prick
Last updated
A tiny, self-hosted secrets manager for small teams, powered by Cloudflare Workers and D1.
Install with winget
$ winget install --id yashau.prick --exact --version 2026.901.0Run in Command Prompt, PowerShell, or Windows Terminal. Prompts for any agreements.
For Intune admins
Stop chasing app updates. Pckgr patches them for you.
Automated application patching for Microsoft Intune. Pckgr keeps a curated library of 1,000+ apps continuously up-to-date in your tenant via Microsoft Graph - no manual repackaging, no chasing vendor sites.
Start free 30-day trialNo credit card required.
About
prick stores secrets in your own Cloudflare account and injects them into processes at runtime. The server is one Cloudflare Worker backed by a D1 database, deployed to your account and operated by you. Values are encrypted with AES-256-GCM and each ciphertext is cryptographically bound to the environment, key and version it belongs to. Identity comes from Cloudflare Access — SSO for people, service tokens for CI. The prk client is a single static binary: "prk run -- ./deploy.sh" hands secrets to a child through its environment block and nowhere else, and every reveal is audited with the reason it happened. A web console and an MCP server ship alongside the CLI.
Installers · v2026.901.0
Copy a command tailored to that specific architecture, type, and scope - useful when winget would otherwise pick a different default.
Security
No known CVEs for prick.
Coverage is best-effort and depends on a winget package mapping to an NVD CPE entry. Absence here is not a guarantee of safety.
Related apps
More from yashau or browse cli, cloudflare-access, cloudflare-d1.
Frequently asked questions
How do I install prick on Windows?
How do I install prick silently for unattended deployment?
How do I uninstall prick via winget?
Is prick free?
Does prick work on Windows 10?
How do I keep prick up to date?
Recent versions
- 2026.901.0latest
- 2026.819.2