Doppler SecretOps
for LuumenAI

Read Doppler configs and history, then roll back or lock as an approved step

Connect Doppler and Luumen can read your projects, environments, configs, and change logs while you work. Ask who changed a config last night, or what a staging environment contains. When something needs to change — a rollback, a lock, a cloned branch config — Luumen shows the plan first and waits for your approval before calling Doppler. Authentication is by API key.

The Doppler SecretOps toolbox

29 tools: 13 read, 16 write. Reads answer instantly. Writes require approval by default. Everything is logged.

  • ReadActivity Logs ListList workplace activity logs.
  • ReadRetrieve Activity LogRetrieve a single activity log entry by id.
  • ReadRetrieve Config Log EntryRetrieve a specific config log entry.
  • ReadConfig Logs ListList config change logs for a specific config.
  • ReadGet Config DetailsFetch a config's details.
  • ReadGet Environment DetailsRetrieve an environment.
  • ReadList EnvironmentsList environments in a Doppler project.
  • ReadIntegrations ListList all external integrations.
  • ReadInvites ListList open workplace invites.
  • ReadGet Project MemberRetrieve a project member by type and slug.
  • ReadProject Permissions ListList project-level permissions.
  • ReadGet Project RoleRetrieve a project role.
  • ReadList ProjectsList Doppler projects.
  • WriteConfig Logs RollbackRollback a config to a selected log version. Approval by default
  • WriteClone ConfigClone a branch config including all its secrets. Approval by default
  • WriteCreate Branch ConfigCreate a branch config. Approval by default
  • WriteConfigs DeleteDelete a config permanently. Approval by default
  • WriteLock ConfigLock a config. Approval by default
  • WriteUnlock ConfigUnlock a config. Approval by default
  • WriteUpdate ConfigModify an existing config. Approval by default
  • WriteRevoke Dynamic Secret LeaseRevoke a dynamic secret lease. Approval by default
  • WriteCreate EnvironmentCreate a new environment. Approval by default
  • WriteEnvironments DeleteDelete an environment. Approval by default
  • WriteRename EnvironmentRename an environment. Approval by default
  • WriteRemove Group MemberRemove a member from a group. Approval by default
  • WriteRemove Project MemberRemove a member from a project. Approval by default
  • WriteCreate ProjectCreate a project. Approval by default
  • WriteProjects DeleteDelete a project permanently. Approval by default
  • WriteUpdate SecretsUpdate secrets in a config. Approval by default

One prompt, start to finish

What a governed Doppler SecretOps run looks like inside Luumen.

Questions

How does LuumenAI connect to Doppler SecretOps?

Authorize once with API token. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.

Can LuumenAI change things in Doppler SecretOps on its own?

Read actions answer immediately. Anything that writes — config logs rollback, clone config, create branch config, configs delete, and more — is shown as a plan and requires approval by default, including the 6 actions classified as destructive. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.

Who gets access to the integration?

You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.

Is there an audit trail?

Every call to Doppler SecretOps — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.

Put Doppler SecretOps to work with Luumen

Connect in minutes. Every action scoped, approved, and audited from day one.