diff_environments
Compare secret values across two environments to spot drift before a deploy. Reports per-key status: same, different, or present on one side only—never values.
Instructions
[secrets] Compare two environments across the visible secrets and report, per key, whether the values are the same, different, or present on only one side — statuses only, never values. Use before a deploy or promotion to see environment drift; follow up with promote_secret per key. A single-value (collapsed) secret applies to every environment and is reported as 'collapsed'. Read-only apart from a 'list' audit event. Returns { a, b, entries: [{ key, scope, status }], summary, drift }.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| envA | Yes | First environment. Example: 'staging'. | |
| envB | Yes | Second environment. Example: 'prod'. | |
| keys | No | Restrict the comparison to these keys. | |
| orgId | No | Organization identifier for org-scoped secrets. Required only when scope='org'. Example: 'acme-corp'. | |
| scope | No | Where the secret lives. 'global' = user keyring (default if omitted on reads), 'project' = scoped to projectPath, 'team' = team-shared (needs teamId), 'org' = org-shared (needs orgId). | |
| teamId | No | Team identifier for team-scoped secrets. Required only when scope='team'. Example: 'acme-platform'. | |
| projectPath | No | Absolute path to the project root for project-scoped secrets and policy resolution. Defaults to the MCP server's current working directory when omitted. |