32 MCP tools · 11 platform surfaces · shared registry
One workspace, every client.
Sync keeps a canonical workspace snapshot reconciled across the coding clients already on your machine. Push projects managed regions; adopt imports honest client edits; revoke removes only what Zephr wrote. Hand-edits outside the fences stay byte-for-byte.
zephr sync statusmanaged region - Zephr writes
## Continuity
status: synced - hash 8d13ba0
hand-edit - preserved byte-for-byte
# my notes from Tuesday
# not touched by push or revoke
Illustrative example — not live data
Status, project, adopt, watch - or halt.
The verbs match the CLI. When a managed region conflicts, the loop does not overwrite: it stops, quarantines the collision under .zephr-conflict, and leaves the reader’s hand-edits alone. Abstention is a first-class outcome, not an error buried in a log.
01 - status
Read dual-layer state: local ~/.zephr/sync.state and cloud fleet_sync_state. Report synced, drifted, conflict, or not-installed.
02 - push
Project the canonical snapshot into client-native paths. Managed regions are fenced; unmanaged files are left alone.
03 - adopt
Import client-side edits into the snapshot after a secret preflight. Partial adopt is best-effort and never silent.
04 - watch
Optional file watcher re-runs the loop when a projected file changes, with loop-suppression so Zephr does not thrash itself.
Illustrative example — not live data
Four states, read from two layers.
Local ~/.zephr/sync.state and cloud fleet_sync_state. Status reports what is true, including an honest empty when nothing has been installed yet.
Local and cloud agree; projected files match the snapshot hash.
A managed region diverged. Reconcile before the next push.
A managed-region collision halted projection. Quarantined under .zephr-conflict.
No local sync state yet. Status is honest empty, not fabricated green.
Four states, five transitions, one honest read.
The verbs move the system between states. Conflict quarantines; revoke removes only managed regions. The state machine diagram shows how each verb changes the dual-layer state.
synced
Local and cloud agree; projected files match the snapshot hash.
drifted
A managed region diverged. Reconcile before the next push.
conflict
A managed-region collision halted projection. Quarantined under .zephr-conflict.
not-installed
No local sync state yet. Status is honest empty, not fabricated green.
Transitions
- pushnot-installed → synced— first projection
- driftsynced → drifted— managed region diverged
- adoptdrifted → synced— import client edits
- conflictdrifted → conflict— managed-region collision
- revokesynced → not-installed— remove managed regions
Five verbs. One contract.
The MCP tool zephr_sync_status exposes the same dual-layer read path the CLI uses. Codex TOML emit is deferred; Claude Code, Cursor, and opencode are the v1 projection targets.
zephr sync statusReport dual-layer state without writing files.
zephr sync pushProject the snapshot into client paths; halt on managed-region conflict.
zephr sync adoptImport client edits after secret scan; quarantine unsafe material.
zephr sync watchRe-run the loop on file change with loop-suppression.
zephr sync revokeRemove only managed regions; leave hand-edits and unmanaged files intact.
Illustrative example — not live data
What Sync will not do.
The surface is defined as much by its refusals as by its verbs. These are load-bearing, not marketing.
No silent overwrite
Managed-region conflicts halt and quarantine. They never clobber the reader's file.
Hand-edits preserved
Content outside fenced managed regions is left byte-for-byte, including on revoke.
Secrets stay out
Adopt runs a secret preflight. Unsafe material is refused rather than imported.
Revoke is surgical
Revoke removes only managed regions Zephr wrote. It is not a workspace wipe.
See how clients connect, or read the platform.
Sync sits next to Connect: Connect projects the tool contract; Sync projects the workspace. The platform page shows the store addresses and the 32-tool contract underneath both.