# Install and CLI

Install zn-gate for Node.js, Python or from source, and the commands it provides.

Source: https://usezn.com/docs/zn-gate/

zn-gate is the open-source local engine: deterministic rules, an MCP server and proxy, an evidence ledger and SDKs. It has no runtime dependencies and works offline on macOS, Windows and Linux.

## Install

<div class="zn-tabs">
<div data-tab="npm">

```bash
# Run without installing
npx -y zn-gate --version

# Or add it to a project
npm install zn-gate
```

</div>
<div data-tab="pip">

Python 3.8 or later, standard library only:

```bash
pip install zn-gate
```

</div>
<div data-tab="Source (Rust core)">

```bash
git clone https://github.com/usezn/zn
cd zn && cargo build --release
```

</div>
</div>

## Commands

| Command | What it does |
| - | - |
| `init` | Finds MCP configs in supported agent environments and wraps their servers with zn ([details](https://usezn.com/docs/zn-gate/shield/)) |
| `shield` | Wraps any MCP server command (`uvx`, `npx`, `node`, `python`) with zn |
| `mcp` | Runs zn as a standalone MCP server ([clients](https://usezn.com/docs/mcp/)) |
| `analyze <text>` | Checks one input and prints verdict and rule |
| `scan <path>` | Recursively audits prompt templates, Markdown, skills and configs for injection traps |
| `evidence` | Verifies, browses and exports the audit ledger ([details](https://usezn.com/docs/zn-gate/evidence/)) |
| `logs` | Tails or inspects security event logs |
| `test` | Runs the built-in self-test (attack and benign vectors plus latency) |
| `status` | Shows engine configuration and gateway connectivity |

Run `npx -y zn-gate --help` for every option.

## Configuration

| Setting | How to set it | Effect |
| - | - | - |
| API key | `ZN_API_KEY` env var or `--key` | Enables the cloud neural gate in addition to local rules |
| Local only | `--local-only` | Forces offline rules even when a key is set |
| Endpoint | `--url` | Overrides the gateway URL |
| Scan scope | `--all`, `--include .rst,.xml`, `--exclude fixtures` | Controls which files `scan` reads |
| Debug | `--verbose` | Debug logging to stderr |

Without a key, zn-gate uses local rules only and never sends data anywhere.
