Skip to content
Get ProGet Pro

Windows

Set up Guard as a Windows mainnet service, or rehearse in paper mode in your own account.

Guard runs on 64-bit Windows. The mainnet installer creates a managed Windows service with its own virtual service account, independent of your desktop login. Paper and testnet can also run in your normal user account.

Open Windows PowerShell 5.1 or PowerShell 7 as administrator, then run:

Terminal window
& ([scriptblock]::Create((irm https://zunderlabs.com/i.ps1))) -Network mainnet

To carry over your website rules and public account, use the command from Set up Guard. It adds -Rules and -Account; neither contains a secret. Setup asks you to confirm the account separately, choose the trading-equity cap, and enter the API wallet key in a hidden prompt.

The loader verifies the release signature, checksums and service helper before installing into protected machine locations. The service stores a machine-encrypted credential with restricted access. At every start, its broker decrypts it and passes it to the Guard child through standard input. The key stays out of command arguments, environment variables and plaintext files.

Mainnet requires native x64 Windows and an elevated interactive console. The installer refuses an unsupported platform or a per-user installation fallback. Do not use -Force, -InstallOnly or unattended setup for this service.

Setup leaves the service stopped and prints commands for this installation, including its protected helper and binding paths. Keep those commands: a standalone zunder-guard from your user PATH may address a different installation.

  1. Preserve the initial bot client key and browser pairing code in their intended secret storage. Neither is the API wallet key.
  2. Apply your licence, or approve pay per order for the same mainnet account.
  3. If this account has no mainnet journal yet, run the printed journal command with the repeated account confirmation and your review note. Keep existing journals; setup never clears a halt.
  4. Use the printed Start command, explicitly choosing the startup behavior. Check health, account, mainnet mode, active risk state and fee mode before starting your bot.

Guard binds to 127.0.0.1:8547. Service registration or Windows showing “Running” alone does not prove readiness. See Mainnet activation and bot integrations.

Use the installation’s printed management commands. Adding a client or changing risk or network configuration requires the service to be stopped and the changed configuration explicitly admitted again. Licence updates have their own command and do not require configuration readmission.

Stop bots before an upgrade. The managed upgrade preserves configuration, pairings, licence, encrypted credential and journals, and leaves the service stopped for your explicit Start. If interrupted, use its printed recovery instructions; do not rerun initialization or overwrite state.

Stop and uninstall through the protected helper, not by deleting the executable while the service is registered. Credentials and journals are retained unless you deliberately remove them separately.

For a separate per-user paper installation, run without administrator rights:

Terminal window
& ([scriptblock]::Create((irm https://zunderlabs.com/i.ps1))) -Network paper
zunder-guard run --network paper

The binary is installed to %LOCALAPPDATA%\Programs\zunder-guard; state is in %LOCALAPPDATA%\zunder-guard unless you set ZUNDER_GUARD_HOME. Ctrl-C stops the foreground process. For testnet, select -Network testnet during setup and use run --network testnet; its API wallet key is stored in Windows Credential Manager for your user. This per-user installation is separate from the mainnet machine service.

This page as plain Markdown, for people and LLMs: /docs/deploy/windows.md