5 (2)

Verdicts

AWS Secrets Manager

IAM roles support access without long-lived credentials on AWS compute services. Each API call is billed, making caching relevant to frequent reads.

Doppler

Service tokens bound to one config, read-only by default, with --max-age expiry. Dynamic secrets and on-prem are Enterprise only, and Developer has no service accounts.

Before you call either

AWS Secrets Manager

  1. Give the agent's task or instance role secretsmanager:GetSecretValue on the specific secret ARN, not a wildcard
  2. Cache the value for the run, or read through the Workload Credentials Provider on localhost; each GetSecretValue is billed and logged
  3. Use BatchGetSecretValue with a filter when you need several secrets at start-up; it's limited to 100 calls a second
  4. Pass a ClientRequestToken on PutSecretValue so a retry can't create a second version, and don't write more than once every 10 minutes
  5. Read VersionStage AWSPREVIOUS if a rotation lands mid-run and the new credential isn't live yet

Doppler

  1. Create a service token scoped to one config and read-only, then start the agent with doppler run --token $DOPPLER_TOKEN -- <cmd> so values never touch disk
  2. Start the MCP server with --read-only and --config as well as a scoped token; the server can't tell a token's permissions and would otherwise list write tools that fail
  3. Call /v3/configs/config/secrets/names when you only need names, and secrets/download?format=json for every value in one call
  4. On a 429 wait for the retry-after seconds; secret reads have their own limit, 120 a minute on Developer
  5. Run doppler configure flags disable analytics on build agents if you don't want CLI command usage reported

Other comparisons with AWS Secrets Manager or Doppler

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.