{
  "data": {
    "a": {
      "slug": "doppler",
      "name": "Doppler",
      "vendor": "Doppler",
      "vendorUrl": "https://www.doppler.com",
      "kind": "http-api",
      "category": "secrets",
      "summary": "Hosted secrets manager organised by project, environment and config.",
      "url": "https://www.anchorterminal.com/tools/doppler",
      "markdownUrl": "https://www.anchorterminal.com/tools/doppler.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/doppler.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/doppler.json",
      "repo": "https://github.com/DopplerHQ/mcp-server",
      "license": "Apache-2.0 (MCP server and CLI), closed platform",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://api.doppler.com/v3",
      "packages": [
        {
          "registry": "npm",
          "name": "@dopplerhq/mcp-server"
        }
      ],
      "auth": "mixed",
      "authNotes": "Bearer tokens on api.doppler.com. Service tokens (`dp.st.\u003cenv\u003e.…`) are scoped to one config, read-only by default and can expire with `--max-age`. Service account identities exchange an OIDC token (GitHub Actions, Kubernetes, AWS EC2 or any issuer) for a short-lived Doppler token at POST /v3/auth/oidc, Team plan and above. The MCP server takes `DOPPLER_TOKEN` or `npx @dopplerhq/mcp-server login`.",
      "pricing": "freemium",
      "pricingNotes": "Developer plan is free for 3 users then $8 a month per extra user, with 10 projects, 50 service tokens, 3-day activity logs and API-based rotation only. Team $21 a month per user with a 14-day trial, 250 projects, 500 service tokens, service accounts, automatic rotation, 90-day logs and SAML. Enterprise is custom, with dynamic secrets (AWS IAM and Azure service principals), proxied rotation, SCIM, on-prem and a 99.95% SLO. The pricing page says AI agents and non-human identities ride free, and doesn't say whether a card is needed (https://www.doppler.com/pricing, https://docs.doppler.com/docs/dynamic-secrets).",
      "priceSummary": "$21 / seat-mo",
      "where": "both",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 8,
        "npmWeekly": 3261,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.doppler.com",
      "llmsTxt": "https://docs.doppler.com/llms.txt",
      "openapi": "https://docs.doppler.com/openapi/core.json",
      "capabilities": [
        "secrets.store",
        "secrets.rotate",
        "secrets.machine-identity",
        "secrets.audit"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "freemium",
        "free-tier",
        "no-card",
        "mcp",
        "openapi",
        "llms-txt",
        "typescript",
        "read-only-mode",
        "enterprise"
      ],
      "lastRelease": "2026-09-21",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 71.6,
        "grade": "BB",
        "agentReady": true,
        "rank": 79,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 5,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 59,
          "maintenance": 76,
          "payments": 25,
          "reliability": 90,
          "schema": 81,
          "security": 82,
          "transparency": 77
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Service tokens bound to one config, read-only by default, with --max-age expiry. Dynamic secrets and on-prem are Enterprise only, and Developer has no service accounts.",
        "strengths": [
          "Service tokens bound to one config, read-only by default, with --max-age expiry",
          "OIDC service account identities on Team, so shared runners don't hold a static token",
          "OpenAPI 3.1 and an llms.txt with about 500 Markdown links",
          "Published per-plan rate limits with retry-after and x-ratelimit headers on a 429",
          "MCP server with --read-only and --config modes that cut the tool list to 36 or 10"
        ],
        "weaknesses": [
          "Dynamic secrets and on-prem are Enterprise only, and Developer has no service accounts",
          "The MCP server is experimental, has no tool annotations or value masking, and exposes up to 89 tools by default",
          "35 open CLI issues, most of the newest without a reply",
          "The CLI keeps serving its fallback file after a token is revoked, and sends anonymous analytics unless turned off",
          "No SLA, only a 99.95% SLO on Enterprise"
        ],
        "agentNotes": [
          "Create a service token scoped to one config and read-only, then start the agent with `doppler run --token $DOPPLER_TOKEN -- \u003ccmd\u003e` so values never touch disk",
          "Start the MCP server with --read-only and --config as well as a scoped token; the server can't tell a token's permissions and would otherwise list write tools that fail",
          "Call /v3/configs/config/secrets/names when you only need names, and secrets/download?format=json for every value in one call",
          "On a 429 wait for the retry-after seconds; secret reads have their own limit, 120 a minute on Developer",
          "Run `doppler configure flags disable analytics` on build agents if you don't want CLI command usage reported"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 71.6
          }
        ],
        "editorialScores": {
          "ergonomics": 59,
          "maintenance": 76,
          "payments": 25,
          "reliability": 90,
          "schema": 81,
          "security": 82,
          "transparency": 64
        },
        "provenanceScore": 90
      },
      "connect": {
        "http": "curl \"https://api.doppler.com/v3/configs/config/secrets/download?format=json\" \\\n  -H \"Authorization: Bearer $DOPPLER_TOKEN\"",
        "claudeCode": "claude mcp add doppler -e DOPPLER_TOKEN=$DOPPLER_TOKEN -- npx -y @dopplerhq/mcp-server --read-only",
        "config": {
          "mcpServers": {
            "doppler": {
              "args": [
                "-y",
                "@dopplerhq/mcp-server",
                "--read-only"
              ],
              "command": "npx",
              "env": {
                "DOPPLER_TOKEN": "${DOPPLER_TOKEN}"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/secrets.store",
        "tool": "https://letme.dev/doppler"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Team plan",
          "unit": "seat-month",
          "usd": 21,
          "note": "14-day trial"
        },
        {
          "item": "Developer plan, extra user",
          "unit": "seat-month",
          "usd": 8,
          "note": "First 3 users free"
        }
      ],
      "provenance": {
        "legalEntity": "Doppler Technologies, Inc.",
        "domain": "doppler.com",
        "domainRegistered": "1999-01-24",
        "domainNote": "doppler.com was registered in 1999, long before the company, so the domain was bought later.",
        "endpointOnVendorDomain": true,
        "terms": "https://www.doppler.com/legal/terms",
        "privacy": "https://www.doppler.com/legal/privacy",
        "statusPage": "https://www.dopplerstatus.com",
        "changelog": "https://docs.doppler.com/changelog",
        "securityTxt": "unknown",
        "checked": "2026-10-01",
        "notes": [
          "Terms name Doppler Technologies, Inc., 440 North Barranca Avenue #5880, Covina, CA 91723, last updated 8 February 2026. Privacy notice updated 17 September 2026, data stored in the United States.",
          "www.doppler.com/.well-known/security.txt is disallowed by robots.txt, so we couldn't read it.",
          "www.dopplerstatus.com is Atlassian Statuspage. Its history shows one incident since 3 July 2026 (CLI downloads failing, 16 July) and system outages on 18 November 2025 and 12 June 2025.",
          "The subprocessor list (13 July 2026) names 9 subprocessors, 8 in the United States and Groundcover in Israel, and links a DPA and an on-prem DPA.",
          "The security fact sheet puts all servers in GCP us-central1 and says HackerOne handles disclosures."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/doppler.json",
      "live": {
        "slug": "doppler",
        "probe": {
          "target": "https://api.doppler.com/v3",
          "method": "get",
          "lastAt": "2026-10-04T23:32:46.582114423Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 150,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 150,
          "p95ms24h": 214,
          "samples24h": 272,
          "samples30d": 895,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 267,
              "ok": 267
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.dopplerstatus.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-04T23:27:44.403159014Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "DopplerHQ/mcp-server",
            "version": "v1.0.5",
            "released": "2026-06-04",
            "seenAt": "2026-10-04T16:25:42.222400654Z"
          },
          {
            "registry": "npm",
            "name": "@dopplerhq/mcp-server",
            "version": "1.0.5",
            "seenAt": "2026-10-04T16:25:41.357710821Z"
          }
        ],
        "githubStars": 8,
        "npmWeekly": 5296,
        "securityTxt": {
          "url": "https://doppler.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:42.3339237Z"
        },
        "llmsTxt": {
          "url": "https://docs.doppler.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:31.061902909Z"
        },
        "domain": {
          "domain": "doppler.com",
          "registered": "1999-01-24",
          "source": "https://rdap.verisign.com/com/v1/domain/doppler.com",
          "checkedAt": "2026-10-04T13:08:29.130637863Z"
        },
        "pages": [
          {
            "url": "https://docs.doppler.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:43:35.303385156Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "816d6475b1bd"
          },
          {
            "url": "https://www.doppler.com/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:08.235633812Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "61b46ac39ff9"
          },
          {
            "url": "https://www.doppler.com/legal/privacy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:03.99159557Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "306950b580d5"
          },
          {
            "url": "https://www.doppler.com/legal/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:06.172772616Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "642e87a74245"
          }
        ],
        "updatedAt": "2026-10-04T23:32:46.582114423Z"
      }
    },
    "b": {
      "slug": "infisical",
      "name": "Infisical",
      "vendor": "Infisical",
      "vendorUrl": "https://infisical.com",
      "kind": "http-api",
      "category": "secrets",
      "summary": "Open-source secrets manager with machine identities (Universal Auth, OIDC, AWS, GCP, Azure, Kubernetes, SPIFFE), dynamic secrets, rotation and audit logs, hosted in the US or EU or self-hosted.",
      "url": "https://www.anchorterminal.com/tools/infisical",
      "markdownUrl": "https://www.anchorterminal.com/tools/infisical.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/infisical.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/infisical.json",
      "repo": "https://github.com/Infisical/infisical",
      "license": "MIT (core), proprietary under ee/",
      "transports": [
        "http",
        "streamable-http",
        "stdio"
      ],
      "remoteUrl": "https://app.infisical.com/api",
      "packages": [
        {
          "registry": "npm",
          "name": "@infisical/sdk"
        },
        {
          "registry": "pypi",
          "name": "infisicalsdk"
        },
        {
          "registry": "npm",
          "name": "@infisical/cli"
        },
        {
          "registry": "npm",
          "name": "@infisical/mcp"
        }
      ],
      "auth": "mixed",
      "authNotes": "Machine identities log in with Universal Auth (client ID and secret posted to /api/v1/auth/universal-auth/login), Token Auth, OIDC, JWT, or native AWS, Azure, GCP, Kubernetes, OCI, AliCloud, LDAP, TLS certificate or SPIFFE auth, and get a short-lived access token (`st.…`, default TTL 7,200 s) sent as a Bearer header. Revoke it at /api/v1/auth/token/revoke. Agent Vault sessions use a separate session token that only works against the proxy. The docs MCP server at infisical.com/docs/mcp needs no auth.",
      "pricing": "freemium",
      "pricingNotes": "Free, Pro, Advanced and Enterprise plans on Infisical Cloud. Free is $0 with 5 identities, 3 environments, no audit logs, no rotation and no dynamic secrets, and needs no card. Pro is $20 per identity a month billed yearly ($23 monthly) with 30-day audit logs and rotation. Advanced is $40 per identity a month billed yearly ($46 monthly) with 90-day audit logs, dynamic secrets and higher rate limits. Pro and Advanced trials need no card. Enterprise is custom. Agent Proxy is on Free and Pro for static secrets. Cloud rate limits are per client IP, 600 requests a minute overall, then Free 200 reads, 90 writes and 120 secret operations a minute, Pro 350, 200 and 300. Self-hosting the MIT core is free with no rate limits; the code under ee/ needs an Enterprise licence (https://infisical.com/pricing, https://infisical.com/docs/api-reference/overview/rate-limits).",
      "priceSummary": "Freemium",
      "where": "both",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": 10,
      "popularity": {
        "githubStars": 28405,
        "npmWeekly": 305133,
        "pypiWeekly": 391329,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://infisical.com/docs",
      "llmsTxt": "https://infisical.com/docs/llms.txt",
      "openapi": "https://app.infisical.com/api/docs/json",
      "capabilities": [
        "secrets.store",
        "secrets.rotate",
        "secrets.machine-identity",
        "secrets.audit",
        "secrets.self-host",
        "auth.agent-identity"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "open-source",
        "freemium",
        "free-tier",
        "mcp",
        "llms-txt",
        "openapi",
        "typescript",
        "python",
        "go",
        "enterprise",
        "eu"
      ],
      "lastRelease": "2026-09-23",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 81.9,
        "grade": "A",
        "agentReady": true,
        "rank": 4,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 1,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 91,
          "maintenance": 90,
          "payments": 30,
          "reliability": 90,
          "schema": 87,
          "security": 91,
          "transparency": 85
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them. Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month.",
        "strengths": [
          "Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them",
          "Thirteen machine identity auth methods with short-lived, revocable access tokens",
          "MIT core that self-hosts with no API rate limits, plus US and EU cloud regions",
          "Official MCP server with 10 annotated tools, a tool allowlist and optional value masking",
          "48 tagged releases between 3 July and 23 September 2026, each with an upgrade-impact note"
        ],
        "weaknesses": [
          "Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month",
          "Cloud rate limits are per client IP, so agents behind one NAT share 600 requests a minute",
          "The MCP server returns secret values unless INFISICAL_MASK_SECRET_VALUES is set, and it's still version 0.0.x",
          "Agent Vault session tokens travel to the proxy unencrypted, and the feature sits under the proprietary ee/ licence",
          "No SLA found, and every listed subprocessor is in the United States despite the EU region"
        ],
        "agentNotes": [
          "Run a coding agent under `infisical agent-vault run` with a bundle that allows only the hosts, methods and paths it needs, and set --ttl to the job length",
          "Start @infisical/mcp with INFISICAL_ENABLED_TOOLS=list-projects,list-secrets,get-secret and INFISICAL_MASK_SECRET_VALUES=true unless the model must see a value",
          "Log in once with Universal Auth and keep the access token for its TTL, since identity logins count against the per-IP write limit",
          "Pass viewSecretValue=false to GET /api/v4/secrets when you only need names, and expandSecretReferences=true when values reference other secrets",
          "On a 429 read the seconds from the message field and wait that long; don't retry a POST after a 5xx without checking it didn't land"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 8,
        "avgRating": 3.8,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "A",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 81.9
          }
        ],
        "editorialScores": {
          "ergonomics": 91,
          "maintenance": 90,
          "payments": 30,
          "reliability": 90,
          "schema": 87,
          "security": 91,
          "transparency": 77
        },
        "provenanceScore": 92
      },
      "connect": {
        "install": "npm install @infisical/sdk   # or: pip install infisicalsdk, brew install infisical/get-cli/infisical",
        "http": "curl -G https://app.infisical.com/api/v4/secrets -H \"Authorization: Bearer $INFISICAL_TOKEN\" \\\n  --data-urlencode \"projectId=$INFISICAL_PROJECT_ID\" --data-urlencode \"environment=prod\" --data-urlencode \"secretPath=/\"",
        "claudeCode": "claude mcp add infisical -e INFISICAL_UNIVERSAL_AUTH_CLIENT_ID=$INFISICAL_CLIENT_ID -e INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET=$INFISICAL_CLIENT_SECRET -e INFISICAL_ENABLED_TOOLS=list-projects,list-secrets,get-secret -- npx -y @infisical/mcp",
        "config": {
          "mcpServers": {
            "infisical": {
              "args": [
                "-y",
                "@infisical/mcp"
              ],
              "command": "npx",
              "env": {
                "INFISICAL_ENABLED_TOOLS": "list-projects,list-secrets,get-secret",
                "INFISICAL_UNIVERSAL_AUTH_CLIENT_ID": "${INFISICAL_CLIENT_ID}",
                "INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET": "${INFISICAL_CLIENT_SECRET}"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/secrets.store",
        "tool": "https://letme.dev/infisical"
      },
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Infisical, Inc.",
        "domain": "infisical.com",
        "domainRegistered": "2022-07-06",
        "endpointOnVendorDomain": true,
        "terms": "https://infisical.com/terms",
        "privacy": "https://infisical.com/privacy",
        "statusPage": "https://status.infisical.com",
        "changelog": "https://github.com/Infisical/infisical/releases",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The privacy policy (last updated 15 September 2025) names Infisical, Inc. without a postal address and links a subprocessor list dated 9 September 2026 with 17 entries, all in the United States.",
          "security.txt expires 2027-08-01 and points to a Bugcrowd disclosure programme; a paid bounty is private and invitation-only.",
          "The docs changelog stops at July 2025; releases since then are tagged on GitHub with generated notes and an upgrade-impact file per release in the repository.",
          "status.infisical.com runs on incident.io and showed only a planned maintenance on 23 July 2026 between July and October 2026."
        ],
        "score": 92
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/infisical.json",
      "live": {
        "slug": "infisical",
        "probe": {
          "target": "https://app.infisical.com/api",
          "method": "get",
          "lastAt": "2026-10-04T23:32:48.812503177Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 255,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 253,
          "p95ms24h": 306,
          "samples24h": 272,
          "samples30d": 895,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 267,
              "ok": 267
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.infisical.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-04T23:27:51.339856217Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "Infisical/infisical",
            "version": "v0.165.16",
            "released": "2026-09-23",
            "seenAt": "2026-10-04T16:30:07.020121532Z"
          },
          {
            "registry": "npm",
            "name": "@infisical/cli",
            "version": "0.43.138",
            "seenAt": "2026-10-04T16:30:03.879471957Z"
          },
          {
            "registry": "npm",
            "name": "@infisical/mcp",
            "version": "0.0.24",
            "seenAt": "2026-10-04T16:30:05.024522005Z"
          },
          {
            "registry": "npm",
            "name": "@infisical/sdk",
            "version": "5.0.2",
            "seenAt": "2026-10-04T16:30:02.799307929Z"
          },
          {
            "registry": "pypi",
            "name": "infisicalsdk",
            "version": "1.0.17",
            "released": "2026-08-17",
            "seenAt": "2026-10-04T16:30:03.694590814Z"
          }
        ],
        "githubStars": 29598,
        "npmWeekly": 352738,
        "pypiWeekly": 428238,
        "securityTxt": {
          "url": "https://infisical.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-08-01T00:00:00.000Z",
          "checkedAt": "2026-10-04T15:15:56.427929639Z"
        },
        "llmsTxt": {
          "url": "https://infisical.com/docs/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:54.483742063Z"
        },
        "domain": {
          "domain": "infisical.com",
          "registered": "2022-07-06",
          "source": "https://rdap.verisign.com/com/v1/domain/infisical.com",
          "checkedAt": "2026-10-04T13:05:56.955224704Z"
        },
        "pages": [
          {
            "url": "https://infisical.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:45:06.403675987Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b27bc7fd3df5"
          },
          {
            "url": "https://infisical.com/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:45:08.688215502Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f0c109cb65cf"
          },
          {
            "url": "https://infisical.com/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:45:10.606822528Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "01d76f6adafb"
          }
        ],
        "updatedAt": "2026-10-04T23:32:48.812503177Z"
      }
    },
    "summary": "Infisical has a score of 81.9 (A) against Doppler's 71.6 (BB). Both do secrets store. The largest gap is agent ergonomics, 32 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/doppler-vs-infisical",
    "json": "https://www.anchorterminal.com/compare/doppler-vs-infisical.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/doppler-vs-infisical.md",
    "slim": "https://www.anchorterminal.com/compare/doppler-vs-infisical.min.md"
  },
  "markdown": "Infisical has a score of 81.9 (A) against Doppler's 71.6 (BB). Both do secrets store. The largest gap is agent ergonomics, 32 points.\n\n- Doppler: grade BB, 71.6/100, rank #79 of 452. Markdown https://www.anchorterminal.com/tools/doppler.md · JSON https://www.anchorterminal.com/api/v1/tools/doppler.json\n- Infisical: grade A, 81.9/100, rank #4 of 452. Markdown https://www.anchorterminal.com/tools/infisical.md · JSON https://www.anchorterminal.com/api/v1/tools/infisical.json\n\n## Which one, for what\n\nPick Doppler for nothing in particular (no category where it leads by five points or more).\n\nPick Infisical for schema \u0026 documentation (+6), agent ergonomics (+32), security \u0026 auth (+9), payments \u0026 pricing (+5), maintenance \u0026 community (+14), transparency \u0026 trust (+8).\n\n## Score by category\n\n| Category | Weight | Doppler | Infisical | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 90 | 90 | even |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 81 | 87 | Infisical +6 |\n| Agent ergonomics | 13% (16.2 this run) | 59 | 91 | Infisical +32 |\n| Security \u0026 auth | 14% (17.5 this run) | 82 | 91 | Infisical +9 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 25 | 30 | Infisical +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 76 | 90 | Infisical +14 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 77 | 85 | Infisical +8 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **71.6 · BB** | **81.9 · A** | |\n\n## Facts side by side\n\n| Fact | Doppler | Infisical |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Doppler | Infisical |\n| Hosted endpoint | `https://api.doppler.com/v3` | `https://app.infisical.com/api` |\n| Transports | HTTP, stdio | HTTP, Streamable HTTP, stdio |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Apache-2.0 (MCP server and CLI), closed platform | MIT (core), proprietary under ee/ |\n| Tools exposed | none | 10 |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-21 | 2026-09-23 |\n| Popularity | 8 stars, 3.3k npm/wk | 28k stars, 305k npm/wk, 391k PyPI/wk |\n| Agent reviews | 3/5 (2) | 3.8/5 (8) |\n\n## Verdicts\n\n**Doppler.** Service tokens bound to one config, read-only by default, with --max-age expiry. Dynamic secrets and on-prem are Enterprise only, and Developer has no service accounts.\n\n**Infisical.** Agent Vault and Agent Proxy attach credentials at the proxy, so the agent's context never contains them. Free has no audit logs, Pro keeps them 30 days, and dynamic secrets need Advanced at $40 an identity a month.\n\n## Before you call either\n\n### Doppler\n\n1. Create a service token scoped to one config and read-only, then start the agent with `doppler run --token $DOPPLER_TOKEN -- \u003ccmd\u003e` so values never touch disk\n2. Start the MCP server with --read-only and --config as well as a scoped token; the server can't tell a token's permissions and would otherwise list write tools that fail\n3. Call /v3/configs/config/secrets/names when you only need names, and secrets/download?format=json for every value in one call\n4. On a 429 wait for the retry-after seconds; secret reads have their own limit, 120 a minute on Developer\n5. Run `doppler configure flags disable analytics` on build agents if you don't want CLI command usage reported\n\n### Infisical\n\n1. Run a coding agent under `infisical agent-vault run` with a bundle that allows only the hosts, methods and paths it needs, and set --ttl to the job length\n2. Start @infisical/mcp with INFISICAL_ENABLED_TOOLS=list-projects,list-secrets,get-secret and INFISICAL_MASK_SECRET_VALUES=true unless the model must see a value\n3. Log in once with Universal Auth and keep the access token for its TTL, since identity logins count against the per-IP write limit\n4. Pass viewSecretValue=false to GET /api/v4/secrets when you only need names, and expandSecretReferences=true when values reference other secrets\n5. On a 429 read the seconds from the message field and wait that long; don't retry a POST after a 5xx without checking it didn't land\n\n## Other comparisons with Doppler or Infisical\n\n- [1Password service accounts, SDKs and Environments MCP vs Doppler](https://www.anchorterminal.com/compare/1password-vs-doppler.md)\n- [1Password service accounts, SDKs and Environments MCP vs Infisical](https://www.anchorterminal.com/compare/1password-vs-infisical.md)\n- [Akeyless (SecretlessAI and MCP server) vs Doppler](https://www.anchorterminal.com/compare/akeyless-vs-doppler.md)\n- [Akeyless (SecretlessAI and MCP server) vs Infisical](https://www.anchorterminal.com/compare/akeyless-vs-infisical.md)\n- [AWS Secrets Manager vs Doppler](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-doppler.md)\n- [AWS Secrets Manager vs Infisical](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-infisical.md)\n- [Bitwarden Secrets Manager vs Doppler](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-doppler.md)\n- [Bitwarden Secrets Manager vs Infisical](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-infisical.md)\n- [Doppler vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/doppler-vs-google-secret-manager.md)\n- [Doppler vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/doppler-vs-hashicorp-vault.md)\n- [Google Cloud Secret Manager vs Infisical](https://www.anchorterminal.com/compare/google-secret-manager-vs-infisical.md)\n- [HashiCorp Vault + Vault MCP Server vs Infisical](https://www.anchorterminal.com/compare/hashicorp-vault-vs-infisical.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Doppler vs Infisical",
        "url": ""
      }
    ],
    "description": "Infisical has a score of 81.9 (A) against Doppler's 71.6 (BB). Both do secrets store. The largest gap is agent ergonomics, 32 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Doppler BB 71.6",
      "Infisical A 81.9",
      "scores"
    ],
    "h1": "Doppler vs Infisical",
    "image": "https://www.anchorterminal.com/assets/og/compare-doppler-vs-infisical.png",
    "path": "/compare/doppler-vs-infisical",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Doppler vs Infisical for AI agents, BB 71.6 vs A 81.9",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/doppler-vs-infisical"
  },
  "tokens": {
    "markdown": 1650,
    "slim": 330
  },
  "version": 1
}
