Agent-readable docs index: /llms.txt. Full docs in one file: /llms-full.txt. Download /docs.zip to grep all markdown files locally.

Migrate from Doppler

Move one Doppler project into Sigillo without printing secret values in the terminal.
This guide assumes a human or agent is running commands step by step. It intentionally uses placeholders instead of shell variables, loops, or scripts so secret values are never stored in the process environment.

1. Log in to both CLIs

doppler login sigillo login --api-url <sigillo-api-url>
Sigillo has no default server: pass your instance's URL once, and later commands reuse it.

2. Create a Sigillo organization

Create the organization that will own the migrated projects:
sigillo orgs create --name <org-name>
List organizations and copy the new Sigillo organization ID:
sigillo orgs
You will use that value as <sigillo-org-id> in the next steps.

3. List Doppler projects

List the projects in the current Doppler workplace:
doppler projects
Pick the Doppler project to migrate. This guide refers to it as <doppler-project>.

4. Create the matching Sigillo project

Create a Sigillo project with the same name as the Doppler project:
sigillo projects create --org <sigillo-org-id> --name <doppler-project>
List Sigillo projects and copy the new project ID:
sigillo projects
You will use that value as <sigillo-project-id> when creating environments and secrets.

5. List Doppler environments and configs

Doppler stores root environment secret sets in configs like dev, stg, and prd. List both environments and configs before creating anything in Sigillo:
doppler environments -p <doppler-project> doppler configs -p <doppler-project>
Use this mapping when deciding what to create in Sigillo:
DopplerSigillo
ProjectProject
Root config, such as dev, stg, prdEnvironment, such as dev, preview, prod
Branch or personal configSeparate Sigillo environment, if you need to keep it

6. Create matching Sigillo environments

List the environments that already exist in the Sigillo project:
sigillo environments --project <sigillo-project-id>
Create any missing environments:
sigillo environments create --project <sigillo-project-id> --name <environment-name> --slug <environment-slug>
Examples:
sigillo environments create --project <sigillo-project-id> --name Staging --slug stg sigillo environments create --project <sigillo-project-id> --name Production --slug prd

7. List Doppler secret names safely

List secret names for one Doppler config. This prints names only, not values:
doppler secrets --only-names -p <doppler-project> -c <doppler-config>
Example:
doppler secrets --only-names -p <doppler-project> -c dev
Keep this list open and copy each secret name into the command in the next step.

8. Copy each secret without printing it

Pipe each Doppler secret value directly into Sigillo. The value is not printed to the terminal:
doppler secrets get <secret-name> --plain -p <doppler-project> -c <doppler-config> | sigillo secrets set <secret-name> -p <sigillo-project-id> -c <sigillo-env>
Example:
doppler secrets get DATABASE_URL --plain -p <doppler-project> -c dev | sigillo secrets set DATABASE_URL -p <sigillo-project-id> -c dev
Repeat this command for every secret name from the previous step.

9. Repeat for every environment

Repeat the name listing and value piping steps for each Doppler config you want to migrate.
Common mapping:
Doppler configSigillo environment
devdev
stgpreview or stg
prdprod
Example for staging:
doppler secrets --only-names -p <doppler-project> -c stg doppler secrets get <secret-name> --plain -p <doppler-project> -c stg | sigillo secrets set <secret-name> -p <sigillo-project-id> -c preview
Example for production:
doppler secrets --only-names -p <doppler-project> -c prd doppler secrets get <secret-name> --plain -p <doppler-project> -c prd | sigillo secrets set <secret-name> -p <sigillo-project-id> -c prod

10. Verify without revealing values

List migrated Sigillo secret names for each environment:
sigillo secrets --project <sigillo-project-id> -c <sigillo-env>
Avoid sigillo secrets get during verification unless you intentionally want to inspect a value.

11. Cut over your commands

Replace Doppler runtime injection:
doppler run -p <doppler-project> -c <doppler-config> -- pnpm dev
With Sigillo runtime injection:
sigillo run --project <sigillo-project-id> -c <sigillo-env> -- pnpm dev
Optionally save the Sigillo project and environment for the current directory:
sigillo setup --project <sigillo-project-id> --env <sigillo-env> sigillo run -- pnpm dev
sigillo setup stores local CLI config in ~/.sigillo/config.json. It does not write secrets to the repository.

12. CI, servers and Kubernetes

Doppler service tokens become Sigillo API tokens or machine tokens, and GitHub Actions jobs and Kubernetes pods can use workload identity instead of a stored token. External Secrets Operator keeps its Doppler provider: point it at your instance, as its section shows.