zas-agent
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| --profile | No | Which identity directory this process uses. Letters, digits, `.`, `_` and `-`, up to 64, and it may not start with a dot. | claude-code |
| DO_NOT_TRACK | No | `1` turns usage reporting off. Read only to turn it off. | |
| ZAS_API_BASE | No | The API. | https://zas.red/api |
| ZAS_WEB_BASE | No | The web app the pairing URL points at. | https://zas.red |
| ZAS_OPRF_BASE | No | The blind key-derivation service. | https://zas.red/oprf |
| ZAS_AGENT_HOME | No | Where the profile directories live. | ~/.zas/agent |
| ZAS_TOKEN_BASE | No | The challenge and token routes. | https://zas.red/anon-token |
| ZAS_AGENT_TELEMETRY | No | `0` turns usage reporting off for this process, `1` on. It outranks the stored choice. | |
| ZAS_FIREBASE_API_KEY | No | The key used to exchange a custom token for a session. Defaults to the public web key. | |
| ZAS_FIREBASE_PROJECT | No | The project whose Firestore the read path queries. | zas-me |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| zas_statusA | Say whether this agent is paired with a Zas account, and list the owner's channels it may send to or read from. The owner sees every item this agent sends with the >_ agent mark and this agent's name, on every device. |
| zas_pairA | Pair this agent with a Zas account. The first call returns a URL for the owner to open; a later call says whether they approved. If the page shows a code, call again with |
| zas_send_fileA | Send a file from this machine into one of the owner's Zas channels. Returns the item id, or a job id when the upload takes longer than a minute. A channel in Directo mode refuses this tool: use zas_send_direct there. Sends any file this process can read; confirm with the owner before sending secrets, keys or credentials. The owner sees every item this agent sends with the >_ agent mark and this agent's name, on every device. |
| zas_send_directA | Send a file from this machine through Directo: a live, device-to-device transfer into one of the owner's channels that is in Directo mode. Nothing is stored. The owner has to press Receive on another device within ten minutes; the call waits a minute and then returns a job id to check with zas_jobs. Returns the transfer result, or a job id. Sends any file this process can read; confirm with the owner before sending secrets, keys or credentials. The owner sees every item this agent sends with the >_ agent mark and this agent's name, on every device. |
| zas_send_direct_fallbackA | After a zas_send_direct job failed in flight, deliver the same file through reliable delivery instead. Zas encrypts the file on this machine and stores only that encrypted copy in Cloudflare R2 for up to 24 hours; it uses none of the owner's space, and the device that claimed the offer can download it later. This stops being Directo: the encrypted bytes pass through storage. Ask the owner before you use it; it is their choice. Pass the failed job's id. The owner sees every item this agent sends with the >_ agent mark and this agent's name, on every device. |
| zas_receive_directA | Receive a file the owner sends through Directo, straight onto this machine. Call it when the owner says they are sending you something: it waits for the offer, takes it, and writes the file to disk. Nothing is stored anywhere. Only for a channel in Directo mode, and only with a grant that includes reading. The call waits a minute and then returns a job id to check with zas_jobs; the wait for an offer alone can take ten minutes. Returns the path written; it never overwrites an existing file. The owner sees every item this agent sends with the >_ agent mark and this agent's name, on every device. |
| zas_receive_direct_fallbackA | After a zas_receive_direct job failed in flight, download the encrypted copy the sender chose to store instead. It works only if the person who was sending picked reliable delivery for that transfer. The file is decrypted on this machine and written to the same destination. Pass the failed job’s id. The owner sees every item this agent sends with the >_ agent mark and this agent's name, on every device. |
| zas_send_noteB | Send a note — plain text, or a code snippet with its language — into one of the owner's Zas channels. The owner sees every item this agent sends with the >_ agent mark and this agent's name, on every device. |
| zas_list_itemsA | List the most recent items in one of the owner's Zas channels. Needs a grant that includes reading. The owner sees every item this agent sends with the >_ agent mark and this agent's name, on every device. |
| zas_get_itemA | Fetch one item from a Zas channel. A note comes back as text; a file is written to disk. Returns the path written; it can differ from |
| zas_edit_itemA | Change an item this agent sent, keeping its id: the title of a file or a note, or a note's text, language and secret cover. Refuses items sent by anyone else. A file's bytes change with zas_replace_file. Needs a grant that includes reading and sending. Pass only the fields to change; an empty title clears it. The owner sees every item this agent sends with the >_ agent mark and this agent's name, on every device. |
| zas_replace_fileA | Replace the bytes of a file this agent sent with a file from this machine, keeping the item id, its place in the channel and its pin. Refuses items sent by anyone else, notes, and an item with a public share. Returns the item id, or a job id when the upload takes longer than a minute. Sends any file this process can read; confirm with the owner before sending secrets, keys or credentials. The owner sees every item this agent sends with the >_ agent mark and this agent's name, on every device. |
| zas_jobsA | List the sends and Directo transfers this server started, newest first, with the phase each one reached and how it ended — including any |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 13 tools
Each tool targets a distinct action or resource: status/pairing, file sending, note sending, Directo transfer, fallback recovery, receiving, item listing/fetch/edit/replace, and job tracking. The descriptions explicitly separate modes (e.g., Directo vs stored delivery) so an agent can reliably choose the right tool.
All 13 tools use the same zas_ prefix and lower snake_case convention, mostly following verb_noun patterns like zas_send_file, zas_list_items, and zas_get_item. The fallback tools extend the pattern predictably rather than introducing a new style.
With 13 tools, the set fits comfortably in the well-scoped range and each tool appears to earn its place. The fallback and job-tracking tools support edge cases without bloating the surface unnecessarily.
The surface covers pairing, status, sending files and notes, Directo send/receive, fallback recovery, item listing/fetching/editing/replacing, and job tracking. The main gap is deletion or removal of items, though agents may work around this by editing or replacing where possible.