Docs
Reference

Doppler

Import secrets from a Doppler config. One way only: penv never writes back.

Import secrets from a Doppler config. One way only: penv never writes back.

The connection

WhatThis provider
VendorDoppler
Keydoppler-secrets
Availabilityavailable. You can connect it today.
Credential penv holdsdoppler-token
Values read backyes
Activationimmediate

What it moves

DirectionWhat it does
importReads names and values out of the store into penv.

What happens to a name that exists

DirectionPolicies you can pick
importskip_existing, new_version, fail

How syncs work says what each one does.

How you connect

You paste a credential you already hold. penv seals it and never shows it again.

FieldLabelKindRequiredWhat it is
tokenService tokensecret, masked here and sealedyesUse a service token. Doppler returns a restricted secret's value to a service token and withholds it from a token tied to a person.

What a mapping asks for

Answered once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
projectProjecttextyesnoThe Doppler project to read from.
configConfigtextyesnoWhich of its configs. A service token is issued for exactly one.

Permissions it needs

penv probes for these when it verifies the connection.

PermissionDirectionsBlockingWithout it
token:readevery directionyesWe cannot confirm which Doppler workplace this token belongs to.
secrets:readimportyesImport cannot read any values.