All agent CLIs
ZCode in NeuroSquad

ZCode,with a canvas around it

Run as many ZCode agents as you need, each the real zcode in its own card. ZCode’s own hooks report every turn and every question, arrows hand it terminals, notes and other agents, and each card resumes its session and counts every request it makes.

Official sitezcode.z.ai
  • The real zcode, your own providers
  • Your ~/.zcode is only read
  • Free, for Windows and macOS
Lifecycle hooks

It knows when ZCode is done — and when it’s asking

A quiet terminal can mean “finished” or “waiting for your permission”. NeuroSquad doesn’t guess: each card’s settings carry ZCode’s own hooks, and ZCode waits for every one of them.

UserPromptSubmithook
Working

You press Enter. The card’s icon spins, the Squad status card counts it as working, and the toast from its last question is taken down.

PermissionRequesthook
Needs you

ZCode asks before a call. The toast names it — ZCode needs your permission: Bash rm -rf dist — and stays until you answer; the tool’s PostToolUse puts the card back to working.

Stophook
Finished

The turn is over. The next queued prompt goes out, the journal gets the answer, and a toast says it’s done.

Questions and plans count too

ZCode sends AskUserQuestion and ExitPlanMode through the same PermissionRequest, so the toast reads ZCode is asking: Tabs or spaces? and the card waits on you.

Esc is read from the key

Escape cancels a turn (“Turn cancelled.”) without any hook, so the card settles from the key itself. Ctrl+C on an idle ZCode quits it — the card never sends it.

Subagents don’t move it

A subagent runs in a session of its own (sess_subagent_…); its hooks never change the card’s status.

Watch it work

Three things you’ll do with ZCode

Replicas of the app, played step by step. When ZCode asks, the answer is yours.

ZCode fixes a failing test through a terminal card, stops on its permission dialog before deleting a folder, and finishes — the journal writes itself.

Everything it gets

Everything ZCode can do in NeuroSquad

Measured on ZCode runtime 0.16.9 through the zcode command of zcode-app-cli. Most of it is ZCode’s own — hooks, MCP, sessions, its usage ledger. Where NeuroSquad had to build something, or it can’t be done, the card says so.

  • 01

    Knows its state

    ZCode’s own hooks report every turn, permission and question, so nothing is guessed.

  • Finished and waiting are different

    Each card’s settings carry ZCode’s process hooks — SessionStart, UserPromptSubmit, PermissionRequest, Stop — and ZCode awaits each one, so the card learns of every turn as it happens.

    Docs: Finished and waiting are different
  • A notification that says what it needs

    The toast names the call — ZCode needs your permission: Write notes.md — or the question ZCode asks. One per agent; a waiting one stays until you answer.

    Docs: A notification that says what it needs
  • Built by NeuroSquad

    Esc, never Ctrl+C

    Escape cancels a running turn; ZCode sends no hook for it, so the card settles from the key. Ctrl+C on an idle ZCode quits it, so the budget brake and the phone’s key row never send it.

    Docs: Esc, never Ctrl+C
  • Sessions that survive a restart

    ZCode names its session on the first prompt and has no flag to choose one; SessionStart reports it, so the next launch is zcode --resume <id>. A deleted session starts fresh by itself.

    Docs: Sessions that survive a restart
  • The Squad status card

    Every AI agent of the workspace on one card, with its status, model and turn time.

    Docs: The Squad status card
  • 02

    Works through the canvas

    An arrow from the card is a set of tools, over ZCode’s own MCP client.

  • Arrows are tools

    The card’s settings add NeuroSquad’s MCP server with the token as a placeholder. An arrow to a terminal, note, browser or agent gives ZCode those tools.

    Docs: Arrows are tools
  • NeuroSquad’s own tools never prompt

    Every mcp__neurosquad__* tool is in the card’s permission.allowedTools, so they run without a dialog. Everything else still asks the way ZCode always does.

    Docs: NeuroSquad’s own tools never prompt
  • Not possible

    No live tool list

    ZCode reads a server’s tools once and never again. So a card gets every NeuroSquad capability from the start, and the arrows decide at call time.

    Docs: No live tool list
  • Canvas mode that holds

    --disallowedTools removes Bash, its background shells and the web tools from what the model sees — yolo included — and a PreToolUse hook refuses them besides.

    Docs: Canvas mode that holds
  • MCP servers from the registry

    An installed server comes as a second server with no pre-approval: ZCode shows its own dialog before every call to it.

    Docs: MCP servers from the registry
  • 03

    Built for long runs

    Context, Compact, a prompt queue and a journal — handled on the card.

  • Context meter

    The latest request’s tokens against the model’s window, from ZCode’s own rules for that model. The ring turns amber from 80%.

    Docs: Context meter
  • Compact

    The card’s Compact button sends ZCode’s own /compact; its call shows up in Usage too.

    Docs: Compact
  • Prompt queue

    Line up the next messages: each goes out after Stop, as one paste — short, multi-line or long.

    Docs: Prompt queue
  • Journal and hand-off

    The last answer is read from the card’s own session database: into a connected note, into a fresh agent’s first prompt, back to a lead waiting in agent_wait.

    Docs: Journal and hand-off
  • Subagents, counted apart

    ZCode’s Agent tool runs a subagent in a child session. Its requests are counted to the card and marked as a subagent’s in Usage, Run Stats and Agent Pulse.

    Docs: Subagents, counted apart
  • 04

    Works in a team

    Every card has a ZCode folder of its own, so any number of agents share a project without sharing a session list.

  • Built by NeuroSquad

    A ZCode folder per card

    ZCode reads its settings from your home folder and has no switch for it, so a small preload points ZCode — and only ZCode — at the card’s copy: your settings plus NeuroSquad’s. Secrets stay placeholders on disk.

    Docs: A ZCode folder per card
  • Built by NeuroSquad

    Instructions

    ZCode doesn’t read an MCP server’s instructions, so the card’s SessionStart hook hands them over as extra context. Your own AGENTS.md is read as always.

    Docs: Instructions
  • Isolated worktrees

    Give an agent its own git worktree, so parallel agents never edit the same files. The card’s ZCode folder follows the card.

    Docs: Isolated worktrees
  • Dangerous mode, per card

    --mode yolo: no permission dialogs. Switching it restarts the card with the same session; switching it off resumes in your usual mode. Canvas mode still holds.

    Docs: Dangerous mode, per card
  • Model and CLI switch

    Pick the model per card, let a lead agent change it with agent_set_model, or move the conversation to Claude Code and back — the session comes along.

    Docs: Model and CLI switch
  • 05

    Cost, control and access

    What it spends, what it may spend, which model it runs on, and how you reach it.

  • Exact usage, every request

    Read from ZCode’s own usage ledger: one row per request, titles, compaction and subagents included, cache reads and writes split out. A model with no known price shows “no price”, never $0.

    Docs: Exact usage, every request
  • Budget brake

    Past the workspace limit each ZCode gets Escape — the turn stops, ZCode keeps running — and automatic prompts wait until you raise the limit.

    Docs: Budget brake
  • OpenRouter and your own servers

    A provider of the card’s own for OpenRouter, with NeuroSquad’s attribution headers, or for your own server (Chat Completions or Anthropic Messages). The key comes from the card’s environment, never from disk.

    Docs: OpenRouter and your own servers
  • From your phone

    Scan a QR code and the whole canvas opens in the phone’s browser: read ZCode’s terminal, answer its dialog, send the next prompt.

    Docs: From your phone
  • Not in WSL or over SSH yet

    The preload and the Node launcher would have to live inside the target, so ZCode cards run on this computer only for now.

    Docs: Not in WSL or over SSH yet
At a glance

Who’s waiting, and what it cost

Two cards that answer the questions you ask most when several ZCode agents run at once.

The Squad status card

Every agent of the workspace with its status, model and turn time. The ones waiting on you come first, with what ZCode asks. Tap a status to filter.

  • coupon-fixZCodeGLM-5.3ZCode needs your permission: Bash rm -rf distNeeds you2:34
  • api-migrationZCodeGLM-5.3Move routes to the new clientWorking14:58
  • lint-setupZCodeGLM-5.3-FlashZCode is asking: Tabs or spaces?Needs you3:51
  • docs-passZCodez-ai/glm-4.6Update the READMEFinished7 min. ago

Usage & cost

Read from the usage ledger in each card’s own ZCode database, so every request belongs to exactly one card. Tokens and cost add up to the total exactly.

AgentTokensCost
coupon-fix1,184,310$0.96
api-migration802,554$0.64
docs-pass196,402$0.11
Total2,183,266$1.71
Exact to the picodollar; rounded only on screen.Each row includes the side calls ZCode makes for that card — titles, compaction, subagents.
Under the hood

The real ZCode, in a folder of its own

NeuroSquad starts the same zcode you run yourself, in a real terminal in the card. This is everything it adds:

What NeuroSquad adds to the command
❯ zcode
node --require <userData>/zcode/neurosquad-zcode-shim.cjs <zcode.js>every launchZCode’s own launcher, with a preload that points it at the card’s settings
setting.json: yours + hooks, mcp.servers.neurosquad, permission.allowedToolsevery launchyour settings, plus NeuroSquad’s hooks, MCP server and pre-approved tools
ZCODE_SESSION_DB_PATH=<userData>/zcode/<card>/db.sqliteevery launchthe card’s own sessions and usage ledger
ZCODE_PERSONAL_PROVIDER_CONFIG_FILE=<card>/provider_config.jsonevery launchyour providers, plus the card’s OpenRouter or custom one when it has one
ZCODE_DISABLE_UPDATE_CHECK=1every launchno update notice in the card
--resume <sess_…>later launchesthe session its SessionStart hook last reported
--disallowedTools Bash BashOutput KillShell WebFetch WebSearch web_search mcp__node_repl__jscanvas modeshell and web tools out of the model’s list; the canvas’s cards instead
--mode yolodangerous modeskip permission dialogs

Your ~/.zcode is only read

The preload works inside ZCode’s own processes only: your settings file is read, the card’s copy is written. A marker in a user’s setting.json survived every test run byte for byte.

No secrets on disk

Tokens and keys are ${NAME} placeholders in the card’s files, filled in memory and removed from ZCode’s environment — so its shell commands never see them.

Which ZCode

Z.ai publishes ZCode’s source; the zcode command on npm comes from zcode-app-cli, which ships Z.ai’s runtime unchanged. The setup wizard installs that one; Z.ai’s own build runs the same way.

FAQ

ZCode in NeuroSquad, answered

Give ZCode a canvas

Free for Windows and macOS. Your code, your providers and your costs stay on your machine.

Windows 10 / 11 · macOS 12 or newer, Apple silicon and IntelAll 22 agent CLIs