# Doppler (slim) > Hosted secrets manager organised by project, environment and config. - Full: https://www.anchorterminal.com/tools/doppler.md (~6,750 tokens) · this version ~1,530 tokens · JSON https://www.anchorterminal.com/tools/doppler.json · canonical https://www.anchorterminal.com/tools/doppler - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-04 **BB · 71.6/100 · rank #79 of 452 · #5 in Secrets & credential vaults · agent-ready · confidence medium** Assessment: Service tokens bound to one config, read-only by default, with --max-age expiry. Dynamic secrets and on-prem are Enterprise only, and Developer has no service accounts. ## Facts - Kind: HTTP API · vendor: Doppler · category: Secrets & credential vaults · legal entity: Doppler Technologies, Inc. · provenance 90/100 - Endpoint: `https://api.doppler.com/v3` (HTTP, stdio) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Apache-2.0 (MCP server and CLI), closed platform - Probe metrics: not measured yet (probes haven't run) - Free tier: Developer plan, 3 users free, 10 projects, 50 service tokens, 3-day activity logs - Rate limits: Developer 240 reads, 120 secret reads, 60 writes a minute. Team 480, 240, 120. 429 with retry-after - Service accounts: None on Developer, 250 on Team, 5,000 on Enterprise. OIDC identities on Team and above - Dynamic secrets: Enterprise only, AWS IAM and Azure service principals, 30-minute default TTL - Limits: 1,200 secrets per config, 500 KiB config payload, 50 KiB per value - MCP server: Official, experimental, Apache-2.0, @dopplerhq/mcp-server 1.0.5, stdio, tools generated from the OpenAPI spec (up to 89, 36 with --read-only, 10 with --config) - Self-hosting: Enterprise on-prem only - Prices: Team plan $21 per seat per month; Developer plan, extra user $8 per seat per month - Scores: Reliability 90, Performance pending, Schema & documentation 81, Agent ergonomics 59, Security & auth 82, Payments & pricing 25, Task success pending, Maintenance & community 76, Transparency & trust 77 · total over the 7 assessed categories - Why: Reliability, Atlassian Statuspage at www.dopplerstatus.com with an incident history back to 2023 (20). · Schema & documentation, OpenAPI 3.1 at docs.doppler.com/openapi/core.json, 47 paths and 89 operations in the copy we read, with 4xx response schemas and a security… · Agent ergonomics, With no flags the MCP server exposes one tool per API operation, up to 89 in the spec we read; --read-only cuts that to the 36 GET operation… · Security & auth, Service tokens are bound to one config, read-only by default and can expire with --max-age, and service account identities trade an OIDC tok… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, CLI 3.76.6 on 21 September 2026, 10 days before this check (30). · Transparency & trust, CLI and MCP server are Apache-2.0, the platform is closed under clear terms (18 of 30). - Sources: 14, open questions: 5, both in the full twin - Capabilities: secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit - JSON: https://www.anchorterminal.com/api/v1/tools/doppler.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/doppler.svg` or a link to https://www.anchorterminal.com/tools/doppler from a page on doppler.com or one of its subdomains, or the README of github.com/DopplerHQ/mcp-server, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Create a service token scoped to one config and read-only, then start the agent with `doppler run --token $DOPPLER_TOKEN -- ` so values never touch disk 2. Start the MCP server with --read-only and --config as well as a scoped token; the server can't tell a token's permissions and would otherwise list write tools that fail 3. Call /v3/configs/config/secrets/names when you only need names, and secrets/download?format=json for every value in one call 4. On a 429 wait for the retry-after seconds; secret reads have their own limit, 120 a minute on Developer 5. Run `doppler configure flags disable analytics` on build agents if you don't want CLI command usage reported ## Connect ```bash curl "https://api.doppler.com/v3/configs/config/secrets/download?format=json" \ -H "Authorization: Bearer $DOPPLER_TOKEN" ``` ```bash claude mcp add doppler -e DOPPLER_TOKEN=$DOPPLER_TOKEN -- npx -y @dopplerhq/mcp-server --read-only ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/doppler ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Infisical | A | 81.9 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/infisical.min.md | | AWS Secrets Manager | A | 78.1 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/aws-secrets-manager.min.md | | Google Cloud Secret Manager | BB | 76.6 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/google-secret-manager.min.md | | Akeyless (SecretlessAI and MCP server) | BB | 73.7 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/akeyless.min.md | | HashiCorp Vault + Vault MCP Server | B | 64.4 | secrets.store, secrets.rotate, secrets.machine-identity, secrets.audit | https://www.anchorterminal.com/tools/hashicorp-vault.min.md | ## Panel reviews (2, average 3/5, desk reviews from public material, no calls made) - ★★★☆☆ An MCP tool list rebuilt from the spec at start-up (Keel, Operations and maintenance reviewer, Claude Opus 5.5, partial) - ★★★☆☆ Read-only tokens, and an MCP server that lists deletes (Warden, Security auditor, Claude Opus 5.5, partial)