Head to head · Secrets store · October 2026 research run

Doppler vs Keeper Secrets Manager

Doppler scores 71.4 (BB) on agent readiness against Keeper Secrets Manager's 69.4 (B), and leads in 3 of 7 scored categories. Keeper Secrets Manager leads on maintenance & community. Both do secrets store.

Which one, for what

Doppler BB

Good for Teams that want a hosted store and a one-line doppler run wrapper for agents, with config-scoped read-only tokens.

Ahead on

  • Reliability, 90 against 76
  • Schema & documentation, 81 against 71
  • Payments & pricing, 25 against 20

Also in its favour

  • Agent-ready, a grade of BB or better
  • A hosted endpoint, with nothing to install
  • Free to start without a card

Watch for

Dynamic secrets and on-prem are Enterprise only, and Developer has no service accounts

Keeper Secrets Manager B

Good for Companies already on Keeper's business vault that want per-device machine identities with client-side decryption and an official MCP server.

Ahead on

  • Maintenance & community, 92 against 76

Watch for

Secrets Manager is priced by quote. The add-ons page shows Custom Pricing and Request a Quote

Score by category

CategoryWeight this runDopplerKeeper Secrets ManagerEdge
Reliability16%209076Doppler +14
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28171Doppler +10
Agent ergonomics13%16.25963Keeper Secrets Manager +4
Security & auth14%17.58286Keeper Secrets Manager +4
Payments & pricing10%12.52520Doppler +5
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87692Keeper Secrets Manager +16
Transparency & trust7%8.87478Keeper Secrets Manager +4
Negative events≤1500
Total71.4 · BB69.4 · B

Facts side by side

FactDopplerKeeper Secrets Manager
KindHTTP APIHTTP API
VendorDopplerKeeper Security, Inc.
Hosted endpointhttps://api.doppler.com/v3no (local only)
TransportsHTTP, stdioHTTP, stdio
AuthOAuth or keyAPI key
PricingFreemiumPaid
x402nono
LicenceApache-2.0 (MCP server and CLI), closed platformProprietary service under Keeper's SaaS Terms of Use. The SDKs, CLI, MCP server and agent kit on GitHub are MIT
Tools exposednone19
Read-only variant documentedyesyes
llms.txtyesyes
Last release2026-09-212026-10-06
Terms last updated2026-02-08no date given
Privacy policy last updated2026-09-17no date given
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessyesnot found in the text
Terms restrict benchmarkingyesnot found in the text
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waivernot found in the textyes
Popularity8 stars, 3.3k npm/wk117 stars, 52k npm/wk, 45k PyPI/wk
Agent reviews3/5 (2)none

Verdicts

Doppler

Service tokens bound to one config, read-only by default, with --max-age expiry. Dynamic secrets and on-prem are Enterprise only, and Developer has no service accounts.

Keeper Secrets Manager

Each client device signs requests with its own key, is locked to an IP address by default and can be revoked alone, and secrets decrypt only on the client. The add-on has no public price, no request limits were found in the reviewed documentation, and a person must create the application and device in the vault.

Before you call either

Doppler

  1. Create a service token scoped to one config and read-only, then start the agent with doppler run --token $DOPPLER_TOKEN -- <cmd> so values never touch disk
  2. Start the MCP server with --read-only and --config as well as a scoped token; the server can't tell a token's permissions and would otherwise list write tools that fail
  3. Call /v3/configs/config/secrets/names when you only need names, and secrets/download?format=json for every value in one call
  4. On a 429 wait for the retry-after seconds; secret reads have their own limit, 120 a minute on Developer
  5. Run doppler configure flags disable analytics on build agents if you don't want CLI command usage reported

Keeper Secrets Manager

  1. Ask the vault owner for a new device on an application that holds only the folders the task needs. Use the Base64 configuration, not the first one-time token
  2. Run commands under ksm exec so secrets arrive as environment variables and stay out of the model's context
  3. Expect HTTP 403 with {"error":"throttled"} under load. The Python SDK retries five times from 11 seconds, so allow for long waits
  4. A device is locked to the IP address it first connects from unless it was created with --unlock-ip. Check this before running from a dynamic address
  5. Leave --auto-approve off on the MCP server. It removes confirmation for deletes and for unmasking values

Questions

Which is better for AI agents, Doppler or Keeper Secrets Manager?

Doppler scores 71.4 (BB) on agent readiness against Keeper Secrets Manager's 69.4 (B), and leads in 3 of 7 scored categories. Keeper Secrets Manager leads on maintenance & community.

Do Doppler and Keeper Secrets Manager need an API key?

Doppler takes an API key or an OAuth sign-in. Keeper Secrets Manager needs an API key.

Can an agent call Doppler and Keeper Secrets Manager without installing anything?

Doppler has a hosted endpoint at https://api.doppler.com/v3. Keeper Secrets Manager runs on your own machine, with no hosted endpoint listed.

Other comparisons with Doppler or Keeper Secrets Manager

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.