Doppler
A weekend of work, and real gaps remain.
A secrets manager for application configuration: one place to hold environment variables per project and environment, synced into your hosting, CI and local shells.
Build encrypted secrets that live in the repository. STACK - SOPS with age, or git-crypt; no service at all HOW IT WORKS - Secrets in a YAML file, encrypted at rest, committed - Each developer and each deployment target has an age key; the file is encrypted to all of them - Removing someone means re-encrypting without their key, and rotating what they saw WHY THIS IS GOOD - A secret change is a commit: reviewable, revertible, and dated - No service to be down when you are deploying IN CI AND IN PRODUCTION - One key in the platform's own secret store, used to decrypt at deploy time - Never decrypt into a file on disk; pipe into the process environment WHAT YOU DO NOT GET - An audit log of reads. You get an audit log of changes instead, which is often what people actually wanted Include the SOPS configuration, the key layout and the deploy step.
What you lose
- Integrations that push secrets into your hosting provider, CI and container platform without you writing a sync
- An audit log of who read which secret and when
- Rotation and versioning, so a leaked value can be replaced without a redeploy hunt
If you would rather not build
- HashiCorp Vault, if you need real rotation
The escape hatch
open source · no votes, no paid placement
SOPS
$0Encrypts values inside YAML and JSON so the file stays reviewable in git.
getsops/sopsfree · open source
Infisical
$0A self-hostable secrets manager with sync integrations and an audit log.
Infisical/infisicalfree · open source
Why this verdict
our own opinion · changed only by a person
58/100
Verdict kinda at 58. Encrypted files in git cover most teams and make secret changes reviewable; read auditing and automatic rotation are what you leave behind.
History
tracked since 10 Aug 2026 · nothing is ever overwritten
Nothing recorded yet. This chart fills in once the page has visitors, votes or prompt copies — it will not draw a flat line to look busy.
Questions about Doppler
answered from the record above
Is Doppler free?
No — the plan we track is $8 a month. Developer at around $8 per seat per month billed monthly; a free tier covers a single developer.
Can you replace Doppler by building your own?
ALMOST. A weekend of work, and real gaps remain. Replacement score 58 out of 100, build time a weekend. Read what you lose before you decide.
How much does Doppler cost?
$8 a month on Developer — $96 a year. Recorded 10 Aug 2026.
What do you lose by replacing Doppler?
Integrations that push secrets into your hosting provider, CI and container platform without you writing a sync; An audit log of who read which secret and when; Rotation and versioning, so a leaked value can be replaced without a redeploy hunt. If any of those carry weight for you, keep paying.
Is there an open-source alternative to Doppler?
Yes: SOPS, Infisical. The prompt on this page is for when you want it your way instead.
Related entries
same category first, most replaced first
Every week, something stops being worth paying for.
New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click.
free forever · no tracking pixel · every prompt stays free on the site