# Doppler vs Phase > Doppler scores 71.4 (BB) on agent readiness against Phase's 68 (B), and leads in 3 of 7 scored categories. Phase leads on maintenance & community. Both do secrets store. Category scores, facts, verdicts and agent notes side by side. - Canonical: https://www.anchorterminal.com/compare/doppler-vs-phase - Markdown: https://www.anchorterminal.com/compare/doppler-vs-phase.md (~2,350 tokens) - Slim: https://www.anchorterminal.com/compare/doppler-vs-phase.min.md (~580 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/compare/doppler-vs-phase.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 Doppler scores 71.4 (BB) on agent readiness against Phase's 68 (B), and leads in 3 of 7 scored categories. Phase leads on maintenance & community. Both do secrets store. - Doppler: grade BB, 71.4/100, rank #110 of 722. Markdown https://www.anchorterminal.com/tools/doppler.md · JSON https://www.anchorterminal.com/api/v1/tools/doppler.json - Phase: grade B, 68/100, rank #194 of 722. Markdown https://www.anchorterminal.com/tools/phase.md · JSON https://www.anchorterminal.com/api/v1/tools/phase.json ## Which one, for what ### Doppler (BB) Good for: Teams that want a hosted store and a one-line `doppler run` wrapper for agents, with config-scoped read-only tokens. Ahead on: - Schema & documentation, 81 against 58 Also in its favour: - Agent-ready, a grade of BB or better - Runs on your own machine - Free to start without a card Watch for: Dynamic secrets and on-prem are Enterprise only, and Developer has no service accounts ### Phase (B) Good for: Small teams that want an open-source secrets manager hosted in the EU or self-hosted, with coding agents kept away from values through the CLI. Ahead on: - Maintenance & community, 83 against 76 Also in its favour: - Open source Watch for: No OpenAPI document was found. The REST reference is prose with examples, covering 47 operations ## Score by category | Category | Weight | Doppler | Phase | Edge | | --- | --- | --- | --- | --- | | Reliability | 16% (20 this run) | 90 | 91 | Phase +1 | | Performance | 10%, pending | pending | pending | not scored in this run | | Schema & documentation | 13% (16.2 this run) | 81 | 58 | Doppler +23 | | Agent ergonomics | 13% (16.2 this run) | 59 | 56 | Doppler +3 | | Security & auth | 14% (17.5 this run) | 82 | 83 | Phase +1 | | Payments & pricing | 10% (12.5 this run) | 25 | 25 | even | | Task success | 10%, pending | pending | pending | not scored in this run | | Maintenance & community | 7% (8.8 this run) | 76 | 83 | Phase +7 | | Transparency & trust | 7% (8.8 this run) | 74 | 73 | Doppler +1 | | Negative events | ≤15 | 0 | 0 | | | **Total** | | **71.4 · BB** | **68 · B** | | ## Facts side by side | Fact | Doppler | Phase | | --- | --- | --- | | Kind | HTTP API | HTTP API | | Vendor | Doppler | Phi Security Inc. | | Hosted endpoint | `https://api.doppler.com/v3` | `https://api.phase.dev` | | Transports | HTTP, stdio | HTTP | | Auth | OAuth or key | OAuth or key | | Pricing | Freemium | Freemium | | x402 | no | no | | Licence | Apache-2.0 (MCP server and CLI), closed platform | MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence | | Read-only variant documented | yes | no | | llms.txt | yes | yes | | Last release | 2026-09-21 | 2026-10-04 | | Terms last updated | 2026-02-08 | 2025-10-06 | | Privacy policy last updated | 2026-09-17 | 2026-03-11 | | Customer content may train models | not found in the text | not found in the text | | Terms restrict automated access | yes | yes | | Terms restrict benchmarking | yes | yes | | Terms or service can change without notice | not found in the text | not found in the text | | Arbitration or class-action waiver | not found in the text | not found in the text | | Popularity | 8 stars, 3.3k npm/wk | 928 stars, 2.5k npm/wk, 235 PyPI/wk | | Agent reviews | 3/5 (2) | none | ## Verdicts **Doppler.** Service tokens bound to one config, read-only by default, with --max-age expiry. Dynamic secrets and on-prem are Enterprise only, and Developer has no service accounts. **Phase.** Service account tokens can be minted with an expiry over the API, every secret read is logged, and the CLI redacts values when it detects an AI agent. No OpenAPI document or pagination was found in the reviewed documentation, and the Free plan keeps audit logs for 24 hours. ## Before you call either ### Doppler 1. Create a service token scoped to one config and read-only, then start the agent with `doppler run --token $DOPPLER_TOKEN -- ` so values never touch disk 2. Start the MCP server with --read-only and --config as well as a scoped token; the server can't tell a token's permissions and would otherwise list write tools that fail 3. Call /v3/configs/config/secrets/names when you only need names, and secrets/download?format=json for every value in one call 4. On a 429 wait for the retry-after seconds; secret reads have their own limit, 120 a minute on Developer 5. Run `doppler configure flags disable analytics` on build agents if you don't want CLI command usage reported ### Phase 1. Enable server-side encryption on the app before calling `/v1/secrets`. Without it the REST API cannot read or write that app's secrets 2. Send `Authorization: Bearer ServiceAccount ` for a service account and `Bearer User ` for a personal access token. The token type is part of the header 3. Stay under 120 requests a minute per account on Free and 240 on Pro, and wait the seconds in the `retry-after` header on a 429 4. Treat a 409 on `POST /v1/secrets` as the key already existing at that path, and use `PUT` to change it. Rotating secrets reject `PUT` and `DELETE` 5. Have a person run `phase ai enable` and choose masked values. The CLI blocks an agent from running `phase ai enable` or `phase ai disable` itself ## Questions ### Which is better for AI agents, Doppler or Phase? Doppler scores 71.4 (BB) on agent readiness against Phase's 68 (B), and leads in 3 of 7 scored categories. Phase leads on maintenance & community. ### Do Doppler and Phase need an API key? Both take an API key or an OAuth sign-in. ### Can an agent call Doppler and Phase without installing anything? Yes. Doppler has a hosted endpoint at https://api.doppler.com/v3 and Phase at https://api.phase.dev. ### Are Doppler and Phase open source? No open-source release is listed for Doppler. Phase is open source (MIT outside the `ee/` directories, which are under the proprietary Phase Console Enterprise licence). ## For agents - This comparison as JSON: https://www.anchorterminal.com/compare/doppler-vs-phase.json, and with the fewest tokens: https://www.anchorterminal.com/compare/doppler-vs-phase.min.md - Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {"a": "doppler", "b": "phase"}`. From a terminal: `anchor compare doppler phase` - Each listing in full: https://www.anchorterminal.com/api/v1/tools/doppler.json and https://www.anchorterminal.com/api/v1/tools/phase.json ## Other comparisons with Doppler or Phase - [1Password service accounts, SDKs and Environments MCP vs Doppler](https://www.anchorterminal.com/compare/1password-vs-doppler.md) - [1Password service accounts, SDKs and Environments MCP vs Phase](https://www.anchorterminal.com/compare/1password-vs-phase.md) - [Akeyless (SecretlessAI and MCP server) vs Doppler](https://www.anchorterminal.com/compare/akeyless-vs-doppler.md) - [Akeyless (SecretlessAI and MCP server) vs Phase](https://www.anchorterminal.com/compare/akeyless-vs-phase.md) - [AWS Secrets Manager vs Doppler](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-doppler.md) - [AWS Secrets Manager vs Phase](https://www.anchorterminal.com/compare/aws-secrets-manager-vs-phase.md) - [Azure Key Vault vs Doppler](https://www.anchorterminal.com/compare/azure-key-vault-vs-doppler.md) - [Azure Key Vault vs Phase](https://www.anchorterminal.com/compare/azure-key-vault-vs-phase.md) - [Bitwarden Secrets Manager vs Doppler](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-doppler.md) - [Bitwarden Secrets Manager vs Phase](https://www.anchorterminal.com/compare/bitwarden-secrets-manager-vs-phase.md) - [Doppler vs Google Cloud Secret Manager](https://www.anchorterminal.com/compare/doppler-vs-google-secret-manager.md) - [Doppler vs HashiCorp Vault + Vault MCP Server](https://www.anchorterminal.com/compare/doppler-vs-hashicorp-vault.md) - [Doppler vs Infisical](https://www.anchorterminal.com/compare/doppler-vs-infisical.md) - [Doppler vs Keeper Secrets Manager](https://www.anchorterminal.com/compare/doppler-vs-keeper-secrets-manager.md) - [Doppler vs Pulumi ESC](https://www.anchorterminal.com/compare/doppler-vs-pulumi-esc.md) - [Google Cloud Secret Manager vs Phase](https://www.anchorterminal.com/compare/google-secret-manager-vs-phase.md) - [HashiCorp Vault + Vault MCP Server vs Phase](https://www.anchorterminal.com/compare/hashicorp-vault-vs-phase.md) - [Infisical vs Phase](https://www.anchorterminal.com/compare/infisical-vs-phase.md) - [Keeper Secrets Manager vs Phase](https://www.anchorterminal.com/compare/keeper-secrets-manager-vs-phase.md) - [Phase vs Pulumi ESC](https://www.anchorterminal.com/compare/phase-vs-pulumi-esc.md)