Z.ai claims its published ZCode repository includes the coding-agent runtime, CLI, backend, and desktop and web clients, enabling developers to inspect and extend the execution stack rather than depend on an opaque client.
state: seedheat: mediumuncertainty: mediumconvergesscott: highagent-harnesses open-source-agentsZ.ai
What is this?
Z.ai (zai-org), a Chinese AI lab, published the ZCode repository on GitHub under Apache 2.0 on September 20, 2026. The repository contains the full execution stack — Electron desktop app, web client, backend services, shared UI components, Agent CLI, and the agent runtime itself — as a single codebase with multiple entry points (desktop, `zcode --web`, terminal TUI). This makes the coding-agent runtime inspectable and extensible locally rather than gated behind a closed client. The release followed community pressure after security concerns about workspace uploads, though the snippets do not detail the allegations.
Why it matters to Scott
Z.ai (Zhipu), a Chinese frontier lab, has open-sourced its full coding-agent stack — desktop, web, CLI, backend, and runtime — under Apache 2.0. This independently arrives at Scott's load-bearing position that agentic capability resides in the disclosed harness (model-plus-harness benchmark unit), not weights alone, and that the harness should be inspectable at the boundary (agent-native computing: machine-native middle, human-legible edges). The release also responds to workspace-upload privacy allegations, directly engaging Scott's containment/provenance architectures (SiloOS, Agent Provenance Stack, runtime containment). A consequential actor adopting the open-harness posture Scott argued for creates a dated-receipts publishing opportunity.
ip:concept.model-plus-harness-benchmark-unitip:framework.agent-native-computingip:concept.capability-symmetryip:concept.model-perishabilityip:framework.siloosip:framework.agent-provenance-stackdev:project.askdev:project.openclawdev:project.silo-osdev:technology.z-airadar:0pirate-ast-anonymizer-mcp-proxyradar:aa-agentperf-local-benchmarkradar:514-coding-agent-simulation-infraradar:abliterated-weights-agent-backdoor
queries asked of Scott's wikis
- open-source agent harness architecture patterns
- local agent runtime inspectability and extensibility
- multi-platform agent interfaces desktop web CLI unified stack
- Chinese frontier labs open-weight models vs open-source runtimes
- agent harness as separate layer from foundation model
- coding agent workspace upload privacy threat model
Measured heat
now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 495h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion
How the heat travelled
pace: p9 vs 1032 stories at the 336h mark (now 495h old) — behind addom-local-coding-harness (0.5x)
Evidence (2) — ⭐ canonical anchor
| source | object | author | score | comments |
| 🟧 hn ⭐ | ZCode: Z.ai's coding agent harness. Powerful, intelligent, extensibleRetrieved article excerptOpen article · Retrieved 2026-09-21T02:21:45.235277+00:00 # ZCode
[ZCode](https://github.com/zai-org/ZCode/blob/main/public/logo/icons/1024x1024.png)
[飞书社群](https://applink.feishu.cn/client/chat/chatter/add_by_link?link_token=47ag983c-8fcb-4d6d-814b-5395193a712c&qr_code=true) ·
[Discord](https://discord.gg/z9aBcQXZQ3)
简体中文 | [English](https://github.com/zai-org/ZCode/blob/main/README.en.md)
ZCode 是 AI 编程工作台,提供桌面应用、浏览器界面和终端 Agent。本仓库包含客户端、后端服务、共享 UI,以及 Agent CLI 与运行时源码。
| 入口 | 用途 | 开发命令 |
| --- | --- | --- |
| Desktop | Electron 桌面应用 | `pnpm dev:desktop` |
| Web / ZCode 命令行版 | 终端与浏览器工作台;将 TUI、Web、后端和 Agent 组装为独立运行包 | `pnpm dev:web` |
| Agent CLI | 在终端中使用 `zcode`,也为 Desktop 和 Web 提供 Agent 运行时 | `pnpm --filter @zcode/cli dev` |
## 初始化
准备 Git、Node.js **24.14.0** 和 pnpm **10.33.2**,版本以 [mise.toml](https://github.com/zai-org/ZCode/blob/main/mise.toml) 为准。以下开发和打包命令均在仓库根目录执行。
```
pnpm bootstrap
```
`pnpm bootstrap` 安装 workspace 依赖、准备桌面本地运行资源,再执行 `build:bootstrap`。
Agent CLI 与运行时源码位于 [apps/zcode-cli/](https://github.com/zai-org/ZCode/blob/main/apps/zcode-cli),作为普通目录随本仓库一起克隆,无需单独拉取或初始化 Git submodule。
根据需要选择其他初始化或构建入口:
| 命令 | 用途 |
| --- | --- |
| `pnpm install` | 安装依赖 |
| `pnpm prepare:desktop-runtime` | 准备桌面运行资源,默认包含远程资源准备 |
| `pnpm prepare:remote-assets` | 单独准备远程运行资源 |
| `pnpm bootstrap:with-remote` | 初始化依赖、本地与远程资源,并串行构建相关包;跳过桌面应用 bundle |
| `pnpm build` | 递归执行各 workspace 包的构建脚本,包括包内的资源准备步骤 |
默认 `bootstrap` 跳过远程资源准备,适合本地桌面开发。使用远程工作区或验证远程发行资源时,再运行对应准备命令。
## 开发与运行
### 桌面版
```
pnpm dev:desktop
# 使用测试环境
pnpm dev:desktop:test
```
`pnpm dev:desktop` 默认等同于 `pnpm dev:desktop:prod`,使用生产服务配置。启动脚本会准备本地运行资源、构建桌面 Agent,再启动 Electron 和源码监听。
需要独立开发数据目录时,可设置 `ZCODE_DATA_BASE_DIR`。例如在 macOS / Linux 中:
```
ZCODE_DATA_BASE_DIR="$HOME/.zcode-dev-home" pnpm dev:desktop:test
```
### 远程功能(SSH/WSL)
先执行 `pnpm bootstrap:with-remote` 准备远程资源(mock-cdn),再 `pnpm dev:desktop`;连接远程项目时资源选择「本地下载后上传」。开发态资源取自本地 `packages/desktop/mock-cdn` 和本地构建产物,经 SFTP 上传到远程,不访问 CDN。
### Web 开发
修改 Web 或后端源码时,使用开发模式:
```
pnpm dev:web
# 指定后端工作区(macOS / Linux)
ZCODE_SERVER_WORKSPACE=/path/to/project pnpm dev:web
```
该命令同时启动 Web 开发服务器(默认 `http://localhost:5173`)和后端(默认 `http://localhost:3030`);浏览器访问前者。`/ws` 和一般 `/api` 请求代理到本地后端,`/api/v1/oauth/token` 单独代理到当前配置的产品服务。
Agent 源码修改后,执行 `pnpm --filter @zcode/cli... build` 并重启服务。需要验证完整发行包时,按下方“ZCode 命令行版”打包章节解压运行。
### ZCode 命令行版
命令行发行包包含 TUI、Web 和 Agent,统一使用 `zcode` 启动:无参数进入 TUI;第一个参数为 `--web` 时启动 Web;其他参数交给现有 Agent CLI 处理。两种模式都在本机运行,无需 Electron。
```
# 默认进入终端交互界面
zcode
# 启动 Web 界面
zcode --web
# 指定项目和端口,不自动打开浏览器
zcode --web --workspace /path/to/project --port 3030 --no-open
# 查看 CLI 或 Web 参数
zcode --help
zcode --web --help
```
Web 模式默认工作目录为当前目录,监听 `127.0.0.1`,默认不启用访问令牌,自动选择空闲端口并打开浏览器。访问终端输出的地址,按 `Ctrl+C` 停止服务。局域网访问可使用 `--host 0.0.0.0`;监听非本机地址时默认生成访问令牌,使用终端输出的带令牌链接。可通过 `--token` 指定令牌或 `--no-token` 关闭令牌认证。
直接启动通用 Web 服务的 HTTP 入口时,通过 `ZCODE_SERVER_AUTH_TOKEN` 配置 API/WebSocket 认证;通过程序接口创建服务时,使用 `authToken` 选项。
构建方式见下方打包章节。`pnpm build:zcode` 只生成发行包,不会替换 `PATH` 中已有的 `zcode`。如果命令仍指向旧安装或其他源码目录,macOS / Linux 可用 `command -v zcode` 检查,Windows 可用 `where.exe zcode` 检查。
### CLI 源码开发
直接开发 TUI 或 Agent 时,运行源码入口:
```
pnpm --filter @zcode/cli dev --help
pnpm --filter @zcode/cli dev
# 构建 CLI 及其 workspace 依赖
pnpm --filter @zcode/cli... build
node apps/zcode-cli/packages/cli/dist/zcode.cjs --help
```
这个入口直接运行 Agent CLI,不经过发行包的 `--web` 分流。开发 Web 用 `pnpm dev:web`;验证统一的 `zcode` 命令,用下方解压后的 `bin/zcode.mjs`。
## 配置
根目录 [.env.example](https://github.com/zai-org/ZCode/blob/main/.env.example) 提供服务地址与构建配置示例,可按需复制到 `.env`,本地覆盖放入 `.env.local`。Desktop 的开发环境通过 `dev:desktop:test` / `dev:desktop:prod` 选择。
| 配置 | 用途 |
| --- | --- |
| `ZCODE_DATA_BASE_DIR` | 应用数据基目录,数据写入其下的 `.zcode/` |
| `ZCODE_SERVER_WORKSPACE` | Web 后端的工作区路径 |
| `ZCODE_BUILTIN_PROVIDER_CONFIG_FILE` | 本地 Provider 配置文件路径;未设置时使用内置配置 |
| `ZCODE_DIST_BASE_URL` | 命令行安装脚本使用的下载根地址 |
运行时变量可在启动命令的环境中显式设置。随客户端发布的默认配置见 [config/README.md](https://github.com/zai-org/ZCode/blob/main/config/README.md)。
## 打包
第三方声明生成、发行校验流程及声明在发行物中的位置见 [third-party/README.md](https://github.com/zai-org/ZCode/blob/main/third-party/README.md)。
### 桌面版
```
pnpm bundle:desktop
# 指定目标平台与 CPU 架构
pnpm bundle:desktop -- --os win --arch x64
pnpm bundle:desktop -- --help
```
默认目标为 macOS arm64,默认输出目录为 `packages/desktop/dist/`。`--os` 支持 `mac`、`win`、`linux`,`--arch` 支持 `x64`、`arm64`;实际打包与签名需要目标平台对应的工具和配置。
安装:双击打开产物 DMG,将 ZCode 拖入"应用程序"。本地构建未签名,首次打开若被 macOS 拦截,执行:
```
sudo xattr -rd com.apple.quarantine /Applications/ZCode.app
```
### ZCode 命令行版
构建入口为 `pnpm build:zcode`。脚本会依次构建 CLI/TUI、后端和 Web,收集 TUI 的原生库、worker 与运行时依赖,再组装发行包;运行发行包仍需要 Node.js,版本以 `mise.toml` 为准。
打包前必须设置下载根地址 `ZCODE_DIST_BASE_URL`(可放在 `.env`、`.env.local` 或环境变量中),也可以通过 `--base-url` 传入。以下地址是占位示例,发布时替换为实际托管地址:
```
pnpm build:zcode --base-url https://downloads.example.com/zcode/
# 已配置 ZCODE_DIST_BASE_URL 时
pnpm build:zcode
# 仅重新组包,复用已有的 Agent、后端和 Web 构建产物
pnpm build:zcode --skip-build
# 查看版本、输出目录等可选参数
pnpm build:zcode --help
```
默认版本取根目录 `package.json`,输出目录为 `dist/zcode/`:
- `releases/<version>/zcode-<version>.tar.gz`:运行包。
- `releases/<version>/sha256.txt`:校验摘要。
- `latest.json`、`install.sh`:版本索引和安装脚本。
完整目录可上传到配置的下载根地址。安装脚本从该地址下载运行包,默认安装到 `~/.zcode/runtime`,并在 `~/.local/bin` 创建 `zcode` 命令。安装目录可通过 `ZCODE_DIST_HOME` 修改,命令目录可通过 `ZCODE_DIST_BIN_DIR` 修改。
旧 Lite 用户需要改用上述构建命令、环境变量和新的安装脚本。新安装不会删除旧 Lite 目录,也不会迁移或删除已有会话数据。
本地调试打包产物时,可直接解压运行,无需上传或安装:
```
zcode_version=$(node -p "require('./dist/zcode/latest.json').version")
mkdir -p dist/zcode/debug
tar -xzf "dist/zcode/releases/$zcode_version/zcode-$zcode_version.tar.gz" \
-C dist/zcode/debug
# 默认启动 TUI
node dist/zcode/debug/zcode/bin/zcode.mjs
# 启动 Web
node dist/zcode/debug/zcode/bin/zcode.mjs --web \
--workspace "$PWD" --port 3030 --no-open
```
浏览器打开 `http://127.0.0.1:3030`,即可验证同一后端服务托管 Web 页面和 Agent 的完整链路。该端口需要空闲;如正在运行 `pnpm dev:web`,可改用其他 `--port`。
## 仓库结构
| 目录 | 职责 |
| --- | --- |
| `packages/desktop` | Electron Main、Host、Renderer 与桌面打包 |
| `packages/web` | Web 客户端 |
| `packages/server` | HTTP / WebSocket 服务与远程连接 |
| `packages/zcode-server-cli` | 独立 Server 启动与进程管理 |
| `packages/ui` | 共享 React 组件、hooks 与 Zustand 状态 |
| `packages/services` | 业务服务与持久化 |
| `packages/shared`、`packages/rpc`、`packages/client` | 共享协议和类型、RPC 框架、Agent 客户端 SDK |
| `packages/provider`、`packages/provider-node` | Provider 公共能力与 Node 实现 |
| `apps/zcode-cli` | Agent CLI、TUI、运行时与工具 |
| `scripts`、`config`、`third-party` | 构建维护脚本、内置配置与第三方声明材料 |
## 项目声明
功能与优惠范围、维护规则、执行与数据风险,以及许可和第三方版权说明,详见 [NOTICE.md](https://github.com/zai-org/ZCode/blob/main/NOTICE.md)。 | doppp | 4 | 0 |
| 🟧 echo.github | The repository includes the client, backend service, shared UI, Agent CLI, and runtime source, with local development and packaging instruct | Z.ai | — | — |
Interpretation history
2026-10-10T11:31:11Z
grounded: converges/high — Z.ai (Zhipu), a Chinese frontier lab, has open-sourced its full coding-agent stack — desktop, web, CLI, backend, and runtime — under Apache 2.0. This independen
2026-09-21T14:12:15Z
anchor promoted to claim owner's artifact: echo.github.11c0e859fa -> hn.story.49782006 — Z.ai's official repository directly substantiates the already-open ZCode runtime-release case.
2026-09-21T09:24:08Z
case created — The inspectable runtime release is a concrete event distinct from the existing allegations about workspace uploads.
Decision trace
- 10-10 22:31groundZ.ai (Zhipu), a Chinese frontier lab, has open-sourced its full coding-agent stack — desktop, web, CLI, backend, and runtime — under Apache 2.0. This independently arrives at Scott's load-bearing
- 09-22 00:12promote_anchorZ.ai's official repository directly substantiates the already-open ZCode runtime-release case.