Doppler secretops MCP integration
Pulls config audit trails, creates projects and branch configs, locks what must not change, and rolls a bad config back to an earlier version.
29actions available
Three actions you can hand over today
Every action runs live through MCP. Nothing to build, nothing to maintain.
Update config
Lyro modifies an existing config in Doppler SecretOps. Supporters can update secrets and settings without logging into the vault interface.
Get config details
Lyro fetches a config's details from Doppler. Supporters can view secret metadata and configurations without direct vault access.
Clone config
Lyro clones a branch config including all its secrets in Doppler. Supporters can duplicate configurations for new environments instantly.
How businesses use Doppler secretops + Lyro
Each card is one request a support team gets, and the Doppler secretops actions Lyro runs to close it.
Trace who changed a config and when
Lyro pulls the workplace activity log and the change history for a specific config, then reads the single entry behind a suspect change, so an audit question is answered without opening the Doppler dashboard.
Activity Logs ListConfig Logs ListRetrieve Config Log EntryStand up a new project and its environments
Lyro creates the Doppler project, adds the environments it needs, and clones an existing branch config with its secrets so a new service starts from a known-good setup rather than an empty one.
Create ProjectCreate EnvironmentClone ConfigLock the configs that must not change
Lyro locks a production config so it cannot be renamed or deleted, unlocks it again for a planned change, and renames an environment when a team's naming convention shifts.
Lock ConfigUnlock ConfigRename EnvironmentRoll back a bad change and cut off a live lease
When a deploy breaks, Lyro rolls the config back to the log version that last worked, writes the corrected secret values, and revokes a dynamic secret lease that should no longer be valid.
Config Logs RollbackUpdate SecretsRevoke Dynamic Secret Lease
How it works
Get started in 3 steps
Connect once, then just ask. There is no workflow builder to learn and nothing to maintain — Lyro reads the Doppler secretops actions it has and picks the ones a request needs.
- 01
Connect Doppler secretops
Authorize the Doppler secretops account your team already uses — one consent screen, no API keys, no mapping tables. Lyro can only do what you granted that account, and you can disconnect it at any time.
- 02
Tell your agent what you need
Describe the job the way you would hand it to a teammate. Lyro maps it to the Doppler secretops actions that close it and chains as many as the request needs.
- 03
Watch it work
The agent runs the actions inside the conversation the customer is already in, so nobody copies data between tabs and your team can take over at any point.
Get started free
Everything else about Doppler secretops
Setup, permissions, and the limits of what Lyro can do inside Doppler secretops.
No action in this toolkit returns a secret's value. Lyro writes values through Update Secrets and works with config, environment, project, and member metadata through calls like Get Config Details and List Environments, but the stored values themselves are never read back into a conversation.
Every action available in Doppler secretops
All 29 actions your agent can call on Doppler secretops, straight from the live MCP connection.
Activity logs list
List workplace activity logs.
Retrieve activity log
Retrieve a single activity log entry by id.
Retrieve config log entry
Retrieve a specific config log entry.
Config logs list
List config change logs for a specific config.
Config logs rollback
Rollback a config to a selected log version.
Clone config
Clone a branch config including all its secrets.
Create branch config
Create a branch config.
Configs delete
Delete a config permanently.
Get config details
Fetch a config's details.
Lock config
Lock a config.
Unlock config
Unlock a config.
Update config
Modify an existing config.
Revoke dynamic secret lease
Revoke a dynamic secret lease.
Create environment
Create a new environment.
Environments delete
Delete an environment.
Get environment details
Retrieve an environment.
List environments
List environments in a Doppler project.
Rename environment
Rename an environment.
Remove group member
Remove a member from a group.
Integrations list
List all external integrations.
Invites list
List open workplace invites.
Remove project member
Remove a member from a project.
Get project member
Retrieve a project member by type and slug.
Project permissions list
List project-level permissions.
Get project role
Retrieve a project role.
Create project
Create a project.
Projects delete
Delete a project permanently.
List projects
List Doppler projects.
Update secrets
Update secrets in a config.
The tools Doppler secretops sits next to
Same connection, same setup. Pick the next one your team already uses.

Apiflash
Apiflash is a website screenshot API for programmatically capturing web pages.
Circleci
Explains why a job failed, triggers a pipeline rerun, manages contexts and environment variables, and reports flaky tests and credit spend.
Dock certs
Verifies credentials and presentations, resolves DID documents, reports what an account holds, and manages API keys, webhooks, and tags.
Jumpcloud
Validates API credentials, returns the real device-enrollment steps with Connect key guidance, and permanently removes a custom role by ID.
Prerender
Searches cached URLs, fetches prerendered snapshots, recaches pages after a deploy, schedules wildcard cache clears, and tracks the job.
Statuscake
Creates uptime, page speed and heartbeat checks, reports alert and downtime history, maintains alert contact groups, and retunes or retires checks.

Ready to connect Doppler secretops?
Authorize the account and your agent has all 29 actions from the first conversation.


