Windows

Install Prism on Windows Without Administrator Rights

By Kavin M KPublished Updated 7 min read

Quick answer
Download the MSI and run it — it installs per user into %LOCALAPPDATA%\Programs\Prism and writes only to HKCU\Software\Prism, so no administrator password is required. A portable executable is also available if you would rather not install anything.

Prism installs on Windows without administrator rights. There is no elevation prompt, no "do you want to allow this app to make changes" dialog, and nothing is written to Program Files. That matters on a managed laptop where you have a user account but not admin, and it also matters on your own machine if you would rather not grant installer rights to an app that runs as you anyway.

There are two supported paths, and they differ in more than file location.

Option 1 — the per-user MSI

Prism-Windows-x64.msi installs per user. Windows Installer performs the whole operation inside your own profile hive, which is what makes elevation unnecessary. Concretely:

Installs to your profile

%LOCALAPPDATA%\Programs\Prism\prism.exe, with install state under HKCU\Software\Prism.

Appears in Apps & features

You can uninstall it the normal way. Its uninstall entry is registered per-user even though Windows lists uninstall information in a shared location — that is normal for this package shape and does not mean anything was elevated.

Adds a Start Menu shortcut

Under Programs → Prism. There is deliberately no desktop shortcut.

Launches Prism when it finishes

As you, not elevated. An in-place upgrade does the same, and closes the running copy first so the new executable can replace it.

Never turns auto-start on behind your back

If you already had "Start at Login" enabled, the installer repoints that entry at the installed copy. If you did not, it leaves the setting alone.

:: Silent install into your own profile - no elevation prompt
msiexec /i Prism-Windows-x64.msi /qn

:: Uninstall, same rules
msiexec /x Prism-Windows-x64.msi /qn

Option 2 — the portable executable

prism.exe is a single self-contained binary. Put it anywhere you can write: %USERPROFILE%\Applications, a project folder, a synced drive. It writes nothing to the registry on its own and leaves no Start Menu entry, so removing it means deleting the file.

Choose the MSI when

It is your machine, you want it in Apps & features, and you want one obvious way to uninstall it.

Choose the portable build when

You want zero install footprint, you carry it on a USB stick, or your organisation blocks MSI deployments to user profile directories.

Both update themselves in place
The updater replaces the running file, so whichever shape you pick stays on that channel. A portable copy stays portable; an MSI install updates through Windows Installer, silently and still without elevation.

Where the installer deliberately does not go

A machine-wide package exists in the build tooling, but it is not the download. Installing to Program Files means every future upgrade needs an elevated msiexec, which turns an automatic update into a UAC prompt — the opposite of what a tray app that keeps itself current should ask for. The shipped package is the per-user one.

What Prism writes, and where

%APPDATA%prism                 config, keys, stats
├── config.json
├── model_remapping.json
├── stats.db
├── logsproxy.log
└── searxng                     managed search engine data

HKCUSoftwareMicrosoftWindowsCurrentVersionRunPrism
                                 only if you enable Start at Login

Nothing goes to Program Files, ProgramData or HKLM. All of it is inside your profile, which is also why a roaming profile follows you and why deleting %APPDATA%\prism is a complete reset.

How to tell which install you have

reg query HKCU\Software\Prism /v InstallType
rem InstallType  REG_SZ  msi        -> an MSI install
rem (no key at all)                 -> a portable copy

This is the same marker Prism itself reads, and the comparison is against the running executable rather than the marker alone — so a portable prism.exeon a machine that also has an MSI install is still treated as portable and will not be "repaired" by Windows Installer.

Things that surprise people

A SmartScreen prompt on first run

The Windows builds carry version metadata but are not Authenticode-signed, so the first launch of a freshly downloaded file can show "Windows protected your PC". Choose More info → Run anyway. The MSI and the portable exe behave the same way.

Two processes, one name

Task Manager shows two prism.exe entries: the tray parent and the proxy child, which carries the --serve flag. That is normal, and it is why an upgrade can replace the file while Prism is running.

"Prism is already running"

A single-instance lock held on prism.lock in the config directory. A second launch steps aside instead of fighting over port 11434.

Port already in use

Check whether something else claims 11434 — a local Ollama or another LLM server is the usual culprit. Prism's port is configurable with PRISM_PORT, and the admin UI uses PRISM_ADMIN_PORT (default 8765).

If your organisation blocks things

An app-control policy that allowlists signed binaries will block both shapes, since neither is signed. The portable build is the better fit where MSI installation to a user profile directory is blocked but running an executable from your own folder is not — and its config directory stays inside %APPDATA% either way.

If you need network isolation rather than install isolation, keep the default PRISM_HOST of 127.0.0.1. Prism binds to loopback only, so nothing is exposed on the LAN unless you deliberately change it, and it writes a warning to the log when you do.

Reference

Every claim on this page is checked against the Prism source, and the reference documentation is where those details live in full.

Try it yourself

Prism is a free, MIT-licensed local proxy for AI coding agents. Install it, point one agent at http://127.0.0.1:11434, and the rest of this post applies as written.