Skip to main content
Glama
aledlie

Doppler MCP Server

by aledlie

doppler_secrets_list

Retrieve and display all secrets stored in a Doppler configuration to manage sensitive data access across your projects and environments.

Instructions

List all secrets in a Doppler config

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
projectNoThe Doppler project name (optional if set via doppler setup)
configNoThe Doppler config name (optional if set via doppler setup)

Implementation Reference

  • Specific handler logic for doppler_secrets_list tool: builds the CLI command 'doppler secrets list [--project X] [--config Y] --json'
    case "doppler_secrets_list":
      parts.push("secrets", "list");
      if (getString("project")) parts.push("--project", getString("project")!);
      if (getString("config")) parts.push("--config", getString("config")!);
      parts.push("--json");
      break;
  • Input schema and metadata definition for the doppler_secrets_list tool
    {
      name: "doppler_secrets_list",
      description: "List all secrets in a Doppler config",
      inputSchema: {
        type: "object",
        properties: {
          project: {
            type: "string",
            description: "The Doppler project name (optional if set via doppler setup)",
          },
          config: {
            type: "string",
            description: "The Doppler config name (optional if set via doppler setup)",
          },
        },
      },
    },
  • src/index.ts:27-31 (registration)
    Registers the listTools handler, exposing the doppler_secrets_list tool definition
    server.setRequestHandler(ListToolsRequestSchema, async () => {
      return {
        tools: toolDefinitions,
      };
    });
  • MCP callTool request handler that dispatches to executeCommand based on tool name, handling the execution for doppler_secrets_list
    server.setRequestHandler(CallToolRequestSchema, async (request) => {
      const { name, arguments: args } = request.params;
    
      try {
        const result = await executeCommand(name, args || {});
        return {
          content: [
            {
              type: "text",
              text: JSON.stringify(result, null, 2),
            },
          ],
        };
      } catch (error) {
        const errorMessage = error instanceof Error ? error.message : String(error);
        throw new McpError(ErrorCode.InternalError, `Doppler CLI error: ${errorMessage}`);
      }
    });
  • Core helper function that executes the Doppler CLI command for all tools, including doppler_secrets_list, by running execSync on the built command and parsing output
    export async function executeCommand(
      toolName: string,
      args: DopplerArgs
    ): Promise<any> {
      const command = buildDopplerCommand(toolName, args);
    
      try {
        const output = execSync(command, {
          encoding: "utf-8",
          stdio: ["pipe", "pipe", "pipe"],
          maxBuffer: 10 * 1024 * 1024, // 10MB buffer
        });
    
        // Try to parse as JSON, if it fails return raw output
        try {
          return JSON.parse(output);
        } catch {
          return { output: output.trim() };
        }
      } catch (error: any) {
        // Handle execution errors
        const stderr = error.stderr?.toString() || "";
        const stdout = error.stdout?.toString() || "";
        const message = stderr || stdout || error.message;
        throw new Error(`Doppler CLI command failed: ${message}`);
      }
    }

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

C2.6/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries full burden for behavioral disclosure. It doesn't mention that listing secrets may expose sensitive values, whether output is masked/redacted, rate limits, or what happens when config/project aren't set. For a security-sensitive secrets tool, the lack of disclosure about sensitive value exposure is a notable gap.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Single sentence, zero waste. The description is efficient and front-loaded with the verb. Could arguably add a bit more context but the brevity is appropriate for a simple list operation.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The tool is a list operation with no output schema, no annotations, and 2 optional params. For a secrets-listing tool, the description should clarify whether the output includes secret values (sensitive) or just names, and how config/project resolution works when not set. These gaps matter for an agent deciding whether to call this tool and how to handle the result safely.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so both parameters are documented in the schema itself. The description doesn't add any parameter-specific meaning beyond what the schema provides. Both params are marked optional with fallback to doppler setup, which is captured in the schema. Baseline 3 is correct when schema does the heavy lifting and description adds no extra context.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose3/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description 'List all secrets in a Doppler config' uses a clear verb (List) and resource (secrets in config). It distinguishes from get/set/delete but is generic about scope—doesn't specify whether it returns all values/keys or requires auth. It's adequate for listing but lacks distinctions like whether this returns secret values vs just names, unlike a sibling comparison.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

No indication of when to use this vs doppler_secrets_get specifically. It distinguishes from get/set/delete by being 'all secrets' vs individual, but there's no explicit statement of when to prefer this tool, no alternative naming, and no mention of whether secrets are decrypted or masked. Little guidance beyond the obvious reading.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.