Zephr

32 MCP tools · 11 platform surfaces · shared registry

Continuity / Sync

One workspace, every client.

Sync keeps a canonical workspace snapshot reconciled across the coding clients already on your machine. Push projects managed regions; adopt imports honest client edits; revoke removes only what Zephr wrote. Hand-edits outside the fences stay byte-for-byte.

Shipped - local reconcile
zephr sync status
docs/architecture.md - projected

managed region - Zephr writes

## Continuity

status: synced - hash 8d13ba0

hand-edit - preserved byte-for-byte

# my notes from Tuesday

# not touched by push or revoke

Illustrative example — not live data

The loop

Status, project, adopt, watch - or halt.

The verbs match the CLI. When a managed region conflicts, the loop does not overwrite: it stops, quarantines the collision under .zephr-conflict, and leaves the reader’s hand-edits alone. Abstention is a first-class outcome, not an error buried in a log.

01 - status

Read dual-layer state: local ~/.zephr/sync.state and cloud fleet_sync_state. Report synced, drifted, conflict, or not-installed.

02 - push

Project the canonical snapshot into client-native paths. Managed regions are fenced; unmanaged files are left alone.

03 - adopt

Import client-side edits into the snapshot after a secret preflight. Partial adopt is best-effort and never silent.

04 - watch

Optional file watcher re-runs the loop when a projected file changes, with loop-suppression so Zephr does not thrash itself.

Illustrative example — not live data

The states

Four states, read from two layers.

Local ~/.zephr/sync.state and cloud fleet_sync_state. Status reports what is true, including an honest empty when nothing has been installed yet.

synced

Local and cloud agree; projected files match the snapshot hash.

drifted

A managed region diverged. Reconcile before the next push.

conflict

A managed-region collision halted projection. Quarantined under .zephr-conflict.

not-installed

No local sync state yet. Status is honest empty, not fabricated green.

The state machine

Four states, five transitions, one honest read.

The verbs move the system between states. Conflict quarantines; revoke removes only managed regions. The state machine diagram shows how each verb changes the dual-layer state.

CLI

Five verbs. One contract.

The MCP tool zephr_sync_status exposes the same dual-layer read path the CLI uses. Codex TOML emit is deferred; Claude Code, Cursor, and opencode are the v1 projection targets.

zephr sync status

Report dual-layer state without writing files.

zephr sync push

Project the snapshot into client paths; halt on managed-region conflict.

zephr sync adopt

Import client edits after secret scan; quarantine unsafe material.

zephr sync watch

Re-run the loop on file change with loop-suppression.

zephr sync revoke

Remove only managed regions; leave hand-edits and unmanaged files intact.

Illustrative example — not live data

Guarantees

What Sync will not do.

The surface is defined as much by its refusals as by its verbs. These are load-bearing, not marketing.

  • No silent overwrite

    Managed-region conflicts halt and quarantine. They never clobber the reader's file.

  • Hand-edits preserved

    Content outside fenced managed regions is left byte-for-byte, including on revoke.

  • Secrets stay out

    Adopt runs a secret preflight. Unsafe material is refused rather than imported.

  • Revoke is surgical

    Revoke removes only managed regions Zephr wrote. It is not a workspace wipe.

See how clients connect, or read the platform.

Sync sits next to Connect: Connect projects the tool contract; Sync projects the workspace. The platform page shows the store addresses and the 32-tool contract underneath both.