Skip to content
Join the waitlistWaitlist

CLI

The zunder-guard commands, and the zunder-runner commands they are modelled on.

CommandWhat it doesWhoToday’s model
zunder-guard init --interactive [--rules zr1_…] [--account 0x…] [--no-key] [--force]guided setup on the terminal: keep or edit the rules, the account, the mode (paper by default; mainnet typed in full, then the account again), then the key with hidden input; writes the config and starts the journala personzunder-runner journal-init
zunder-guard init --non-interactive --rules zr1_… --network N [--account 0x…] [--confirm-mainnet 0x…] [--key-stdin|--no-key] [--listen L] [--force]the same without prompts; refuses anything missingan installer, cloud-initnew
zunder-guard run [--network N] [--listen L] [--key-stdin|--key-file F]run until stopped; mainnet needs ZUNDER_GUARD_MAINNET_CONFIRM naming the account at every starta person or a servicezunder-runner testnet / mainnet
zunder-guard paira client key for a bot, printed once, with a pairing codea personnew
zunder-guard key check --key-stdinchecks the key on standard input is an API wallet of the configured account; prints the wallet address, never the keythe installernew
zunder-guard config get network|account|listen|rulesprints one configured valueanyone on the machinenew
zunder-guard health [--listen L|--url U]exit 0 if /healthz answers 200a healthchecknew
zunder-guard statusrisk state, positions, last decisionsanyone on the machinestatus.json
zunder-guard kill --reason "…"pull the kill switchanyone on the machinezunder-runner kill
zunder-guard resume --note "…"clear a drawdown halt after a reviewa personzunder-runner journal-resume
zunder-guard journal showprint the journalanyone on the machinezunder-runner journal-show
zunder-guard journal repair --note "…"cut a torn last recorda personzunder-runner journal-repair
zunder-guard check-configvalidate the config; no key, no networkanyonezunder-runner check-config
zunder-guard client add|list|revokemanage client keys for botsa personnew
zunder-guard-mcp (later also zunder-guard mcp)run the MCP server over stdioan MCP clientnew
zunder-guard rules exportprint your rules as a zr1_ codeanyonenew
zunder-guard --versionthe versionanyonenew

The commands an installer or a container relies on (init, run, pair, key check, config get, health, --version) follow the contract in deploy/guard/README.md. Every flag also has an environment variable (ZUNDER_GUARD_HOME, ZUNDER_GUARD_RULES, ZUNDER_GUARD_NETWORK, ZUNDER_GUARD_ACCOUNT, ZUNDER_GUARD_LISTEN, ZUNDER_GUARD_KEY_FILE, ZUNDER_GUARD_MAINNET_CONFIRM), so a container without a shell can be configured. A refusal exits with status 2 and the reason on standard error.

init, pair, resume, journal repair and client add change what Guard may do. They are never called by Guard itself, by the MCP server, by the monitor page or through the relay. resume also needs Guard stopped, as zunder-runner journal-resume does today.

Terminal window
zunder-guard kill --reason "bot looping on SOL"
zunder-guard status
# state: killed (bot looping on SOL) · positions: none · session: killed

This page as plain Markdown, for people and LLMs: /docs/reference/cli.md