Doppler
for LuumenAI

Read Doppler configs and change logs, then roll back a bad config with approval

Connect Doppler and Luumen can answer questions about your projects without anyone opening the dashboard: which configs exist in an environment, who changed one and when, which webhooks and integrations are wired up. When something needs to change — a rollback, a new branch config, a lock — Luumen shows the plan first and waits for your approval. Authentication is by API key.

The Doppler toolbox

61 tools: 32 read, 29 write. Reads answer instantly. Writes require approval by default. Everything is logged.

  • ReadList Activity LogsList workplace activity logs with pagination support.
  • ReadGet Activity LogRetrieve detailed information about a specific activity log entry.
  • ReadGet Authenticated User InfoRetrieve information about the authenticated user or token.
  • ReadGet Config LogRetrieve a specific config log from Doppler.
  • ReadList Config LogsRetrieve configuration change logs for a specific config in a project.
  • ReadGet ConfigRetrieve a specific Doppler config by project and config name.
  • ReadList Doppler ConfigsList configurations from a Doppler project.
  • ReadGet EnvironmentRetrieves detailed metadata for a specific Doppler environment within a project.
  • ReadList EnvironmentsList all environments in a Doppler project.
  • ReadGet WebhookRetrieve an existing webhook by its slug.
  • ReadGet Workplace UserRetrieve a specific workplace user by their workplace_user id.
  • ReadList IntegrationsRetrieve all existing integrations in Doppler.
  • ReadList InvitesList open workplace invites.
  • ReadList Change RequestsList existing change requests in the Doppler workplace.
  • ReadList Project MembersList all members of a Doppler project including users, groups, service accounts, and invites.
  • ReadList Service TokensList all service tokens for a specific Doppler config.
  • ReadList Workplace UsersList all users in the Doppler workplace.
  • ReadList WebhooksList all webhooks configured for a Doppler project.
  • ReadGet Project MemberRetrieve a specific project member's details including their role and environment access permissions.
  • ReadList Project PermissionsList all available project-level permissions in Doppler.
  • ReadGet Project RoleRetrieve detailed information about a specific project role in Doppler, including its permissions, display name, identifier, creation timestamp, and whether it's a custom or built-in role.
  • ReadList Project RolesList all available project roles in Doppler.
  • ReadGet Project DetailsRetrieve details of a specific Doppler project by its identifier.
  • ReadList Doppler ProjectsList all Doppler projects in your workspace.
  • ReadDownload SecretsDownload secrets from a Doppler config in various formats.
  • ReadGet SecretRetrieve a specific secret from a Doppler project config.
  • ReadList Doppler SecretsList all secrets for a specific Doppler config within a project.
  • ReadList Secret NamesRetrieve the list of secret names from a specific Doppler config.
  • ReadGet Workplace InformationRetrieve workplace information from Doppler.
  • ReadGet Workplace RoleRetrieve workplace role information from Doppler.
  • ReadList Workplace RolesList all workplace roles in your Doppler workspace.
  • ReadList Workplace PermissionsRetrieves all available workplace permissions in Doppler.
  • WriteAdd WebhookCreate a new webhook for a Doppler project. Approval by default
  • WriteRollback Config LogRollback a config to a selected log version. Approval by default
  • WriteClone ConfigClone a branch config including all its secrets. Approval by default
  • WriteCreate ConfigCreate a branch config. Approval by default
  • WriteDelete ConfigDelete a config permanently. Approval by default
  • WriteLock ConfigLock a Doppler config to prevent it from being renamed or deleted. Approval by default
  • WriteUnlock ConfigUnlock a config. Approval by default
  • WriteUpdate ConfigRename an existing Doppler config within a project. Approval by default
  • WriteCreate Encrypted Share LinkCreate a Doppler Share link for an end-to-end encrypted secret. Approval by default
  • WriteCreate Plain Text Share LinkGenerate a Doppler Share link by sending a plain text secret. Approval by default
  • WriteCreate Service TokenCreate a new service token for a Doppler config. Approval by default
  • WriteDelete Service TokenDelete an existing service token from a Doppler config. Approval by default
  • WriteDelete WebhookDelete an existing webhook. Approval by default
  • WriteDisable WebhookDisable an existing Doppler webhook. Approval by default
  • WriteRevoke Dynamic Secret LeaseRevoke a dynamic secret lease immediately before its TTL expires. Approval by default
  • WriteEnable WebhookEnable a previously disabled webhook. Approval by default
  • WriteCreate EnvironmentCreate a new environment in a Doppler project. Approval by default
  • WriteDelete EnvironmentDelete an environment. Approval by default
  • WriteRename EnvironmentRename an environment's display name within a Doppler project. Approval by default
  • WriteRemove Group MemberRemove a member from a Doppler group. Approval by default
  • WriteRemove Project MemberRemove a member from a project. Approval by default
  • WriteCreate ProjectCreate a project. Approval by default
  • WriteDelete ProjectDelete a project permanently. Approval by default
  • WriteDelete SecretDelete a secret from a Doppler config. Approval by default
  • WriteUpdate Doppler SecretsUpdate secrets in a Doppler config. Approval by default
  • WriteUpdate Secret NoteUpdate a note for a secret in Doppler. Approval by default
  • WriteUpdate ProjectUpdate an existing Doppler project's name or description. Approval by default
  • WriteUpdate WebhookUpdate an existing webhook configuration in Doppler. Approval by default
  • WriteUpdate Workplace SettingsUpdate workplace settings in Doppler. Approval by default

One prompt, start to finish

What a governed Doppler run looks like inside Luumen.

Questions

How does LuumenAI connect to Doppler?

Authorize once with API token. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.

Can LuumenAI change things in Doppler on its own?

Read actions answer immediately. Anything that writes — add webhook, rollback config log, clone config, create config, and more — is shown as a plan and requires approval by default, including the 9 actions classified as destructive. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.

Who gets access to the integration?

You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.

Is there an audit trail?

Every call to Doppler — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.

Put Doppler to work with Luumen

Connect in minutes. Every action scoped, approved, and audited from day one.