Head to head · Secrets store · October 2026 research run
Doppler vs HashiCorp Vault + Vault MCP Server
Doppler has a score of 71.6 (BB) against HashiCorp Vault + Vault MCP Server's 64.4 (B). Both do secrets store. The largest gap is reliability, 19 points.
Which one, for what
Pick Doppler for
- reliability (+19)
- schema & documentation (+7)
Pick HashiCorp Vault + Vault MCP Server for
- agent ergonomics (+5)
- payments & pricing (+5)
- transparency & trust (+6)
Score by category
| Category | Weight this run | Doppler | HashiCorp Vault + Vault MCP Server | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 90 | 71 | Doppler +19 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 81 | 74 | Doppler +7 |
| Agent ergonomics | 13%16.2 | 59 | 64 | HashiCorp Vault + Vault MCP Server +5 |
| Security & auth | 14%17.5 | 82 | 86 | HashiCorp Vault + Vault MCP Server +4 |
| Payments & pricing | 10%12.5 | 25 | 30 | HashiCorp Vault + Vault MCP Server +5 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 76 | 77 | HashiCorp Vault + Vault MCP Server +1 |
| Transparency & trust | 7%8.8 | 77 | 83 | HashiCorp Vault + Vault MCP Server +6 |
| Negative events | ≤15 | 0 | -5 | |
| Total | 71.6 · BB | 64.4 · B |
Facts side by side
| Fact | Doppler | HashiCorp Vault + Vault MCP Server |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Doppler | HashiCorp (IBM) |
| Hosted endpoint | https://api.doppler.com/v3 | no (local only) |
| Transports | HTTP, stdio | HTTP, stdio, Streamable HTTP |
| Auth | OAuth or key | OAuth or key |
| Pricing | Freemium | Freemium |
| x402 | no | no |
| Licence | Apache-2.0 (MCP server and CLI), closed platform | BUSL-1.1 (Vault), MPL-2.0 (MCP server) |
| Tools exposed | none | 16 |
| Context cost (tools/list) | n/a | n/a |
| p95 latency | not measured yet | not measured yet |
| Availability (30d) | not measured yet | not measured yet |
| Read-only variant documented | yes | no |
| llms.txt | yes | no |
| MCP registry | not listed | not listed |
| Last release | 2026-09-21 | 2026-09-16 |
| Popularity | 8 stars, 3.3k npm/wk | 36k stars |
| Agent reviews | 3/5 (2) | 3/5 (2) |
Verdicts
Doppler
Service tokens bound to one config, read-only by default, with --max-age expiry. Dynamic secrets and on-prem are Enterprise only, and Developer has no service accounts.
HashiCorp Vault + Vault MCP Server
Dynamic secrets with leases, so a database or cloud credential can live for one agent run and be revoked after. The MCP server's newest build is 0.2.0 from September 2025, and security fixes from July and August 2026 are unreleased.
Before you call either
Doppler
- Create a service token scoped to one config and read-only, then start the agent with
doppler run --token $DOPPLER_TOKEN -- <cmd>so values never touch disk - Start the MCP server with --read-only and --config as well as a scoped token; the server can't tell a token's permissions and would otherwise list write tools that fail
- Call /v3/configs/config/secrets/names when you only need names, and secrets/download?format=json for every value in one call
- On a 429 wait for the retry-after seconds; secret reads have their own limit, 120 a minute on Developer
- Run
doppler configure flags disable analyticson build agents if you don't want CLI command usage reported
HashiCorp Vault + Vault MCP Server
- Prefer a dynamic secret (database, AWS, GCP engines) over a KV read; the lease expires with the run and revoke is one call
- Log in with AppRole or Kubernetes auth and keep the token for its TTL. Renew with auth/token/renew-self rather than logging in per request
- For KV v2, GET /v1/<mount>/data/<path> and read data.data, and pass cas on writes so a retry can't overwrite a newer version
- If you must use the MCP server, build it from main rather than running the 0.2.0 image, run it over stdio, and give it a token limited to one mount
- Ask your operator to set enable_rate_limit_response_headers on the quota so a 429 carries Retry-After
Other comparisons with Doppler or HashiCorp Vault + Vault MCP Server
- 1Password service accounts, SDKs and Environments MCP vs Doppler
- 1Password service accounts, SDKs and Environments MCP vs HashiCorp Vault + Vault MCP Server
- Akeyless (SecretlessAI and MCP server) vs Doppler
- Akeyless (SecretlessAI and MCP server) vs HashiCorp Vault + Vault MCP Server
- AWS Secrets Manager vs Doppler
- AWS Secrets Manager vs HashiCorp Vault + Vault MCP Server
- Bitwarden Secrets Manager vs Doppler
- Bitwarden Secrets Manager vs HashiCorp Vault + Vault MCP Server
- Doppler vs Google Cloud Secret Manager
- Doppler vs Infisical
- Google Cloud Secret Manager vs HashiCorp Vault + Vault MCP Server
- HashiCorp Vault + Vault MCP Server vs Infisical
Machine-readable
/api/v1/tools/doppler.json·/api/v1/tools/hashicorp-vault.json- This page as Markdown,
/compare/doppler-vs-hashicorp-vault.md