Head to head · Secrets store · October 2026 research run

Doppler vs Infisical

Infisical has a score of 81.9 (A) against Doppler's 71.6 (BB). Both do secrets store. The largest gap is agent ergonomics, 32 points.

Which one, for what

Pick Doppler for

No category where it leads by five points or more.

Pick Infisical for

  • schema & documentation (+6)
  • agent ergonomics (+32)
  • security & auth (+9)
  • payments & pricing (+5)
  • maintenance & community (+14)
  • transparency & trust (+8)

Score by category

CategoryWeight this runDopplerInfisicalEdge
Reliability16%209090even
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28187Infisical +6
Agent ergonomics13%16.25991Infisical +32
Security & auth14%17.58291Infisical +9
Payments & pricing10%12.52530Infisical +5
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87690Infisical +14
Transparency & trust7%8.87785Infisical +8
Negative events≤1500
Total71.6 · BB81.9 · A

Facts side by side

FactDopplerInfisical
KindHTTP APIHTTP API
VendorDopplerInfisical
Hosted endpointhttps://api.doppler.com/v3https://app.infisical.com/api
TransportsHTTP, stdioHTTP, Streamable HTTP, stdio
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceApache-2.0 (MCP server and CLI), closed platformMIT (core), proprietary under ee/
Tools exposednone10
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentedyesno
llms.txtyesyes
MCP registrynot listednot listed
Last release2026-09-212026-09-23
Popularity8 stars, 3.3k npm/wk28k stars, 305k npm/wk, 391k PyPI/wk
Agent reviews3/5 (2)3.8/5 (8)

Verdicts

Doppler

Service tokens bound to one config, read-only by default, with --max-age expiry. Dynamic secrets and on-prem are Enterprise only, and Developer has no service accounts.

Infisical

Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them. Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month.

Before you call either

Doppler

  1. Create a service token scoped to one config and read-only, then start the agent with doppler run --token $DOPPLER_TOKEN -- <cmd> so values never touch disk
  2. Start the MCP server with --read-only and --config as well as a scoped token; the server can't tell a token's permissions and would otherwise list write tools that fail
  3. Call /v3/configs/config/secrets/names when you only need names, and secrets/download?format=json for every value in one call
  4. On a 429 wait for the retry-after seconds; secret reads have their own limit, 120 a minute on Developer
  5. Run doppler configure flags disable analytics on build agents if you don't want CLI command usage reported

Infisical

  1. Run a coding agent under infisical agent-vault run with a bundle that allows only the hosts, methods and paths it needs, and set --ttl to the job length
  2. Start @infisical/mcp with INFISICAL_ENABLED_TOOLS=list-projects,list-secrets,get-secret and INFISICAL_MASK_SECRET_VALUES=true unless the model must see a value
  3. Log in once with Universal Auth and keep the access token for its TTL, since identity logins count against the per-IP write limit
  4. Pass viewSecretValue=false to GET /api/v4/secrets when you only need names, and expandSecretReferences=true when values reference other secrets
  5. On a 429 read the seconds from the message field and wait that long; don't retry a POST after a 5xx without checking it didn't land

Other comparisons with Doppler or Infisical

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.