CLI
A single binary with no dependencies, for macOS, Linux and Windows.
Installing
Download it from zero.nnumbers.com.br/downloads, check the checksum and put it on your PATH:
curl -fsSLO https://zero.nnumbers.com.br/downloads/zero-darwin-arm64.tar.gz
curl -fsSLO https://zero.nnumbers.com.br/downloads/SHA256SUMS
shasum -a 256 -c SHA256SUMS --ignore-missing
tar -xzf zero-darwin-arm64.tar.gz
sudo mv zero /usr/local/bin/
zero version
On Linux, use sha256sum -c. On Windows, extract the .zip and put zero.exe in a folder on your PATH.
Authenticating
zero auth login
The CLI asks for your email and opens the approval in the browser: the terminal shows a link and a short code, you check the code on your company's sign-in page and approve — with its MFA and policies. The email only finds out where to send the sign-in; the provider is who authenticates. The session is stored encrypted, with the key in the system keychain (where there is no keychain, in a file readable only by your user), and it renews on its own.
For machines (CI, containers) there are two paths: ZERO_TOKEN in the environment, which takes precedence over everything and is not stored, or a service token read from standard input — never from an argument, which ends up in shell history and in the process list:
echo "$TOKEN" | zero auth login --token
zero auth status # who am I, and where
zero auth logout # discards the credential
If your account belongs to more than one organization:
zero orgs list
zero orgs use <organization>
The journey
PROJ=$(zero projects create shop) # the production environment is created with it
zero projects get "$PROJ" # shows the environment's identifier
zero source set "$PROJ" --provider github --repo you/shop --ref main
SVC=$(zero services create web --env <environment> --subdir apps/web)
zero deploy "$SVC"
projects create and services create print only the identifier on stdout — deliberately, so it can be chained in scripts. Explanations go to stderr.
The repository belongs to the project. zero source set configures the source; the service only declares the folder it builds (--subdir). --repo accepts owner/repo, the full URL, or the SSH address; --provider (github, gitlab, or bitbucket) is required when the address does not name the host. For a private repository, add --token: the token is read from standard input, never from an argument. --repo on services create or on deploy is refused, with a sentence pointing to zero source set.
Creating a service does not deploy it, and the CLI says so.
Deploying
zero deploy "$SVC"
zero deploy "$SVC" --ref release/2026-09 # another branch or tag, just this once
zero deploy follows the deployment live and exits with code 0 when it becomes ready and 1 when it fails — showing the reason, such as HEALTH_CHECK_FAILED when the application started but did not answer. The reasons are in Deployment states.
Operating
zero status <project> # environments, services and what is up
zero logs --project <project> --follow # the application's output, live
zero logs <deployment> --build # the build output
zero releases <service> # the immutable history of activations
zero artifacts <service> # the versions already built, each with its digest
Application log
zero logs --project <project> # the LATEST lines of the last hour
zero logs --project <project> --follow # then each new line, until Ctrl-C
zero logs --project <project> --level error --from 24h --follow
zero logs --project <project> --all --from 7d > app.log # the whole period, to a file
zero logs --project <project> --all --json | jq -r .message
| Option | What it does |
|---|---|
--follow | Shows the latest lines, then each new line, until Ctrl-C (exit code 0) |
--all | The whole period, from the oldest line to the most recent |
--from 30m|24h|7d|<instant> | The start of the period; the default is one hour ago |
--to <instant> | The end of the period; without it, until now |
--service, --level, --search | Narrow by service, level (debug, info, warning, error), and text |
--limit | How many lines the first page brings, from 1 to 1000 |
--json | With --follow and --all, one object per line |
--follow does not lose lines when the application has more than one instance, nor when the network hiccups: it continues from where it stopped. The log is kept for 7 days — see Logs.
Promoting
zero promote web-prod --from web-preview
See Promoting between environments.
Deleting a project
zero projects delete <project> --reason "pilot ended" --yes
Without --yes, the CLI asks for the project's name, typed — and refuses when the input is not a terminal: in a script, --yes is the explicit confirmation. The deletion is followed to the end: code 0 when it finishes, 1 when it fails, and repeating the command tries again. What changes and what stays is in Deleting the project.
Users and access
zero users list # the identity provider's people, with each one's access
zero users search carolina # by name, email or username
zero access grant <id> --role operator
zero access update <id> --role member --project <space>
zero access revoke <id> # the account in the provider keeps existing
zero users create --email ana@company.com --first-name Ana --last-name Souza --role admin
zero users resend-password-setup <id>
Granting takes effect immediately, with no invitation and nothing to accept. create has no password option: the account is created without one and the identity provider sends the person the official email to set it. The <id> is the person's identifier in the provider, shown by zero users list. Details in Users and access.
Networking Between Projects
zero networks create payments
zero networks attach <environment> --network payments # one environment of each project
zero networks get payments # who is in the network
zero services internal-name <service> api # prints api.zero.internal
zero networks grant payments --from <project> --to <service> --wait
zero networks grants payments # the permissions, for services and internal entries
zero networks revoke payments <permission>
zero projects network <project> # who comes in, where it goes out, the internal addresses
zero environments network <environment> # the environment's network and the state of its rules
The network and the internal entry go by name or by identifier. The permission uses the service's port; --port is accepted only if it is that one.
A project with no internet address:
zero projects create billing --internal
zero projects exposure <project> internal # or public, to go back
Gateway internal entries, with paths to services in the network:
zero entries create api --network payments # api.zero.internal
zero entries add-route api --service <service> --path /v1 --strip-prefix
zero entries add-route api --service <other-service> --path /health --exact
zero entries routes api
zero entries grant api --from <project>
zero entries grants api
zero entries remove-route api <route>
zero entries revoke api <permission>
zero entries delete api
With a single Gateway in the organization, the CLI uses it; with more than one, say which with --gateway.
Revoking, detaching from the network, removing a path, changing the exposure, removing the name and deleting ask for the target's name, typed — and refuse when the input is not a terminal: in a script, --yes is the explicit confirmation. --wait waits for the rule to be applied and exits with code 1 if the deadline passes (--timeout, 5m by default). See Networking between projects.
Domains
There is no CLI command for domains. Changing the address and custom domain zones live in the console and in the API.
Details that matter
--jsonon nearly every command, for script consumption.--detachondeployandpromotereturns control immediately; without it the CLI follows live to the outcome.Ctrl-Cwhile following cancels the following, not the deployment — and closes the connection cleanly.- The exit code is non-zero when the operation fails, so
zero deploy && zero promoteis safe.
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.