prick

yashau·yashau.prick

A tiny, self-hosted secrets manager for small teams, powered by Cloudflare Workers and D1.

prick stores secrets in your own Cloudflare account and injects them into processes at runtime. The server is one Cloudflare Worker backed by a D1 database, deployed to your account and operated by you. Values are encrypted with AES-256-GCM and each ciphertext is cryptographically bound to the environment, key and version it belongs to. Identity comes from Cloudflare Access — SSO for people, service tokens for CI. The prk client is a single static binary: "prk run -- ./deploy.sh" hands secrets to a child through its environment block and nowhere else, and every reveal is audited with the reason it happened. A web console and an MCP server ship alongside the CLI.

winget install --id yashau.prick --exact --source winget

Latest 2026.901.0·September 1, 2026

Release Notes

What's Changed

  • fix(cli): read back an environment the server was willing to write by @yashau in #25
  • fix(cli): give a guard refusal its own code instead of LAUNCH_FAILED by @yashau in #24
  • fix(deps): override cookie and esbuild past two advisories upstream will not release by @yashau in #26
  • fix(cli): three findings from a live 2026.819.1 smoke test by @yashau in #27
  • fix(ci): make the root pnpm lint and check scripts actually run by @yashau in #29
  • feat(ui): add sign out and stop the idle dialog offering re-authentication by @yashau in #28
  • fix(ui): card spacing, danger-zone ring, and whole-row links in the lists by @yashau in #30
  • docs: stop the setup instructions assuming the reader's platform by @yashau in #31
  • fix(cli): exit 126 for a non-image on Windows, and correct a docs command by @yashau in #32
  • fix(cli): give an edge mitigation its own code instead of FORBIDDEN by @yashau in #33
  • ci: gate the docs build on docs/**, and openapi.json on js by @yashau in #35
  • feat(cli): complete a login by pasting the redirect when loopback is unreachable by @yashau in #36
  • feat(cli): revoke the session on logout instead of only deleting the file by @yashau in #37
  • fix(ci): stop mise run ci racing bootstrap, and itself, on a fresh tree by @yashau in #38
  • feat(docs): serve the site from docs.getprick.dev, and nowhere else by @yashau in #39
  • fix(ci): report the docs URL from the config, not from wrangler's log by @yashau in #40
  • fix: close the actionable findings from a full security audit by @yashau in #41
  • docs: comment out the winget line until Microsoft approves it by @yashau in #42 Full Changelog: v2026.819.2...v2026.901.0

Installer type: zip

x64—21774A94B72F8ECC6A841AB202A0BDD1229DD5E2AD309A1534CB7BC75BE81FD1
arm64—C2E669F0D976369B1C62C67FB439CFF918B2F0A4133D077881F308B8C40EFDF2

Details

Homepage
https://github.com/yashau/prick
License
MIT
Publisher
yashau
Support
https://github.com/yashau/prick/issues
Copyright
Copyright (c) 2026 yashau
Moniker
prk

Tags

clicloudflare-accesscloudflare-d1cloudflare-workersdeveloper-toolsdevopsdotenvenvironment-variablesrustsecrets-managementsecurityself-hostedsvelte

Older versions (1)

2026.819.2
x64—DCCA9A62DDBD1BFF387AB52543093DBACC72365CBFA0BA1F2508AA24A1FEAC1A
arm64—FD76CF14609310764BB8CAA2DB697C9BAD4EAA5FB4B774B2257AD71DD5692DDE