Privileges and security
No DevKit code runs as root
Section titled “No DevKit code runs as root”Setup makes its privileged changes with one osascript … with administrator privileges call that installs two plain files: the launchd plist and /etc/resolver/test. DevKit writes both files itself; the only values in them are your user name and DevKit’s paths, which are XML-escaped in the plist and quoted in the script, and the TLD is fixed. Trusting the certificate authority runs as you, in your login keychain, with macOS’s own confirmation. launchd binds ports 80 and 443 as root and hands the sockets to devkitd, which runs as you. Removal undoes the same two files with one more prompt.
Loopback only
Section titled “Loopback only”The proxy, DNS server, services, workers, Mailpit and the dump collector all bind to 127.0.0.1. Nothing DevKit runs is reachable from your network. Sharing works by cloudflared connecting out to Cloudflare, so no ports are opened.
Certificates
Section titled “Certificates”DevKit’s certificate authority is name-constrained to .test: even if its key leaked, it couldn’t sign a certificate a browser would accept for any other domain. Site certificates last at most 397 days and renew automatically. The CA’s key stays in DevKit’s folder, readable only by you.
Shared sites
Section titled “Shared sites”Requests from Cloudflare arrive at a separate listener. Password and IP checks happen there, before your site sees the request. Visitor IPs come from Cloudflare’s CF-Connecting-IP, which visitors can’t set themselves.
Downloads
Section titled “Downloads”Downloads come over HTTPS from each project’s official releases. Where the project publishes a SHA-256, DevKit checks the file against it and refuses a mismatch: Node against nodejs.org’s SHASUMS256.txt, Composer against getcomposer.org’s checksum, and GitHub-hosted downloads (cloudflared, Mailpit, PostgreSQL, Meilisearch, RustFS) against the digest GitHub reports for each release file. MySQL and the static PHP builds publish none, so they rely on HTTPS alone. Valkey and Xdebug are built on your computer from their release sources. Updates to DevKit itself are checked against DevKit’s signing key.
Secrets
Section titled “Secrets”The share password and Cloudflare tokens are stored in secrets/sharing.json in DevKit’s folder, with permissions 0600. They’re never shown back in the app or sent anywhere except Cloudflare’s API.
Requests and dumps stay in memory. Request headers that usually carry secrets are hidden on screen until you choose to show them.