About Doppler
Iru calls the Doppler API with a Bearer token (Service Token or Personal Token). Evidence includes projects, environments, secret metadata (names, versions, change history), and team structure. Iru does not retrieve or store plaintext secret values - only metadata needed for compliance visibility.How It Works
| Detail | Value |
|---|---|
| Category | Secrets management |
| Authentication | Bearer token (Service or Personal) |
- Service Token: Scoped to a specific project and config; use for narrow audits.
- Personal Token: Follows your user’s access across projects; use for org-wide visibility.
Prerequisites
- Doppler access to the projects and environments your program covers.
Connect Doppler to Iru
- Doppler
- Iru Compliance
Complete this tab before you connect the source in Compliance.
Sign in to Doppler
Open the Doppler dashboard and sign in with a user who can create API tokens for the workplace or project Iru will read.
Open the API tokens screen
Navigate to API for your workplace (URL pattern similar to
https://dashboard.doppler.com/workplace/api).Name the token
Enter a label such as Iru Compliance so you can revoke the correct credential during audits.
Choose Service vs Personal token
Pick Service Token when you want a narrow, project/config-scoped secret, or Personal Token when the integration should inherit your user access. Align the choice with least-privilege policy.
Continue on the Iru Compliance tab.
Troubleshooting
Nothing opens when you turn the source on
Nothing opens when you turn the source on
Check pop-up blocker settings for the Iru site and try again.
401 Unauthorized
401 Unauthorized
Missing projects
Missing projects
Service Tokens are single-project - use a Personal Token or additional scoped tokens per project.
Exposure
Exposure
Revoke in Doppler, issue a new token, update Iru.
Considerations
If a Personal Token’s user loses workspace access,…
If a Personal Token’s user loses workspace access, the token stops working - reconnect with an active account.
Related Articles
Sources Management
Browse and manage every Compliance source.
Getting Started With Compliance
Frameworks, actions, and Artifacts.
Iru Overview
How Endpoint, Compliance, and Identity fit together.
Artifacts Management
Upload, review, and organize evidence from sources and actions.
