diff --git a/.github/workflows/publish-nuget.yml b/.github/workflows/publish-nuget.yml
new file mode 100644
index 0000000..ca12b64
--- /dev/null
+++ b/.github/workflows/publish-nuget.yml
@@ -0,0 +1,32 @@
+name: Publish NuGet tool
+
+on:
+ workflow_dispatch:
+
+permissions:
+ contents: read
+
+concurrency:
+ group: nuget-publish
+ cancel-in-progress: false
+
+jobs:
+ publish:
+ if: github.ref == 'refs/heads/main'
+ runs-on: ubuntu-latest
+ steps:
+ - uses: actions/checkout@v7
+ - uses: actions/setup-dotnet@v5
+ with:
+ dotnet-version: '10.0.4xx'
+ - run: dotnet test WhyConfig.slnx -c Release
+ - run: dotnet pack src/WhyConfig.Cli/WhyConfig.Cli.csproj -c Release --no-restore -o artifacts
+ - name: Publish to NuGet.org
+ env:
+ NUGET_API_KEY: ${{ secrets.NUGET_API_KEY }}
+ run: |
+ if [ -z "$NUGET_API_KEY" ]; then
+ echo "Set the NUGET_API_KEY repository secret before publishing." >&2
+ exit 1
+ fi
+ dotnet nuget push artifacts/WhyConfig.NET.*.nupkg --source https://api.nuget.org/v3/index.json
diff --git a/docs/RELEASING.md b/docs/RELEASING.md
new file mode 100644
index 0000000..88538c2
--- /dev/null
+++ b/docs/RELEASING.md
@@ -0,0 +1,10 @@
+# Releasing WhyConfig.NET
+
+The GitHub repository can stay private while the tool package is public on NuGet.org.
+
+1. Sign in to the [Benziza NuGet.org account](https://www.nuget.org/profiles/Benziza) and create a [Push API key](https://learn.microsoft.com/en-us/nuget/nuget-org/publish-a-package#create-an-api-key). For the first release, allow new packages in the key's package scope.
+2. Save the key as the `NUGET_API_KEY` secret in this repository's **Settings → Secrets and variables → Actions**. Do not commit the key.
+3. Run the **Publish NuGet tool** workflow from `main` in the Actions tab.
+4. After NuGet.org lists the package, verify installation with `dotnet tool install --global WhyConfig.NET` and `whyconfig --help`.
+
+For another release, change `Version` in `src/WhyConfig.Cli/WhyConfig.Cli.csproj`, merge it, then run the workflow again. NuGet.org does not allow replacing a published package version.
diff --git a/src/WhyConfig.Cli/WhyConfig.Cli.csproj b/src/WhyConfig.Cli/WhyConfig.Cli.csproj
index ee0635b..d43dae1 100644
--- a/src/WhyConfig.Cli/WhyConfig.Cli.csproj
+++ b/src/WhyConfig.Cli/WhyConfig.Cli.csproj
@@ -20,7 +20,7 @@
whyconfig
WhyConfig.NET
0.1.0
- WhyConfig.NET
+ Benziza
Explain .NET configuration provider precedence for a key.
README.md