Activity Log Event Schema
Learn about the schema used in Doppler Activity Log events
When a logging service is connected to your workplace, Doppler delivers every new Activity Log entry to it as a JSON document. This page describes that document, the actor and metadata objects it contains, and every event type Doppler currently generates.
This schema applies to the logging services: AWS SQS, Datadog, Generic HTTPS, Splunk, and Sumo Logic. The chat services (Slack, Microsoft Teams, and Discord) receive a message formatted for that chat platform instead and are not covered here.
Payload Structure
| Field | Type | Description |
|---|---|---|
source | string | Always doppler. Datadog payloads use the field name ddsource instead of source. |
slug | string | Unique identifier of the Activity Log entry. This is the same value returned as id by the Activity Logs API. |
type | string | The event type. See Events for the full list. |
title | string | Always Activity Log: <slug>. |
text | string | Human-readable description of the event as HTML. Only <a>, <br>, <em>, <span>, and <strong> tags are used. Links point to the Doppler dashboard, use mailto: when they refer to a person, or point to the external site a secret was imported from. For events that carry a diff, up to 10 changed names are appended as a bulleted list followed by and N others... when there are more. |
user | object | The actor that performed the action. See Actor. |
link | string | Dashboard URL that opens this entry in the workplace Activity Log. |
workplace | object | id (the workplace slug) and name of the workplace the event belongs to. |
createdAt | string | ISO 8601 timestamp of when the event occurred. |
metadata | object | Structured, event-specific fields. See Metadata. If Doppler is unable to build the metadata for an entry, the payload is still delivered but this field is omitted. |
Delivery differences between services
The document above is the same for every logging service, with these exceptions:
- Datadog: the
sourcefield is namedddsource. - Splunk: the document is wrapped in an
eventobject to match the HTTP Event Collector format, for example{ "event": { "source": "doppler", ... } }. - AWS SQS: the document is sent as the message body, serialized as a JSON string.
- Generic HTTPS and Sumo Logic: the document is sent as the JSON body of an HTTPS
POSTrequest.
Examples
The tabs below show a secrets update in a config, a workplace-level event with no project, an automated action attributed to the Doppler Bot, and a change request review.
{
"source": "doppler",
"slug": "ZbDEAEqJEQI9kbTuFLIBHE0J",
"type": "enclave.project.config.secrets.update",
"title": "Activity Log: ZbDEAEqJEQI9kbTuFLIBHE0J",
"text": "Modified secrets in <a class=\"text-purple-500 hover:underline\" rel=\"noopener\" href=\"https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend/configs/dev\">dev</a> of <a class=\"text-purple-500 hover:underline\" rel=\"noopener\" href=\"https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend\">backend</a> project with <a class=\"text-purple-500 hover:underline\" rel=\"noopener\" href=\"https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend/configs/dev/logs?id=fQ2mXk8ZpB4vLr7NwT1cYd6H\">1 added and 1 updated</a>:<br>• STRIPE_API_KEY<br>• DATABASE_URL",
"user": {
"kind": "user",
"slug": "36c1e2ad-ec82-4f01-9711-31047d9accd8",
"email": "[email protected]",
"name": "John Doe",
"username": "jdoe",
"profile_image_url": "https://www.gravatar.com/avatar/a1b2c3d4e5f6a7b8c9d0a1b2c3d4e5f6a7b8c9d0?s=500&d=retro"
},
"link": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/logs?id=ZbDEAEqJEQI9kbTuFLIBHE0J",
"workplace": {
"id": "a1b2c3d4e5f6a7b8c9d0",
"name": "Doppler University"
},
"createdAt": "2025-11-17T15:40:41.624Z",
"metadata": {
"projectId": "backend",
"projectName": "backend",
"projectUrl": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend",
"projectDescription": "Backend API service",
"configName": "dev",
"configUrl": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend/configs/dev",
"changeRequest": null,
"pullRequest": null,
"diff": {
"added": ["STRIPE_API_KEY"],
"removed": [],
"updated": ["DATABASE_URL"]
},
"diffUrl": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend/configs/dev/logs?id=fQ2mXk8ZpB4vLr7NwT1cYd6H",
"importedSecretFrom": null
}
}{
"source": "doppler",
"slug": "Hk3rT9wLmQ2xVb7nYc5dPf8J",
"type": "team.seat.update",
"title": "Activity Log: Hk3rT9wLmQ2xVb7nYc5dPf8J",
"text": "Changed <a class=\"text-purple-500 hover:underline\" rel=\"noopener\" href=\"https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/team/users/7d2f6a1e-3c4b-4e8f-9a0b-1c2d3e4f5a6b\">Jane Doe</a> access from <strong>collaborator</strong> to <strong>admin</strong>",
"user": {
"kind": "user",
"slug": "36c1e2ad-ec82-4f01-9711-31047d9accd8",
"email": "[email protected]",
"name": "John Doe",
"username": "jdoe",
"profile_image_url": "https://www.gravatar.com/avatar/a1b2c3d4e5f6a7b8c9d0a1b2c3d4e5f6a7b8c9d0?s=500&d=retro"
},
"link": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/logs?id=Hk3rT9wLmQ2xVb7nYc5dPf8J",
"workplace": {
"id": "a1b2c3d4e5f6a7b8c9d0",
"name": "Doppler University"
},
"createdAt": "2025-11-17T16:02:13.918Z",
"metadata": {
"name": "Jane Doe",
"email": "[email protected]",
"oldWorkplaceRole": "collaborator",
"newWorkplaceRole": "admin"
}
}{
"source": "doppler",
"slug": "Qw8nB2vXc5zLk9mJt4rYh7Gd",
"type": "enclave.project.rotated_secrets.rotate",
"title": "Activity Log: Qw8nB2vXc5zLk9mJt4rYh7Gd",
"text": "Rotated secret <strong>DB_PASSWORD</strong> in config <a class=\"text-purple-500 hover:underline\" rel=\"noopener\" href=\"https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend/configs/prd\">prd</a> in project <a class=\"text-purple-500 hover:underline\" rel=\"noopener\" href=\"https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend\">backend</a>",
"user": {
"kind": "bot",
"slug": "doppler",
"type": "doppler",
"name": "Doppler Bot",
"username": "doppler-bot",
"profile_image_url": "https://dashboard.doppler.com/imgs/logo_color.png",
"is_bot": true
},
"link": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/logs?id=Qw8nB2vXc5zLk9mJt4rYh7Gd",
"workplace": {
"id": "a1b2c3d4e5f6a7b8c9d0",
"name": "Doppler University"
},
"createdAt": "2025-11-18T03:00:04.211Z",
"metadata": {
"projectId": "backend",
"projectName": "backend",
"projectUrl": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend",
"projectDescription": "Backend API service",
"configName": "prd",
"configUrl": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend/configs/prd",
"rotatedSecretName": "DB_PASSWORD"
}
}{
"source": "doppler",
"slug": "Ld5pR8tKw2mZx7vBn3cQj9Yf",
"type": "enclave.change_request_unit.review_create",
"title": "Activity Log: Ld5pR8tKw2mZx7vBn3cQj9Yf",
"text": "Approved changes in CR <a class=\"text-purple-500 hover:underline\" rel=\"noopener\" href=\"https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/change-requests/cr_01JD3Y5K8QW2ZP7X4NVBM6TR9E\">Rotate Stripe keys</a> into <a class=\"text-purple-500 hover:underline\" rel=\"noopener\" href=\"https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend/configs/prd\">prd</a> of <a class=\"text-purple-500 hover:underline\" rel=\"noopener\" href=\"https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend\">backend</a>",
"user": {
"kind": "user",
"slug": "36c1e2ad-ec82-4f01-9711-31047d9accd8",
"email": "[email protected]",
"name": "John Doe",
"username": "jdoe",
"profile_image_url": "https://www.gravatar.com/avatar/a1b2c3d4e5f6a7b8c9d0a1b2c3d4e5f6a7b8c9d0?s=500&d=retro"
},
"link": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/logs?id=Ld5pR8tKw2mZx7vBn3cQj9Yf",
"workplace": {
"id": "a1b2c3d4e5f6a7b8c9d0",
"name": "Doppler University"
},
"createdAt": "2025-11-18T14:27:50.402Z",
"metadata": {
"projectId": "backend",
"projectName": "backend",
"projectUrl": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend",
"projectDescription": "Backend API service",
"configName": "prd",
"configUrl": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend/configs/prd",
"changeRequestId": "cr_01JD3Y5K8QW2ZP7X4NVBM6TR9E",
"changeRequestTitle": "Rotate Stripe keys",
"changeRequestUrl": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/change-requests/cr_01JD3Y5K8QW2ZP7X4NVBM6TR9E",
"changeRequestUnitId": "cru_01JD3Y6R2VX8QT4WN7ZKP5MBH3"
}
}- Secrets update:
diffUrlopens the corresponding entry in the config's own log, which has a different identifier than the Activity Log entry. When the update came from a merged change request,changeRequestis an object withid,title,unitId, andrequestUrl. When a secret was imported from an external site,importedSecretFromis the origin it came from (for examplehttps://vercel.com). - Workplace event: events that happen at the workplace level carry only the fields relevant to that event in
metadata. This entry records a member's workplace role being changed. - Bot actor: actions Doppler performs on your behalf, such as a scheduled secret rotation, are attributed to a bot actor rather than a person.
- Change request: change request events combine the config being changed with details of the change request itself.
Actor
The user field identifies who or what performed the action. The kind field tells you which shape to expect.
kind | Description | Fields |
|---|---|---|
user | A workplace member acting through the dashboard, CLI, or a personal token. | slug, email, name, username, profile_image_url |
serviceAccount | A service account acting through one of its tokens or identities. | slug, name |
apiToken | A workplace-level token acting directly: a config service token, a SCIM token, or an Audit token. | slug, name (may be null), type (an object with id and name, where id is one of enclave_service_token, workplace_scim_token, or workplace_audit_token and name is Service, SCIM, or Audit respectively) |
bot | Doppler itself, for automated actions such as scheduled secret rotation or a sync, or the GitHub bot for GitHub-initiated actions. | slug, type (doppler or github; older entries may also use heroku or scim), name, username, profile_image_url, is_bot (always true) |
Examples of the serviceAccount and apiToken shapes:
{
"kind": "serviceAccount",
"slug": "ci-deployer",
"name": "CI Deployer"
}{
"kind": "apiToken",
"slug": "f4b1c8e2-6d7a-4a9e-b3c5-2e1f0d9a8b7c",
"name": "prd-api-server",
"type": {
"id": "enclave_service_token",
"name": "Service"
}
}Metadata
metadata contains structured fields specific to the event type, so you can filter and route events without parsing text. Many event types share the same groups of fields. The groups are defined here and referenced by name in the Events tables.
| Group | Fields |
|---|---|
| Project | projectId, projectName, projectUrl, projectDescription |
| Config | Project + configName, configUrl |
| Environment | Project + environmentName, environmentId |
| Member | userName, userEmail. For a member who has not yet accepted their invite, userName is null and userEmail is the invited address. Both are null if the member can no longer be resolved. |
| Group | groupId, groupName, groupUrl |
| Tag | tagId, tagName |
| Service account | serviceAccountId, serviceAccountName, serviceAccountUrl |
| Service account token | Service account + serviceAccountTokenId, serviceAccountTokenName (may be null), serviceAccountTokenApiKeyPreview |
| Service account identity | Service account + serviceAccountIdentityId, serviceAccountIdentityName |
| Service account identity token | Service account identity + serviceAccountIdentityAPITokenId, serviceAccountIdentityTokenAPIKeyPreview |
| Integration | integrationId, integrationType, integrationName, integrationUrl |
| Change request | changeRequestId, changeRequestTitle, changeRequestUrl. Also changeRequestNewStatus (open or closed) when the status changed, and changeRequestAssigned (an object with added and removed counts) when the assigned reviewers changed. |
| Change request unit | Config + Change request + changeRequestUnitId |
| Change request policy | changeRequestPolicyId, changeRequestPolicyName, changeRequestPolicyUrl |
A diff field, where present, is an object with added, removed, and updated arrays of names.
Events
Each table lists the event type, what it records, and the fields present in metadata. "None" means metadata is an empty object. Fields marked nullable are present but null when the value is not applicable.
Workplace
| Type | Description | Metadata |
|---|---|---|
workplace.create | Created the workplace | billingPlan |
workplace.delete | Deleted the workplace | reason (nullable) |
workplace.default_environments.update | Changed the default environments that new projects are created with | None |
workplace.default_environments_view.update | Changed how default environments are displayed | oldView (nullable), newView |
workplace.secret_naming.type.update | Changed the workplace secret naming rules between Classic and Permissive | prevSecretNamingType, secretNamingType (classic or permissive) |
workplace.sessions.invalidate.completed | Finished invalidating every dashboard session in the workplace. success is false if some sessions could not be invalidated | success, failureCount |
workplace.tokens.revoke.initiated | Started revoking every personal and/or CLI token in the workplace | personal, cli |
workplace.tokens.revoke.completed | Finished revoking workplace access tokens. success is false if some tokens could not be revoked | diff, success, failureCount |
workplace.notification_setting.security_secret_read.enable | Enabled forwarding of secret read events to logging services | None |
workplace.notification_setting.security_secret_read.disable | Disabled forwarding of secret read events to logging services | None |
settings.update | Changed workplace settings | None |
domains.add | Verified a domain | domain |
domains.delete | Removed a verified domain | domain |
tags.create | Created a project tag | Tag |
tags.rename | Renamed a project tag | tagId, oldTagName, newTagName |
tags.delete | Deleted a project tag | Tag |
enclave.secrets.referencing.enable | Enabled secret referencing for the whole workplace | None |
enclave.secrets.referencing.disable | Disabled secret referencing for the whole workplace | None |
enclave.inheritance.enable | Enabled config inheritance for the whole workplace | None |
enclave.inheritance.disable | Disabled config inheritance for the whole workplace | None |
Billing
| Type | Description | Metadata |
|---|---|---|
billing.plan.select | Selected a subscription plan | None |
billing.addons.add | Added a plan add-on | oldAddons, newAddons (arrays of add-on names) |
billing.addons.remove | Removed a plan add-on | oldAddons, newAddons (arrays of add-on names) |
billing.card.add | Added a credit card on file for billing | None |
billing.method.update | Switched the billing method between card and ACH | oldBillingMethod, newBillingMethod (Card or Automated clearing house) |
billing.coupon.add | Applied a coupon | couponName (nullable) |
billing.coupon.remove | Removed a coupon | None |
billing.referral.redeemed | Redeemed referral credit | referralCreditAmount |
billing.standing.update | The workplace billing standing changed, for example to past due, delinquent, suspended, or active | oldBillingStanding, newBillingStanding (Active, Past due, Delinquent, or Suspended) |
Team members and roles
| Type | Description | Metadata |
|---|---|---|
team.seat.invite.create | Invited someone to the workplace | email, workplaceRole |
team.seat.invite.delete | Removed a pending invite | email |
team.seat.join | A member joined the workplace by accepting an invite or through Email SSO, SAML SSO, or SCIM | joinMethod (for example Invite, Email SSO, SAML SSO, or SCIM) |
team.seat.update | Changed a member's workplace role | name, email, oldWorkplaceRole (nullable), newWorkplaceRole |
team.seat.delete | Removed a member from the workplace | name, email |
team.roles.update | Changed the default workplace role and/or the default project role given to new members | oldDefaultWorkplaceRole, newDefaultWorkplaceRole, oldDefaultProjectRole, newDefaultProjectRole (each nullable when unchanged) |
team.seat.token.personal.create | A member was issued a personal token | name, email |
team.seat.token.personal.roll | Rolled a member's personal token | name, email, reason (nullable) |
team.seat.token.personal.revoke | Revoked a member's personal token | name, email, reason (nullable) |
team.seat.token.cli.create | Created a CLI token by logging in with the Doppler CLI | None |
team.seat.token.cli.roll | Rolled a CLI token | None |
team.seat.token.cli.revoke | Revoked a CLI token | reason (nullable) |
Groups
| Type | Description | Metadata |
|---|---|---|
team.group.create | Created a group | Group |
team.group.rename | Renamed a group | groupId, groupUrl, oldGroupName, newGroupName |
team.group.delete | Deleted a group | Group |
team.group.members.add | Added one or more members to a group | Group + addedMembers (array of objects with name and email) |
team.group.member.remove | Removed a member from a group | Group + userName, userEmail |
team.group.workplace_role.update | Changed the workplace role granted by a group | Group + oldWorkplaceRole, newWorkplaceRole |
team.group.default_enclave_role.update | Changed or removed the default project role granted by a group | Group + oldDefaultRole (nullable), newDefaultRole (nullable) |
Service accounts
| Type | Description | Metadata |
|---|---|---|
team.service_account.create | Created a service account | Service account + workplaceRoleName (Custom Role when using custom permissions) |
team.service_account.rename | Renamed a service account | serviceAccountId, serviceAccountUrl, oldServiceAccountName, newServiceAccountName |
team.service_account.delete | Deleted a service account | Service account |
team.service_account.workplace_role.update | Changed a service account's workplace role | Service account + oldWorkplaceRoleName, newWorkplaceRoleName (Custom Role when using custom permissions) |
team.service_account.custom_workplace_permissions.update | Changed a service account's custom workplace permissions | Service account |
team.service_account.token.create | Created a service account token | Service account token |
team.service_account.token.rename | Renamed a service account token | Service account + serviceAccountTokenId, serviceAccountTokenApiKeyPreview, oldServiceAccountTokenName, newServiceAccountTokenName |
team.service_account.token.roll | Rolled a service account token | Service account token |
team.service_account.token.revoke | Revoked a service account token | Service account token + reason (nullable) |
team.service_account.identity.create | Created a service account identity | Service account identity |
team.service_account.identity.update | Updated a service account identity | Service account identity |
team.service_account.identity.delete | Deleted a service account identity | Service account identity |
team.service_account.identity.token.revoke | Revoked a short-lived token that was issued to a service account identity | Service account identity token |
SSO, SCIM, and Audit tokens
| Type | Description | Metadata |
|---|---|---|
team.sso.email | Changed Email SSO settings | None |
team.sso.email.enable | Enabled Email SSO | None |
team.sso.email.disable | Disabled Email SSO | None |
team.sso.saml | Changed SAML SSO settings | None |
team.sso.saml.enable | Enabled SAML SSO | domain (nullable) |
team.sso.saml.disable | Disabled SAML SSO. usedRecoveryCode is true if it was disabled with a recovery code | domain (nullable), usedRecoveryCode |
team.scim.enable | Enabled SCIM provisioning | groupManagement |
team.scim.update | Updated SCIM settings | groupManagement |
team.scim.disable | Disabled SCIM provisioning | None |
team.scim.token.create | Generated a SCIM token | None |
team.scim.token.roll | Rolled a SCIM token | None |
team.scim.token.revoke | Revoked a SCIM token | None |
team.audit.token.create | Generated an Audit token | None |
team.audit.token.roll | Rolled an Audit token | reason (nullable) |
team.audit.token.revoke | Revoked an Audit token | None |
Custom roles
| Type | Description | Metadata |
|---|---|---|
custom_roles.create | Created a custom role | type (workplace, project, or integration), name |
custom_roles.update | Changed a custom role's permissions | type, name |
custom_roles.rename | Renamed a custom role | type, oldName, newName |
custom_roles.delete | Deleted a custom role | type, name |
Enterprise Key Management
| Type | Description | Metadata |
|---|---|---|
workplace.ekm.set | Started a migration to a different key management engine | oldTokenEngineName, newTokenEngineName |
workplace.ekm.credentials_update | Updated the credentials used for Enterprise Key Management | tokenEngineName |
workplace.ekm.migration_completed | Completed a key management migration | tokenEngineName |
workplace.ekm.migration_canceled | Canceled a key management migration | tokenEngineName |
workplace.ekm.migration_failed | A key management migration failed and the workplace reverted to the previous engine | newTokenEngineName, fallbackTokenEngineName |
Workplace integrations
These events cover the integration connections managed on the workplace Integrations page, including who has access to each connection. Syncs that use a connection are recorded under Config syncs.
| Type | Description | Metadata |
|---|---|---|
workplace.integration.connect | Connected an integration | Integration |
workplace.integration.update | Updated an integration's configuration or credentials | Integration |
workplace.integration.rename | Renamed an integration | integrationId, integrationType, integrationUrl, oldIntegrationName, newIntegrationName |
workplace.integration.disable | Disabled an integration | Integration |
workplace.integration.delete | Removed an integration | Integration |
workplace.integration.access.user.create | Gave a member access to an integration | Integration + Member + role |
workplace.integration.access.user.role.update | Changed a member's role on an integration | Integration + Member + oldRole (nullable), newRole |
workplace.integration.access.user.delete | Removed a member's access to an integration | Integration + Member |
workplace.integration.access.group.create | Gave a group access to an integration | Integration + Group + role |
workplace.integration.access.group.role.update | Changed a group's role on an integration | Integration + Group + oldRole (nullable), newRole |
workplace.integration.access.group.delete | Removed a group's access to an integration | Integration + Group |
workplace.integration.access.service_account.create | Gave a service account access to an integration | Integration + Service account + role |
workplace.integration.access.service_account.role.update | Changed a service account's role on an integration | Integration + Service account + oldRole (nullable), newRole |
workplace.integration.access.service_account.delete | Removed a service account's access to an integration | Integration + Service account |
Logging and notification services
Each of the services that can receive Activity Logs or notifications has the same four events. Replace <service> with one of datadog, discord, generic_https, microsoft_teams, slack, splunk, sqs, or sumo_logic.
| Type | Description | Metadata |
|---|---|---|
services.<service>.connect | Connected the service, or re-enabled a disabled one | None |
services.<service>.update | Updated the service's URL, name, or credentials | None |
services.<service>.disconnect | Disabled the service. This is recorded both when a user disables it and when Doppler disables it automatically after repeated delivery failures | None |
services.<service>.delete | Deleted the service | None |
Projects
| Type | Description | Metadata |
|---|---|---|
enclave.project.create | Created a project | Project |
enclave.project.details.update | Changed a project's name or description | Project + previousProjectName (only present when renamed) |
enclave.project.delete | Deleted a project | Project |
enclave.project.secrets.referencing.enable | Enabled secret referencing for a project | Project |
enclave.project.secrets.referencing.disable | Disabled secret referencing for a project | Project |
enclave.project.inheritance.enable | Enabled config inheritance for a project | Project |
enclave.project.inheritance.disable | Disabled config inheritance for a project | Project |
enclave.project.secrets.notes.update | Updated secret notes | Config |
enclave.project.tags.assign | Assigned a tag to a project | Project + Tag |
enclave.project.tags.unassign | Removed a tag from a project | Project + Tag |
Project access
| Type | Description | Metadata |
|---|---|---|
enclave.project.access.create | Added a member to a project | Project + Member + role |
enclave.project.access.update | Changed which environments a member can access in a project | Project + Member |
enclave.project.access.role.update | Changed a member's project role | Project + Member + oldRole (nullable), newRole |
enclave.project.access.delete | Removed a member from a project | Project + Member |
enclave.project.access.group.create | Added a group to a project | Project + Group + role |
enclave.project.access.group.update | Changed which environments a group can access in a project | Project + Group |
enclave.project.access.group.role.update | Changed a group's project role | Project + Group + oldRole (nullable), newRole |
enclave.project.access.group.delete | Removed a group from a project | Project + Group |
enclave.project.access.service_account.create | Added a service account to a project | Project + Service account + role |
enclave.project.access.service_account.update | Changed which environments a service account can access in a project | Project + Service account |
enclave.project.access.service_account.role.update | Changed a service account's project role | Project + Service account + oldRole (nullable), newRole |
enclave.project.access.service_account.delete | Removed a service account from a project | Project + Service account |
Environments
| Type | Description | Metadata |
|---|---|---|
enclave.project.environment.create | Created an environment | Environment |
enclave.project.environment.rename | Renamed an environment | Project + oldEnvironmentName, newEnvironmentName, oldEnvironmentId, newEnvironmentId |
enclave.project.environment.settings.update | Enabled or disabled personal configs in an environment | Environment + personalConfigsEnabled |
enclave.project.environment.delete | Deleted an environment | Environment |
Configs
| Type | Description | Metadata |
|---|---|---|
enclave.project.config.create | Created a config | Config |
enclave.project.config.rename | Renamed a config | Project + configUrl, oldConfigName, newConfigName |
enclave.project.config.duplicate | Duplicated a config | Config |
enclave.project.config.lock | Locked a config | Config |
enclave.project.config.unlock | Unlocked a config | Config |
enclave.project.config.delete | Deleted a config | Project + configName |
enclave.project.config.secrets.referencing.enable | Enabled secret referencing for a config | Config |
enclave.project.config.secrets.referencing.disable | Disabled secret referencing for a config | Config |
enclave.project.config.inheritable.enable | Allowed a config to be inherited by other configs | Config |
enclave.project.config.inheritable.disable | Stopped a config from being inherited by other configs | Config |
enclave.project.config.inherits.update | Changed which configs a config inherits from | Config + diff |
enclave.project.config.trusted_ips.update | Changed a config's trusted IP ranges | Config |
enclave.project.config.service_token.create | Created a service token for a config | Config + serviceTokenName, readAccess, writeAccess, autoExpires |
enclave.project.config.service_token.delete | Deleted a service token | Config + serviceTokenName (nullable), reason (nullable) |
Secrets
| Type | Description | Metadata |
|---|---|---|
enclave.project.config.secrets.update | Secrets were added, updated, or removed in a config. This includes changes applied by merging a change request (changeRequest is set) and secrets imported from an external site (importedSecretFrom is set) | Config + diff, diffUrl, changeRequest (nullable), pullRequest (nullable), importedSecretFrom (nullable) |
enclave.project.config.secrets.share | Created a one-time share link for a secret | Config + secretName, viewsUntilExpiration, daysUntilExpiration |
enclave.project.config.secrets.redact | Redacted one previous version of a secret from its history | Config + secretName |
enclave.project.config.secrets.redact.all | Redacted every previous version of a secret from its history | Config + secretName |
enclave.project.config.secrets.dismiss | Dismissed missing-secret warnings for secrets that exist in other environments but not in this config | Config + secretNames |
enclave.project.config.secrets.undismiss | Restored previously dismissed missing-secret warnings | Config + secretNames |
Secret reminders
| Type | Description | Metadata |
|---|---|---|
enclave.project.secrets.reminders.create | Created a reminder for a secret | Environment + secretName |
enclave.project.secrets.reminders.update | Updated a reminder for a secret | Environment + secretName |
enclave.project.secrets.reminders.dismiss | Dismissed a reminder for a secret | Environment + secretName |
enclave.project.secrets.reminders.delete | Deleted a reminder for a secret | Environment + secretName |
Config syncs
| Type | Description | Metadata |
|---|---|---|
enclave.project.integration.create | Added a sync to a config | Config + integrationName, integrationDescription |
enclave.project.integration.enable | Enabled a sync | Config + integrationName, integrationDescription |
enclave.project.integration.disable | Disabled a sync | Config + integrationName, integrationDescription |
enclave.project.integration.delete | Removed a sync. integrationDeleteReason is set when Doppler removed it after a setup or import failure | Config + integrationName, integrationDescription, integrationDeleteReason (Import Failure, Setup Failure, or null) |
Dynamic secrets
| Type | Description | Metadata |
|---|---|---|
enclave.project.dynamic_secrets.create | Created a dynamic secret | Config + secretName |
enclave.project.dynamic_secrets.delete | Deleted a dynamic secret | Config + secretName |
enclave.project.dynamic_secrets.leases.issue | Issued a lease for a dynamic secret | Config + secretName, leaseName |
enclave.project.dynamic_secrets.leases.revoke | Revoked a lease for a dynamic secret | Config + secretName, leaseName |
Rotated secrets
| Type | Description | Metadata |
|---|---|---|
enclave.project.rotated_secrets.create | Created a rotated secret | Config + rotatedSecretName |
enclave.project.rotated_secrets.rotate | Rotated a secret, either on schedule or manually | Config + rotatedSecretName |
enclave.project.rotated_secrets.rename | Renamed a rotated secret | Config + rotatedSecretName, oldRotatedSecretName (nullable), diff |
enclave.project.rotated_secrets.settings.update | Changed a rotated secret's rotation settings | Config + rotatedSecretName |
enclave.project.rotated_secrets.enable | Enabled rotation for a rotated secret | Config + rotatedSecretName |
enclave.project.rotated_secrets.disable | Disabled rotation for a rotated secret | Config + rotatedSecretName |
enclave.project.rotated_secrets.delete | Deleted a rotated secret | Config + rotatedSecretName |
Webhooks
| Type | Description | Metadata |
|---|---|---|
enclave.project.webhook.create | Added a webhook to a project | Project + webhookName |
enclave.project.webhook.update | Updated a webhook | Project + webhookName |
enclave.project.webhook.enable | Enabled a webhook | Project + webhookName |
enclave.project.webhook.disable | Disabled a webhook | Project + webhookName |
enclave.project.webhook.delete | Removed a webhook | Project + webhookName |
Change requests
| Type | Description | Metadata |
|---|---|---|
enclave.change_request.create | Opened a change request | Change request |
enclave.change_request.update | Updated, closed, or reopened a change request, or changed its assigned reviewers | Change request |
enclave.change_request_unit.review_create | Approved the changes to one config within a change request | Change request unit |
enclave.change_request_unit.review_rescind | Withdrew an approval of the changes to one config within a change request | Change request unit |
enclave.change_request_unit.noop_apply | Merged the changes to one config within a change request, but no secrets actually changed. When secrets do change, an enclave.project.config.secrets.update event is recorded instead | Change request unit |
Change request policies
| Type | Description | Metadata |
|---|---|---|
enclave.change_request_policy.create | Created a change request policy | Change request policy |
enclave.change_request_policy.update_definition | Changed a change request policy's name, description, or rules | Change request policy |
enclave.change_request_policy.update_targets | Changed which projects and configs a change request policy applies to | Change request policy |
enclave.change_request_policy.delete | Deleted a change request policy | Change request policy |
Legacy event types
Doppler no longer generates the following event types. Entries of these types may still exist in older workplaces and be returned by the Activity Logs API, but they are never delivered to logging services, since delivery only happens when an entry is created.
| Type | Description |
|---|---|
enclave.project.config.secrets.download | Downloaded a config's secrets. This is now recorded only in the config's log |
enclave.project.pull_request.create, enclave.project.pull_request.approve, enclave.project.pull_request.close, enclave.project.pull_request.merge | Doppler's former pull request feature |
enclave.project.config.cloud.heroku, enclave.project.config.cloud.heroku.enable, enclave.project.config.cloud.heroku.update, enclave.project.config.cloud.heroku.disable | The former Heroku sync |
enclave.project.defaults.update | The former project defaults feature |
services.github.connect, services.github.disconnect | GitHub connections for the former Radar product |
services.heroku.connect, services.heroku.disconnect | The former Heroku connection |
radar.repository.file.ignore, radar.repository.file.track, radar.repository.secret.ignore, radar.repository.secret.track | The former Radar product |
team.group.role.update | Changed a group's project access role |
Updated about 5 hours ago

