Activity Log Event Schema

Learn about the schema used in Doppler Activity Log events

When a logging service is connected to your workplace, Doppler delivers every new Activity Log entry to it as a JSON document. This page describes that document, the actor and metadata objects it contains, and every event type Doppler currently generates.

This schema applies to the logging services: AWS SQS, Datadog, Generic HTTPS, Splunk, and Sumo Logic. The chat services (Slack, Microsoft Teams, and Discord) receive a message formatted for that chat platform instead and are not covered here.

Payload Structure

FieldTypeDescription
sourcestringAlways doppler. Datadog payloads use the field name ddsource instead of source.
slugstringUnique identifier of the Activity Log entry. This is the same value returned as id by the Activity Logs API.
typestringThe event type. See Events for the full list.
titlestringAlways Activity Log: <slug>.
textstringHuman-readable description of the event as HTML. Only <a>, <br>, <em>, <span>, and <strong> tags are used. Links point to the Doppler dashboard, use mailto: when they refer to a person, or point to the external site a secret was imported from. For events that carry a diff, up to 10 changed names are appended as a bulleted list followed by and N others... when there are more.
userobjectThe actor that performed the action. See Actor.
linkstringDashboard URL that opens this entry in the workplace Activity Log.
workplaceobjectid (the workplace slug) and name of the workplace the event belongs to.
createdAtstringISO 8601 timestamp of when the event occurred.
metadataobjectStructured, event-specific fields. See Metadata. If Doppler is unable to build the metadata for an entry, the payload is still delivered but this field is omitted.

Delivery differences between services

The document above is the same for every logging service, with these exceptions:

  • Datadog: the source field is named ddsource.
  • Splunk: the document is wrapped in an event object to match the HTTP Event Collector format, for example { "event": { "source": "doppler", ... } }.
  • AWS SQS: the document is sent as the message body, serialized as a JSON string.
  • Generic HTTPS and Sumo Logic: the document is sent as the JSON body of an HTTPS POST request.

Examples

The tabs below show a secrets update in a config, a workplace-level event with no project, an automated action attributed to the Doppler Bot, and a change request review.

{
  "source": "doppler",
  "slug": "ZbDEAEqJEQI9kbTuFLIBHE0J",
  "type": "enclave.project.config.secrets.update",
  "title": "Activity Log: ZbDEAEqJEQI9kbTuFLIBHE0J",
  "text": "Modified secrets in <a class=\"text-purple-500 hover:underline\" rel=\"noopener\" href=\"https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend/configs/dev\">dev</a> of <a class=\"text-purple-500 hover:underline\" rel=\"noopener\" href=\"https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend\">backend</a> project with <a class=\"text-purple-500 hover:underline\" rel=\"noopener\" href=\"https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend/configs/dev/logs?id=fQ2mXk8ZpB4vLr7NwT1cYd6H\">1 added and 1 updated</a>:<br>• STRIPE_API_KEY<br>• DATABASE_URL",
  "user": {
    "kind": "user",
    "slug": "36c1e2ad-ec82-4f01-9711-31047d9accd8",
    "email": "[email protected]",
    "name": "John Doe",
    "username": "jdoe",
    "profile_image_url": "https://www.gravatar.com/avatar/a1b2c3d4e5f6a7b8c9d0a1b2c3d4e5f6a7b8c9d0?s=500&d=retro"
  },
  "link": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/logs?id=ZbDEAEqJEQI9kbTuFLIBHE0J",
  "workplace": {
    "id": "a1b2c3d4e5f6a7b8c9d0",
    "name": "Doppler University"
  },
  "createdAt": "2025-11-17T15:40:41.624Z",
  "metadata": {
    "projectId": "backend",
    "projectName": "backend",
    "projectUrl": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend",
    "projectDescription": "Backend API service",
    "configName": "dev",
    "configUrl": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend/configs/dev",
    "changeRequest": null,
    "pullRequest": null,
    "diff": {
      "added": ["STRIPE_API_KEY"],
      "removed": [],
      "updated": ["DATABASE_URL"]
    },
    "diffUrl": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend/configs/dev/logs?id=fQ2mXk8ZpB4vLr7NwT1cYd6H",
    "importedSecretFrom": null
  }
}
{
  "source": "doppler",
  "slug": "Hk3rT9wLmQ2xVb7nYc5dPf8J",
  "type": "team.seat.update",
  "title": "Activity Log: Hk3rT9wLmQ2xVb7nYc5dPf8J",
  "text": "Changed <a class=\"text-purple-500 hover:underline\" rel=\"noopener\" href=\"https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/team/users/7d2f6a1e-3c4b-4e8f-9a0b-1c2d3e4f5a6b\">Jane Doe</a> access from <strong>collaborator</strong> to <strong>admin</strong>",
  "user": {
    "kind": "user",
    "slug": "36c1e2ad-ec82-4f01-9711-31047d9accd8",
    "email": "[email protected]",
    "name": "John Doe",
    "username": "jdoe",
    "profile_image_url": "https://www.gravatar.com/avatar/a1b2c3d4e5f6a7b8c9d0a1b2c3d4e5f6a7b8c9d0?s=500&d=retro"
  },
  "link": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/logs?id=Hk3rT9wLmQ2xVb7nYc5dPf8J",
  "workplace": {
    "id": "a1b2c3d4e5f6a7b8c9d0",
    "name": "Doppler University"
  },
  "createdAt": "2025-11-17T16:02:13.918Z",
  "metadata": {
    "name": "Jane Doe",
    "email": "[email protected]",
    "oldWorkplaceRole": "collaborator",
    "newWorkplaceRole": "admin"
  }
}
{
  "source": "doppler",
  "slug": "Qw8nB2vXc5zLk9mJt4rYh7Gd",
  "type": "enclave.project.rotated_secrets.rotate",
  "title": "Activity Log: Qw8nB2vXc5zLk9mJt4rYh7Gd",
  "text": "Rotated secret <strong>DB_PASSWORD</strong> in config <a class=\"text-purple-500 hover:underline\" rel=\"noopener\" href=\"https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend/configs/prd\">prd</a> in project <a class=\"text-purple-500 hover:underline\" rel=\"noopener\" href=\"https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend\">backend</a>",
  "user": {
    "kind": "bot",
    "slug": "doppler",
    "type": "doppler",
    "name": "Doppler Bot",
    "username": "doppler-bot",
    "profile_image_url": "https://dashboard.doppler.com/imgs/logo_color.png",
    "is_bot": true
  },
  "link": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/logs?id=Qw8nB2vXc5zLk9mJt4rYh7Gd",
  "workplace": {
    "id": "a1b2c3d4e5f6a7b8c9d0",
    "name": "Doppler University"
  },
  "createdAt": "2025-11-18T03:00:04.211Z",
  "metadata": {
    "projectId": "backend",
    "projectName": "backend",
    "projectUrl": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend",
    "projectDescription": "Backend API service",
    "configName": "prd",
    "configUrl": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend/configs/prd",
    "rotatedSecretName": "DB_PASSWORD"
  }
}
{
  "source": "doppler",
  "slug": "Ld5pR8tKw2mZx7vBn3cQj9Yf",
  "type": "enclave.change_request_unit.review_create",
  "title": "Activity Log: Ld5pR8tKw2mZx7vBn3cQj9Yf",
  "text": "Approved changes in CR <a class=\"text-purple-500 hover:underline\" rel=\"noopener\" href=\"https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/change-requests/cr_01JD3Y5K8QW2ZP7X4NVBM6TR9E\">Rotate Stripe keys</a> into <a class=\"text-purple-500 hover:underline\" rel=\"noopener\" href=\"https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend/configs/prd\">prd</a> of <a class=\"text-purple-500 hover:underline\" rel=\"noopener\" href=\"https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend\">backend</a>",
  "user": {
    "kind": "user",
    "slug": "36c1e2ad-ec82-4f01-9711-31047d9accd8",
    "email": "[email protected]",
    "name": "John Doe",
    "username": "jdoe",
    "profile_image_url": "https://www.gravatar.com/avatar/a1b2c3d4e5f6a7b8c9d0a1b2c3d4e5f6a7b8c9d0?s=500&d=retro"
  },
  "link": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/logs?id=Ld5pR8tKw2mZx7vBn3cQj9Yf",
  "workplace": {
    "id": "a1b2c3d4e5f6a7b8c9d0",
    "name": "Doppler University"
  },
  "createdAt": "2025-11-18T14:27:50.402Z",
  "metadata": {
    "projectId": "backend",
    "projectName": "backend",
    "projectUrl": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend",
    "projectDescription": "Backend API service",
    "configName": "prd",
    "configUrl": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/projects/backend/configs/prd",
    "changeRequestId": "cr_01JD3Y5K8QW2ZP7X4NVBM6TR9E",
    "changeRequestTitle": "Rotate Stripe keys",
    "changeRequestUrl": "https://dashboard.doppler.com/workplace/a1b2c3d4e5f6a7b8c9d0/change-requests/cr_01JD3Y5K8QW2ZP7X4NVBM6TR9E",
    "changeRequestUnitId": "cru_01JD3Y6R2VX8QT4WN7ZKP5MBH3"
  }
}
  • Secrets update: diffUrl opens the corresponding entry in the config's own log, which has a different identifier than the Activity Log entry. When the update came from a merged change request, changeRequest is an object with id, title, unitId, and requestUrl. When a secret was imported from an external site, importedSecretFrom is the origin it came from (for example https://vercel.com).
  • Workplace event: events that happen at the workplace level carry only the fields relevant to that event in metadata. This entry records a member's workplace role being changed.
  • Bot actor: actions Doppler performs on your behalf, such as a scheduled secret rotation, are attributed to a bot actor rather than a person.
  • Change request: change request events combine the config being changed with details of the change request itself.

Actor

The user field identifies who or what performed the action. The kind field tells you which shape to expect.

kindDescriptionFields
userA workplace member acting through the dashboard, CLI, or a personal token.slug, email, name, username, profile_image_url
serviceAccountA service account acting through one of its tokens or identities.slug, name
apiTokenA workplace-level token acting directly: a config service token, a SCIM token, or an Audit token.slug, name (may be null), type (an object with id and name, where id is one of enclave_service_token, workplace_scim_token, or workplace_audit_token and name is Service, SCIM, or Audit respectively)
botDoppler itself, for automated actions such as scheduled secret rotation or a sync, or the GitHub bot for GitHub-initiated actions.slug, type (doppler or github; older entries may also use heroku or scim), name, username, profile_image_url, is_bot (always true)

Examples of the serviceAccount and apiToken shapes:

{
  "kind": "serviceAccount",
  "slug": "ci-deployer",
  "name": "CI Deployer"
}
{
  "kind": "apiToken",
  "slug": "f4b1c8e2-6d7a-4a9e-b3c5-2e1f0d9a8b7c",
  "name": "prd-api-server",
  "type": {
    "id": "enclave_service_token",
    "name": "Service"
  }
}

Metadata

metadata contains structured fields specific to the event type, so you can filter and route events without parsing text. Many event types share the same groups of fields. The groups are defined here and referenced by name in the Events tables.

GroupFields
ProjectprojectId, projectName, projectUrl, projectDescription
ConfigProject + configName, configUrl
EnvironmentProject + environmentName, environmentId
MemberuserName, userEmail. For a member who has not yet accepted their invite, userName is null and userEmail is the invited address. Both are null if the member can no longer be resolved.
GroupgroupId, groupName, groupUrl
TagtagId, tagName
Service accountserviceAccountId, serviceAccountName, serviceAccountUrl
Service account tokenService account + serviceAccountTokenId, serviceAccountTokenName (may be null), serviceAccountTokenApiKeyPreview
Service account identityService account + serviceAccountIdentityId, serviceAccountIdentityName
Service account identity tokenService account identity + serviceAccountIdentityAPITokenId, serviceAccountIdentityTokenAPIKeyPreview
IntegrationintegrationId, integrationType, integrationName, integrationUrl
Change requestchangeRequestId, changeRequestTitle, changeRequestUrl. Also changeRequestNewStatus (open or closed) when the status changed, and changeRequestAssigned (an object with added and removed counts) when the assigned reviewers changed.
Change request unitConfig + Change request + changeRequestUnitId
Change request policychangeRequestPolicyId, changeRequestPolicyName, changeRequestPolicyUrl

A diff field, where present, is an object with added, removed, and updated arrays of names.

Events

Each table lists the event type, what it records, and the fields present in metadata. "None" means metadata is an empty object. Fields marked nullable are present but null when the value is not applicable.

Workplace

TypeDescriptionMetadata
workplace.createCreated the workplacebillingPlan
workplace.deleteDeleted the workplacereason (nullable)
workplace.default_environments.updateChanged the default environments that new projects are created withNone
workplace.default_environments_view.updateChanged how default environments are displayedoldView (nullable), newView
workplace.secret_naming.type.updateChanged the workplace secret naming rules between Classic and PermissiveprevSecretNamingType, secretNamingType (classic or permissive)
workplace.sessions.invalidate.completedFinished invalidating every dashboard session in the workplace. success is false if some sessions could not be invalidatedsuccess, failureCount
workplace.tokens.revoke.initiatedStarted revoking every personal and/or CLI token in the workplacepersonal, cli
workplace.tokens.revoke.completedFinished revoking workplace access tokens. success is false if some tokens could not be revokeddiff, success, failureCount
workplace.notification_setting.security_secret_read.enableEnabled forwarding of secret read events to logging servicesNone
workplace.notification_setting.security_secret_read.disableDisabled forwarding of secret read events to logging servicesNone
settings.updateChanged workplace settingsNone
domains.addVerified a domaindomain
domains.deleteRemoved a verified domaindomain
tags.createCreated a project tagTag
tags.renameRenamed a project tagtagId, oldTagName, newTagName
tags.deleteDeleted a project tagTag
enclave.secrets.referencing.enableEnabled secret referencing for the whole workplaceNone
enclave.secrets.referencing.disableDisabled secret referencing for the whole workplaceNone
enclave.inheritance.enableEnabled config inheritance for the whole workplaceNone
enclave.inheritance.disableDisabled config inheritance for the whole workplaceNone

Billing

TypeDescriptionMetadata
billing.plan.selectSelected a subscription planNone
billing.addons.addAdded a plan add-onoldAddons, newAddons (arrays of add-on names)
billing.addons.removeRemoved a plan add-onoldAddons, newAddons (arrays of add-on names)
billing.card.addAdded a credit card on file for billingNone
billing.method.updateSwitched the billing method between card and ACHoldBillingMethod, newBillingMethod (Card or Automated clearing house)
billing.coupon.addApplied a couponcouponName (nullable)
billing.coupon.removeRemoved a couponNone
billing.referral.redeemedRedeemed referral creditreferralCreditAmount
billing.standing.updateThe workplace billing standing changed, for example to past due, delinquent, suspended, or activeoldBillingStanding, newBillingStanding (Active, Past due, Delinquent, or Suspended)

Team members and roles

TypeDescriptionMetadata
team.seat.invite.createInvited someone to the workplaceemail, workplaceRole
team.seat.invite.deleteRemoved a pending inviteemail
team.seat.joinA member joined the workplace by accepting an invite or through Email SSO, SAML SSO, or SCIMjoinMethod (for example Invite, Email SSO, SAML SSO, or SCIM)
team.seat.updateChanged a member's workplace rolename, email, oldWorkplaceRole (nullable), newWorkplaceRole
team.seat.deleteRemoved a member from the workplacename, email
team.roles.updateChanged the default workplace role and/or the default project role given to new membersoldDefaultWorkplaceRole, newDefaultWorkplaceRole, oldDefaultProjectRole, newDefaultProjectRole (each nullable when unchanged)
team.seat.token.personal.createA member was issued a personal tokenname, email
team.seat.token.personal.rollRolled a member's personal tokenname, email, reason (nullable)
team.seat.token.personal.revokeRevoked a member's personal tokenname, email, reason (nullable)
team.seat.token.cli.createCreated a CLI token by logging in with the Doppler CLINone
team.seat.token.cli.rollRolled a CLI tokenNone
team.seat.token.cli.revokeRevoked a CLI tokenreason (nullable)

Groups

TypeDescriptionMetadata
team.group.createCreated a groupGroup
team.group.renameRenamed a groupgroupId, groupUrl, oldGroupName, newGroupName
team.group.deleteDeleted a groupGroup
team.group.members.addAdded one or more members to a groupGroup + addedMembers (array of objects with name and email)
team.group.member.removeRemoved a member from a groupGroup + userName, userEmail
team.group.workplace_role.updateChanged the workplace role granted by a groupGroup + oldWorkplaceRole, newWorkplaceRole
team.group.default_enclave_role.updateChanged or removed the default project role granted by a groupGroup + oldDefaultRole (nullable), newDefaultRole (nullable)

Service accounts

TypeDescriptionMetadata
team.service_account.createCreated a service accountService account + workplaceRoleName (Custom Role when using custom permissions)
team.service_account.renameRenamed a service accountserviceAccountId, serviceAccountUrl, oldServiceAccountName, newServiceAccountName
team.service_account.deleteDeleted a service accountService account
team.service_account.workplace_role.updateChanged a service account's workplace roleService account + oldWorkplaceRoleName, newWorkplaceRoleName (Custom Role when using custom permissions)
team.service_account.custom_workplace_permissions.updateChanged a service account's custom workplace permissionsService account
team.service_account.token.createCreated a service account tokenService account token
team.service_account.token.renameRenamed a service account tokenService account + serviceAccountTokenId, serviceAccountTokenApiKeyPreview, oldServiceAccountTokenName, newServiceAccountTokenName
team.service_account.token.rollRolled a service account tokenService account token
team.service_account.token.revokeRevoked a service account tokenService account token + reason (nullable)
team.service_account.identity.createCreated a service account identityService account identity
team.service_account.identity.updateUpdated a service account identityService account identity
team.service_account.identity.deleteDeleted a service account identityService account identity
team.service_account.identity.token.revokeRevoked a short-lived token that was issued to a service account identityService account identity token

SSO, SCIM, and Audit tokens

TypeDescriptionMetadata
team.sso.emailChanged Email SSO settingsNone
team.sso.email.enableEnabled Email SSONone
team.sso.email.disableDisabled Email SSONone
team.sso.samlChanged SAML SSO settingsNone
team.sso.saml.enableEnabled SAML SSOdomain (nullable)
team.sso.saml.disableDisabled SAML SSO. usedRecoveryCode is true if it was disabled with a recovery codedomain (nullable), usedRecoveryCode
team.scim.enableEnabled SCIM provisioninggroupManagement
team.scim.updateUpdated SCIM settingsgroupManagement
team.scim.disableDisabled SCIM provisioningNone
team.scim.token.createGenerated a SCIM tokenNone
team.scim.token.rollRolled a SCIM tokenNone
team.scim.token.revokeRevoked a SCIM tokenNone
team.audit.token.createGenerated an Audit tokenNone
team.audit.token.rollRolled an Audit tokenreason (nullable)
team.audit.token.revokeRevoked an Audit tokenNone

Custom roles

TypeDescriptionMetadata
custom_roles.createCreated a custom roletype (workplace, project, or integration), name
custom_roles.updateChanged a custom role's permissionstype, name
custom_roles.renameRenamed a custom roletype, oldName, newName
custom_roles.deleteDeleted a custom roletype, name

Enterprise Key Management

TypeDescriptionMetadata
workplace.ekm.setStarted a migration to a different key management engineoldTokenEngineName, newTokenEngineName
workplace.ekm.credentials_updateUpdated the credentials used for Enterprise Key ManagementtokenEngineName
workplace.ekm.migration_completedCompleted a key management migrationtokenEngineName
workplace.ekm.migration_canceledCanceled a key management migrationtokenEngineName
workplace.ekm.migration_failedA key management migration failed and the workplace reverted to the previous enginenewTokenEngineName, fallbackTokenEngineName

Workplace integrations

These events cover the integration connections managed on the workplace Integrations page, including who has access to each connection. Syncs that use a connection are recorded under Config syncs.

TypeDescriptionMetadata
workplace.integration.connectConnected an integrationIntegration
workplace.integration.updateUpdated an integration's configuration or credentialsIntegration
workplace.integration.renameRenamed an integrationintegrationId, integrationType, integrationUrl, oldIntegrationName, newIntegrationName
workplace.integration.disableDisabled an integrationIntegration
workplace.integration.deleteRemoved an integrationIntegration
workplace.integration.access.user.createGave a member access to an integrationIntegration + Member + role
workplace.integration.access.user.role.updateChanged a member's role on an integrationIntegration + Member + oldRole (nullable), newRole
workplace.integration.access.user.deleteRemoved a member's access to an integrationIntegration + Member
workplace.integration.access.group.createGave a group access to an integrationIntegration + Group + role
workplace.integration.access.group.role.updateChanged a group's role on an integrationIntegration + Group + oldRole (nullable), newRole
workplace.integration.access.group.deleteRemoved a group's access to an integrationIntegration + Group
workplace.integration.access.service_account.createGave a service account access to an integrationIntegration + Service account + role
workplace.integration.access.service_account.role.updateChanged a service account's role on an integrationIntegration + Service account + oldRole (nullable), newRole
workplace.integration.access.service_account.deleteRemoved a service account's access to an integrationIntegration + Service account

Logging and notification services

Each of the services that can receive Activity Logs or notifications has the same four events. Replace <service> with one of datadog, discord, generic_https, microsoft_teams, slack, splunk, sqs, or sumo_logic.

TypeDescriptionMetadata
services.<service>.connectConnected the service, or re-enabled a disabled oneNone
services.<service>.updateUpdated the service's URL, name, or credentialsNone
services.<service>.disconnectDisabled the service. This is recorded both when a user disables it and when Doppler disables it automatically after repeated delivery failuresNone
services.<service>.deleteDeleted the serviceNone

Projects

TypeDescriptionMetadata
enclave.project.createCreated a projectProject
enclave.project.details.updateChanged a project's name or descriptionProject + previousProjectName (only present when renamed)
enclave.project.deleteDeleted a projectProject
enclave.project.secrets.referencing.enableEnabled secret referencing for a projectProject
enclave.project.secrets.referencing.disableDisabled secret referencing for a projectProject
enclave.project.inheritance.enableEnabled config inheritance for a projectProject
enclave.project.inheritance.disableDisabled config inheritance for a projectProject
enclave.project.secrets.notes.updateUpdated secret notesConfig
enclave.project.tags.assignAssigned a tag to a projectProject + Tag
enclave.project.tags.unassignRemoved a tag from a projectProject + Tag

Project access

TypeDescriptionMetadata
enclave.project.access.createAdded a member to a projectProject + Member + role
enclave.project.access.updateChanged which environments a member can access in a projectProject + Member
enclave.project.access.role.updateChanged a member's project roleProject + Member + oldRole (nullable), newRole
enclave.project.access.deleteRemoved a member from a projectProject + Member
enclave.project.access.group.createAdded a group to a projectProject + Group + role
enclave.project.access.group.updateChanged which environments a group can access in a projectProject + Group
enclave.project.access.group.role.updateChanged a group's project roleProject + Group + oldRole (nullable), newRole
enclave.project.access.group.deleteRemoved a group from a projectProject + Group
enclave.project.access.service_account.createAdded a service account to a projectProject + Service account + role
enclave.project.access.service_account.updateChanged which environments a service account can access in a projectProject + Service account
enclave.project.access.service_account.role.updateChanged a service account's project roleProject + Service account + oldRole (nullable), newRole
enclave.project.access.service_account.deleteRemoved a service account from a projectProject + Service account

Environments

TypeDescriptionMetadata
enclave.project.environment.createCreated an environmentEnvironment
enclave.project.environment.renameRenamed an environmentProject + oldEnvironmentName, newEnvironmentName, oldEnvironmentId, newEnvironmentId
enclave.project.environment.settings.updateEnabled or disabled personal configs in an environmentEnvironment + personalConfigsEnabled
enclave.project.environment.deleteDeleted an environmentEnvironment

Configs

TypeDescriptionMetadata
enclave.project.config.createCreated a configConfig
enclave.project.config.renameRenamed a configProject + configUrl, oldConfigName, newConfigName
enclave.project.config.duplicateDuplicated a configConfig
enclave.project.config.lockLocked a configConfig
enclave.project.config.unlockUnlocked a configConfig
enclave.project.config.deleteDeleted a configProject + configName
enclave.project.config.secrets.referencing.enableEnabled secret referencing for a configConfig
enclave.project.config.secrets.referencing.disableDisabled secret referencing for a configConfig
enclave.project.config.inheritable.enableAllowed a config to be inherited by other configsConfig
enclave.project.config.inheritable.disableStopped a config from being inherited by other configsConfig
enclave.project.config.inherits.updateChanged which configs a config inherits fromConfig + diff
enclave.project.config.trusted_ips.updateChanged a config's trusted IP rangesConfig
enclave.project.config.service_token.createCreated a service token for a configConfig + serviceTokenName, readAccess, writeAccess, autoExpires
enclave.project.config.service_token.deleteDeleted a service tokenConfig + serviceTokenName (nullable), reason (nullable)

Secrets

TypeDescriptionMetadata
enclave.project.config.secrets.updateSecrets were added, updated, or removed in a config. This includes changes applied by merging a change request (changeRequest is set) and secrets imported from an external site (importedSecretFrom is set)Config + diff, diffUrl, changeRequest (nullable), pullRequest (nullable), importedSecretFrom (nullable)
enclave.project.config.secrets.shareCreated a one-time share link for a secretConfig + secretName, viewsUntilExpiration, daysUntilExpiration
enclave.project.config.secrets.redactRedacted one previous version of a secret from its historyConfig + secretName
enclave.project.config.secrets.redact.allRedacted every previous version of a secret from its historyConfig + secretName
enclave.project.config.secrets.dismissDismissed missing-secret warnings for secrets that exist in other environments but not in this configConfig + secretNames
enclave.project.config.secrets.undismissRestored previously dismissed missing-secret warningsConfig + secretNames

Secret reminders

TypeDescriptionMetadata
enclave.project.secrets.reminders.createCreated a reminder for a secretEnvironment + secretName
enclave.project.secrets.reminders.updateUpdated a reminder for a secretEnvironment + secretName
enclave.project.secrets.reminders.dismissDismissed a reminder for a secretEnvironment + secretName
enclave.project.secrets.reminders.deleteDeleted a reminder for a secretEnvironment + secretName

Config syncs

TypeDescriptionMetadata
enclave.project.integration.createAdded a sync to a configConfig + integrationName, integrationDescription
enclave.project.integration.enableEnabled a syncConfig + integrationName, integrationDescription
enclave.project.integration.disableDisabled a syncConfig + integrationName, integrationDescription
enclave.project.integration.deleteRemoved a sync. integrationDeleteReason is set when Doppler removed it after a setup or import failureConfig + integrationName, integrationDescription, integrationDeleteReason (Import Failure, Setup Failure, or null)

Dynamic secrets

TypeDescriptionMetadata
enclave.project.dynamic_secrets.createCreated a dynamic secretConfig + secretName
enclave.project.dynamic_secrets.deleteDeleted a dynamic secretConfig + secretName
enclave.project.dynamic_secrets.leases.issueIssued a lease for a dynamic secretConfig + secretName, leaseName
enclave.project.dynamic_secrets.leases.revokeRevoked a lease for a dynamic secretConfig + secretName, leaseName

Rotated secrets

TypeDescriptionMetadata
enclave.project.rotated_secrets.createCreated a rotated secretConfig + rotatedSecretName
enclave.project.rotated_secrets.rotateRotated a secret, either on schedule or manuallyConfig + rotatedSecretName
enclave.project.rotated_secrets.renameRenamed a rotated secretConfig + rotatedSecretName, oldRotatedSecretName (nullable), diff
enclave.project.rotated_secrets.settings.updateChanged a rotated secret's rotation settingsConfig + rotatedSecretName
enclave.project.rotated_secrets.enableEnabled rotation for a rotated secretConfig + rotatedSecretName
enclave.project.rotated_secrets.disableDisabled rotation for a rotated secretConfig + rotatedSecretName
enclave.project.rotated_secrets.deleteDeleted a rotated secretConfig + rotatedSecretName

Webhooks

TypeDescriptionMetadata
enclave.project.webhook.createAdded a webhook to a projectProject + webhookName
enclave.project.webhook.updateUpdated a webhookProject + webhookName
enclave.project.webhook.enableEnabled a webhookProject + webhookName
enclave.project.webhook.disableDisabled a webhookProject + webhookName
enclave.project.webhook.deleteRemoved a webhookProject + webhookName

Change requests

TypeDescriptionMetadata
enclave.change_request.createOpened a change requestChange request
enclave.change_request.updateUpdated, closed, or reopened a change request, or changed its assigned reviewersChange request
enclave.change_request_unit.review_createApproved the changes to one config within a change requestChange request unit
enclave.change_request_unit.review_rescindWithdrew an approval of the changes to one config within a change requestChange request unit
enclave.change_request_unit.noop_applyMerged the changes to one config within a change request, but no secrets actually changed. When secrets do change, an enclave.project.config.secrets.update event is recorded insteadChange request unit

Change request policies

TypeDescriptionMetadata
enclave.change_request_policy.createCreated a change request policyChange request policy
enclave.change_request_policy.update_definitionChanged a change request policy's name, description, or rulesChange request policy
enclave.change_request_policy.update_targetsChanged which projects and configs a change request policy applies toChange request policy
enclave.change_request_policy.deleteDeleted a change request policyChange request policy

Legacy event types

Doppler no longer generates the following event types. Entries of these types may still exist in older workplaces and be returned by the Activity Logs API, but they are never delivered to logging services, since delivery only happens when an entry is created.

TypeDescription
enclave.project.config.secrets.downloadDownloaded a config's secrets. This is now recorded only in the config's log
enclave.project.pull_request.create, enclave.project.pull_request.approve, enclave.project.pull_request.close, enclave.project.pull_request.mergeDoppler's former pull request feature
enclave.project.config.cloud.heroku, enclave.project.config.cloud.heroku.enable, enclave.project.config.cloud.heroku.update, enclave.project.config.cloud.heroku.disableThe former Heroku sync
enclave.project.defaults.updateThe former project defaults feature
services.github.connect, services.github.disconnectGitHub connections for the former Radar product
services.heroku.connect, services.heroku.disconnectThe former Heroku connection
radar.repository.file.ignore, radar.repository.file.track, radar.repository.secret.ignore, radar.repository.secret.trackThe former Radar product
team.group.role.updateChanged a group's project access role

Did this page help you?