doppler
secrets management and injection platform
TLDR
SYNOPSIS
doppler command [subcommand] [flags]
DESCRIPTION
Doppler is a hosted secrets manager, and its CLI exists mainly to keep secrets out of files. The central command is doppler run, which fetches the current config's secrets and injects them as environment variables into a child process. Nothing is written to disk, so there is no `.env` to leak, commit, or leave stale.The model is a three-level hierarchy: a *project* per service, an *environment* per stage (dev, staging, production), and a *config* holding the actual key/value pairs. `doppler setup` records which project and config a directory belongs to, so that a developer can `cd` into a repository and have `doppler run` pick the right secrets automatically.For CI and production, a *service token* scoped to a single config replaces the interactive login, which is why the same command works unchanged on a laptop and in a pipeline. An encrypted fallback file is written after each successful fetch so that a deploy still comes up if Doppler itself is unreachable.
PARAMETERS
-p, --project NAME / -c, --config NAME
Project and config to act on, overriding what `doppler setup` chose for this directory.--command STRING
Pass the command to run as a single shell string instead of after `--`.--preserve-env [LIST]
Let existing environment values win over Doppler's for the named secrets.--mount PATH
Write secrets to an ephemeral file instead of injecting them into the environment.--fallback PATH, --fallback-only
Use an encrypted local fallback file so processes still start when Doppler is unreachable.--json
Print output as JSON.
COMMANDS
login / logout
Authenticate this machine against Doppler, or disconnect it.setup
Interactively bind the current directory to a project and config, so later commands need no -p/-c.run -- command
Run command with the config's secrets injected into its environment.secrets
List, get, set, delete, download, upload, and substitute secrets.projects / configs / environments
Manage the project, config, and environment hierarchy.configure
View and edit the CLI's own configuration, including the auth token and the directory-to-config mapping.import
Import secrets from another source into a config.activity
Show the audit log of recent changes.me
Show which identity the current token belongs to.open
Open the current project's dashboard in a browser.update
Update the CLI itself to the latest version.
CAVEATS
Doppler is a commercial SaaS product: it needs an account, and secrets are fetched over the network at process start, so an outage or a missing token stops your application from booting unless a fallback file is in place. Secrets injected into the environment are visible to the child process and its descendants, and on Linux to anyone who can read `/proc/<pid>/environ` for that user, so --mount is the safer option for high-value credentials. Exporting with `secrets download --no-file` puts plaintext on your terminal and into shell history, which defeats much of the point of using the tool.
HISTORY
Doppler was founded in 2018, part of a wave of tools reacting to the ubiquity of `.env` files, which are easy to use, easy to commit by accident, and impossible to rotate centrally. The CLI is open source and written in Go, even though the backend service is proprietary, so the injection mechanism can be audited independently of the platform.
SEE ALSO
doppler-secrets(1), doppler-projects(1), vault(1), aws-vault(1), sops(1), env(1)
