Skip to main content

Running as a service

zs-proxy proxy start runs a self-managed daemon that doesn't survive a reboot and isn't restarted if it crashes. To start the proxy on login or boot and restart it on failure, register it as an OS service:

zs-proxy proxy install-service # register + enable, using your current config
zs-proxy proxy install-service --port 9376 # pin a --config/--port at install time
zs-proxy proxy install-service --print # preview what would be installed, without installing
zs-proxy proxy uninstall-service # stop + remove it

The service runs the proxy in the foreground, with its path and flags baked in.

Once installed, the same commands just work​

After you install the service, zs-proxy proxy start|stop|restart|status|logs target the service instead of the self-managed daemon, and proxy logs -f tails the service's log. A self-managed daemon that is still running takes precedence, and the command says so; an encrypted-file wallet install leaves one running, because install-service stops the daemon only when it enables the service.

The service keeps the --config, --network, and --port it was installed with, so start and restart can't change them; re-run install-service to change one. See Proxy CLI reference.

Per-OS notes​

OSServiceRuns asWallet it reads
macOSlaunchd LaunchAgentYour user, in your login sessionKeychain
Linuxsystemd user unitYour user, in your login sessionSecret Service
WindowsWindows serviceThe account that installs itCredential Manager

Each one runs as your user because it needs that to reach your wallet.

macOS: Homebrew installs the proxy as a cask, not a formula, so brew services does not apply. Use install-service however you installed the proxy.

Windows: installing needs administrator rights. If you aren't already elevated, it raises a UAC prompt and continues, still configured to run as you. It asks, with hidden input, for your Windows account password, which the service manager needs to register a service that runs as your user. It grants the "log on as a service" permission itself, so you shouldn't need to touch secpol.msc.

On every platform:

  • Set up the wallet first. A service has no terminal to prompt you in, so a service started without a wallet refuses to run. install-service checks for this and stops before installing anything. Only a wallet set up with the wallet commands counts: a service doesn't inherit your shell's environment, so a *_MNEMONIC variable set there never reaches it (use --print and add the variable to the unit yourself if you need one). Run zs-proxy wallet login (or see Other ways to set up your wallet), then install the service.
  • Wallet unlock. A wallet in your OS keychain, which is where a signed release (Homebrew/Scoop install) creates it, is read unattended. A wallet in the encrypted file can't prompt for its passphrase under a service. There, install-service registers the service without enabling it and tells you to set ZEROSIGNAL_KEYSTORE_PASSPHRASE before you enable it yourself.

What's next​

  • Configuration — every config key, including the network and spend-cap settings you'd typically pin at install time.
  • Proxy CLI reference — the full command and flag list.