Running as a service
zs-proxy proxy start runs a self-managed daemon that doesn't survive a
reboot and isn't restarted if it crashes. To start the proxy on login or boot
and restart it on failure, register it as an OS service:
zs-proxy proxy install-service # register + enable, using your current config
zs-proxy proxy install-service --port 9376 # pin a --config/--port at install time
zs-proxy proxy install-service --print # preview what would be installed, without installing
zs-proxy proxy uninstall-service # stop + remove it
The service runs the proxy in the foreground, with its path and flags baked in.
Once installed, the same commands just work
After you install the service, zs-proxy proxy start|stop|restart|status|logs
target the service instead of the self-managed daemon, and proxy logs -f
tails the service's log. A self-managed daemon that is still running takes
precedence, and the command says so; an encrypted-file wallet install leaves
one running, because install-service stops the daemon only when it enables
the service.
The service keeps the --config, --network, and --port it was installed
with, so start and restart can't change them; re-run install-service to
change one. See Proxy CLI reference.
Per-OS notes
| OS | Service | Runs as | Wallet it reads |
|---|---|---|---|
| macOS | launchd LaunchAgent | Your user, in your login session | Keychain |
| Linux | systemd user unit | Your user, in your login session | Secret Service |
| Windows | Windows service | The account that installs it | Credential Manager |
Each one runs as your user because it needs that to reach your wallet.
macOS: Homebrew installs the proxy as a cask, not a formula, so
brew services does not apply. Use install-service however you installed
the proxy.
Windows: installing needs administrator rights. If you aren't already
elevated, it raises a UAC prompt and continues, still configured to run as
you. It asks, with hidden input, for your Windows account password, which the
service manager needs to register a service that runs as your user. It grants
the "log on as a service" permission itself, so you shouldn't need to touch
secpol.msc.
On every platform:
- Set up the wallet first. A service has no terminal to prompt you in, so
a service started without a wallet refuses to run.
install-servicechecks for this and stops before installing anything. Only a wallet set up with thewalletcommands counts: a service doesn't inherit your shell's environment, so a*_MNEMONICvariable set there never reaches it (use--printand add the variable to the unit yourself if you need one). Runzs-proxy wallet login(or see Other ways to set up your wallet), then install the service. - Wallet unlock. A wallet in your OS keychain, which is where a signed
release (Homebrew/Scoop install) creates it, is read unattended. A wallet in
the encrypted file can't prompt for its passphrase under a service. There,
install-serviceregisters the service without enabling it and tells you to setZEROSIGNAL_KEYSTORE_PASSPHRASEbefore you enable it yourself.
What's next
- Configuration — every config key, including the network and spend-cap settings you'd typically pin at install time.
- Proxy CLI reference — the full command and flag list.