Skip to main content
Glama
aledlie

Doppler MCP Server

by aledlie

doppler_secrets_get

Retrieve secret values from Doppler's secure secrets management system by specifying the secret name, with optional project and config parameters for targeted access.

Instructions

Get a secret value from Doppler

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameYesThe name of the secret to retrieve
projectNoThe Doppler project name (optional if set via doppler setup)
configNoThe Doppler config name (optional if set via doppler setup)

Implementation Reference

  • Specific implementation logic for the doppler_secrets_get tool: builds the CLI command 'doppler secrets get <name> [--project <project>] [--config <config>] --json'
    case "doppler_secrets_get":
      parts.push("secrets", "get", getString("name")!);
      if (getString("project")) parts.push("--project", getString("project")!);
      if (getString("config")) parts.push("--config", getString("config")!);
      parts.push("--json");
      break;
  • Input schema and metadata definition for the doppler_secrets_get tool.
    {
      name: "doppler_secrets_get",
      description: "Get a secret value from Doppler",
      inputSchema: {
        type: "object",
        properties: {
          name: {
            type: "string",
            description: "The name of the secret to retrieve",
          },
          project: {
            type: "string",
            description: "The Doppler project name (optional if set via doppler setup)",
          },
          config: {
            type: "string",
            description: "The Doppler config name (optional if set via doppler setup)",
          },
        },
        required: ["name"],
      },
    },
  • src/index.ts:27-31 (registration)
    Registers the listTools request handler, which provides the tool definitions including doppler_secrets_get.
    server.setRequestHandler(ListToolsRequestSchema, async () => {
      return {
        tools: toolDefinitions,
      };
    });
  • src/index.ts:34-51 (registration)
    Registers the generic callTool request handler that dispatches doppler_secrets_get calls to the executeCommand function.
    server.setRequestHandler(CallToolRequestSchema, async (request) => {
      const { name, arguments: args } = request.params;
    
      try {
        const result = await executeCommand(name, args || {});
        return {
          content: [
            {
              type: "text",
              text: JSON.stringify(result, null, 2),
            },
          ],
        };
      } catch (error) {
        const errorMessage = error instanceof Error ? error.message : String(error);
        throw new McpError(ErrorCode.InternalError, `Doppler CLI error: ${errorMessage}`);
      }
    });
  • Core helper function that executes the built Doppler CLI command for doppler_secrets_get and parses the output.
    export async function executeCommand(
      toolName: string,
      args: DopplerArgs
    ): Promise<any> {
      const command = buildDopplerCommand(toolName, args);
    
      try {
        const output = execSync(command, {
          encoding: "utf-8",
          stdio: ["pipe", "pipe", "pipe"],
          maxBuffer: 10 * 1024 * 1024, // 10MB buffer
        });
    
        // Try to parse as JSON, if it fails return raw output
        try {
          return JSON.parse(output);
        } catch {
          return { output: output.trim() };
        }
      } catch (error: any) {
        // Handle execution errors
        const stderr = error.stderr?.toString() || "";
        const stdout = error.stdout?.toString() || "";
        const message = stderr || stdout || error.message;
        throw new Error(`Doppler CLI command failed: ${message}`);
      }
    }

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

C2.4/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries full burden of behavioral disclosure. It doesn't state whether config/project are required when doppler setup hasn't been run, what happens for missing secrets (error vs empty), or whether the value is sensitive/redacted. This is a secrecy-sensitive read tool with zero behavioral detail.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Single sentence, no wasted words. It's appropriately brief and front-loaded, but arguably under-specified rather than concisely complete. Not verbose, but also conveys almost nothing beyond the name.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a security-sensitive read tool with no output schema and no annotations, the description is incomplete. It doesn't explain return value format, behavior with missing config/project, permission requirements, or error cases. Sibling tools (set/delete) and the secrets-domain context demand more behavioral detail.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so baseline is 3. However, the description adds nothing beyond the schema. The schema documents name/config/project but the description provides no additional context about how project/config interplay works (e.g., when you must supply them vs rely on setup), nor clarifies the required parameter. Slight deduction for adding zero value.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose3/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description 'Get a secret value from Doppler' uses a clear verb (get) and resource (secret value). It distinguishes the read operation from siblings like doppler_secrets_set and doppler_secrets_delete, though it doesn't explicitly name them or contrast. Basic purpose is clear but minimal.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

No guidance on when to use this vs alternatives, no prerequisites mentioned, and the schema hints at optional project/config but no clarity on when setup is needed. The description gives no usage context or exclusions. An agent has to infer from the schema what context is required.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.