Doppler
Connect Doppler to Ploy to see who is in your Doppler workplace, which workplace role each person holds, which service accounts exist, who belongs to each group, and who holds a role on each project. Ploy can also change a person's workplace role, add and remove group members, and grant, change and revoke project roles. Each Ploy connection covers one Doppler workplace.
This integration is in beta. Ploy built it from Doppler's published API and has not yet run it against a live customer workplace, so some behaviour may differ from what is described here. The first step of setup is a consent checkbox, Beta integration acknowledgement. Ticking it lets Ploy capture technical error details from this connection when a call to Doppler fails, including Doppler's API responses with secrets and personal information removed, and use them only to debug and improve the integration. Nothing is shared outside Ploy.
What Ploy syncs
Every user in the connected workplace, with their email, name, workplace role and whether they have two-factor authentication turned on.
Each user's access to Doppler, and the workplace itself as a resource whose members show their workplace role.
Every service account, shown as a non-human identity with its workplace role.
Every group, as a resource showing its members.
Every project, as a resource showing each user and service account with a role on it, and which project role they hold.
When someone is removed from the workplace, a group or a project, Ploy picks this up on the next scan and marks their access as revoked.
Doppler does not report when a user last signed in, so last activity is not synced. Pending invitations are not shown, because Doppler does not share who they were sent to. When a group holds a role on a project, the group's members are shown on the group, not on the project. Secrets, configs, service tokens and the activity log are not synced.
Before you begin
You need to be able to manage service accounts and roles in your Doppler workplace, usually as a workplace owner or admin.
Create a service account for Ploy
In Doppler, create a custom workplace role for Ploy. To let Ploy read your workplace, give it the
team,service_accountsandall_enclave_projectspermissions.If you want Ploy to change workplace roles, group members and project access, also give the role the
team_manageandall_enclave_projects_adminpermissions.Create a service account for Ploy and give it that workplace role.
Create an API token for the service account and copy it. It starts with
dp.sa.. A token with no expiry date keeps the connection working without a reminder to replace it.
A personal token also works, with the permissions of the person who created it. A service token, which is tied to a single config, cannot read the workplace and is rejected.
Connect Doppler to Ploy
In Ploy, go to Integrations and choose Doppler.
Tick Beta integration acknowledgement.
Under Enter your Doppler API token, paste the service account token.
Test the connection. Ploy reads your workplace users to confirm the token works, then completes the setup.
The first scan brings in your users, service accounts, groups and projects shortly afterwards.
What Ploy can change in Doppler
With a token whose role has the write permissions above, Ploy can:
Change a user's workplace role.
Add a user to a group, or remove them, from the group's resource page. Adding someone who is already a member, or removing someone who already left, counts as done.
Grant a user or service account a project role, change it, or revoke it, from the project's resource page. If the person already has a role on the project, choosing a new one changes it.
Doppler's API cannot invite a person to a workplace, suspend them or remove them from it, so Ploy cannot do those either. To take away someone's access to secrets, revoke their project roles.
Troubleshooting
"Doppler rejected that token." The token was copied incompletely, was revoked, or has expired. Create a new token for the service account and paste it again.
"That token cannot read your Doppler workplace users." The token is a service token, or the service account's role is missing the
teampermission. Use a service account token with the read permissions above.A change from Ploy fails with a permissions message. Add
team_manage(for roles and groups) orall_enclave_projects_admin(for project access) to the service account's role.Someone left the workplace but still shows access in Ploy. Removals are picked up by the next scheduled scan, so allow a little time for the change to appear.