prick
A tiny, self-hosted secrets manager for small teams, powered by Cloudflare Workers and D1.
prick stores secrets in your own Cloudflare account and injects them into processes at runtime. The server is one Cloudflare Worker backed by a D1 database, deployed to your account and operated by you. Values are encrypted with AES-256-GCM and each ciphertext is cryptographically bound to the environment, key and version it belongs to. Identity comes from Cloudflare Access — SSO for people, service tokens for CI. The prk client is a single static binary: "prk run -- ./deploy.sh" hands secrets to a child through its environment block and nowhere else, and every reveal is audited with the reason it happened. A web console and an MCP server ship alongside the CLI.
winget install --id yashau.prick --exact --source wingetLatest 2026.819.2·August 19, 2026
Details
- Homepage
- https://github.com/yashau/prick
- License
- MIT
- Publisher
- yashau
- Support
- https://github.com/yashau/prick/issues
- Copyright
- Copyright (c) 2026 yashau
- Moniker
prk