Sazabi
Sandbox CLIs

Doppler

Give the Sazabi agent the Doppler CLI (doppler) in its sandbox to manage secrets and configuration across environments.

About

This CLI connection makes the Doppler CLI (doppler) available in the Sazabi agent's sandbox. The agent can use it for secrets and config management. The tool is baked into the sandbox image; connecting it authenticates the already-installed CLI.

Prerequisites

  • A Sazabi project.
  • A Doppler token (DOPPLER_TOKEN) — a service token scoped to a project/config, or a personal token, generated from the Doppler dashboard.

Set up in the dashboard

Configure the sandbox in the dashboard under Settings > Sandbox CLIs.

Find Doppler in the catalog

In Settings > Sandbox CLIs, find Doppler under Browse sandbox CLIs and choose to connect it.

Provide credentials

Enter the required value: DOPPLER_TOKEN — your Doppler service or personal token. Save to store it securely; Sazabi injects it into the sandbox when the agent runs.

Set up with the CLI

You can also configure the Doppler CLI connection with the Sazabi CLI (installed and authenticated — see CLI reference).

sazabi sandbox-clis set --type doppler --env DOPPLER_TOKEN=<your-doppler-token>

To validate the credentials without saving, run the same command with test in place of set (the test command also requires the --env flags).

Verify

Ask the agent, in a thread, to run the doppler CLI (a read-only or status command) and confirm it returns real output from your account. If the command is not found, the CLI connection may not be enabled; if it runs unauthenticated, recheck the credentials.

Troubleshooting

Command not found — Confirm the Doppler CLI connection is enabled for the project under Settings > Sandbox CLIs.

Authentication fails — Recheck the credential values; a rotated or revoked token must be re-entered under Settings > Sandbox CLIs or with sazabi sandbox-clis set --type doppler.

Further reading