prick

yashau·yashau.prick

A tiny, self-hosted secrets manager for small teams, powered by Cloudflare Workers and D1.

prick stores secrets in your own Cloudflare account and injects them into processes at runtime. The server is one Cloudflare Worker backed by a D1 database, deployed to your account and operated by you. Values are encrypted with AES-256-GCM and each ciphertext is cryptographically bound to the environment, key and version it belongs to. Identity comes from Cloudflare Access — SSO for people, service tokens for CI. The prk client is a single static binary: "prk run -- ./deploy.sh" hands secrets to a child through its environment block and nowhere else, and every reveal is audited with the reason it happened. A web console and an MCP server ship alongside the CLI.

winget install --id yashau.prick --exact --source winget

Latest 2026.819.2·August 19, 2026

Release Notes

What's Changed

  • fix(cli): send the resource indicator Access refuses a login without by @yashau in #22
  • fix(cli): stop a unit test reading the developer's own login by @yashau in #23 Full Changelog: v2026.819.1...v2026.819.2

Installer type: zip

x64DCCA9A62DDBD1BFF387AB52543093DBACC72365CBFA0BA1F2508AA24A1FEAC1A
arm64FD76CF14609310764BB8CAA2DB697C9BAD4EAA5FB4B774B2257AD71DD5692DDE

Details

Homepage
https://github.com/yashau/prick
License
MIT
Publisher
yashau
Support
https://github.com/yashau/prick/issues
Copyright
Copyright (c) 2026 yashau
Moniker
prk

Tags

clicloudflare-accesscloudflare-d1cloudflare-workersdeveloper-toolsdevopsdotenvenvironment-variablesrustsecrets-managementsecurityself-hostedsvelte