Zipper Pilot
Support
The widget on this site is the live Zipper Pilot service — same hall.js, engine, and voice booths customers embed. It runs here on Enterprise with Zipper’s own scrolls. When we upgrade Pilot, this public hall upgrades with it. Asking for a human still needs a sign-in so agents can see your subscription and apply the right SLA.
Response times by plan
Free
48 hours
Business hours
Community queue. Human review after you sign in so we can confirm the Free plan.
Starter
8 hours
Business hours
Email support. First response within 8 hours on the Starter plan.
Business
4 hours
Business hours, extended
Priority queue. First response within 4 hours on the Business plan.
Scale
2 hours
Extended hours
Named account support. First response within 2 hours on the Scale plan.
Enterprise
15 minutes
24/7 on-call
Enterprise on-call. First response within 15 minutes, any hour.
Zipper Pilot already knows
Talk to a human
Human support starts after you sign in so we can apply the SLA for your plan.
Zipper applies a different queue to every plan. We can only see that plan after you sign in.
Free: community queue, first response in 48 hours. Starter: 8 hours. Business: 4 hours. Scale: 2 hours. Enterprise: 15 minutes, 24/7.
Sign in (or create an account), then ask for a human from this widget or open Dashboard → Support.
Plans and what they include
Workspace-priced plans from Free through Enterprise — not billed per hostname.
Plans are billed per workspace, not per domain. Free evaluates Zipper. Starter, Business, and Scale are self-serve. Enterprise is an order form.
Change plan from Dashboard → Billing → Plans. Human support uses the same plan to pick your queue.
Billing, invoices, and Paystack
Recurring Paystack checkout and official PDF receipts.
Checkout runs through Paystack. Paid invoices become official PDF receipts issued by Spatial Regal Digital Ltd.
Open Dashboard → Billing for the current plan, payment method, and invoices. Cancel at period end keeps the workspace on the paid plan until the period closes.
Portcullis bot checks
Site key on the page, secret on Siteverify — same pattern as Turnstile.
Create a widget in Dashboard → Portcullis. Put the site key on your page and the secret on your server for POST /api/portcullis/v1/siteverify.
Demo site key 0xDEMO with secret demo works on this origin for local forms. Production widgets need your hostname on the allow list.
Zones and services
Each hostname is a zone. Creating one provisions every named service, including Palace Guard.
A zone is a hostname on Zipper. Creating a zone provisions every named service automatically, including Palace Guard (edge antivirus).
The Herald stores records and answers DNS-JSON at GET /dns-query?name=&type= (application/dns-json). Proxied A flattens to 191.215.40.237. Zipper does not listen on port 53.
The Gallery stores original image bytes. Serve /gate/{hostname}/_gallery/{key}. /cdn-cgi/image/{params}/{key} is accepted and ignored — no transcode.
Pause a service from Dashboard → Services. Writes to a paused service are refused until you raise it again.
Palace Guard antivirus
Edge antivirus that cordons files in flight using public hashes, filename tricks, polyglots, SVG/PDF smuggle, and ZIP headers.
Palace Guard is Zipper’s edge antivirus. Open Dashboard → Services → Palace Guard, drop a file or tap EICAR / SVG XSS / PDF JavaScript, and watch the cordon.
Live cordon (default on) scans Gallery, Archives, Video PUT, Site Hosting HTML, inbound mail (subject/preview), and function source before persist. Hostile objects return 422 palace_guard_cordon. Quarantined hashes stay held on serve. POST /api/v1/guard/scan with a name, optional SHA-256, and optional content_b64 for CI. Samples are never stored.
Cloudflare has no analogue. Pair Keep (HTTP) with Palace Guard (objects). It is not a detonation sandbox — zip bombs are refused at the header.
Control plane API tokens
Bearer tokens from Dashboard → Settings authenticate /api/v1.
Mint a token in Dashboard → Settings. Send Authorization: Bearer tz_live_… on /api/v1 routes.
Writes accept Idempotency-Key. Every response includes request_id. Plan quotas apply on create.
Sign-in, 2FA, and profile
Password or magic link, then country/phone and authenticator 2FA.
New accounts complete a profile (country and phone), then enroll an authenticator. Backup codes are hashed and shown once.
Reset the authenticator with a unused backup code on the sign-in recovery path, then enroll a new factor.
What Zipper actually runs
Multi-layered Global Server nodes: HTTP DDoS and WAF, in-process cache, DNS-JSON, original-byte images.
This is honest production on multi-layered Global Server nodes: application-layer DDoS and WAF, in-process cache, DNS-JSON (not port 53), and image delivery (not transcoding).
Zipper runs the control plane, The Crown cache, The Keep, The Moat, Herald DNS-JSON, and Edge AI. Object storage holds Gallery, Archives, and Video objects.
The substrate catalog at /docs/gaps lists Cloudflare- and Neon-scale jobs Zipper maps onto Global Server nodes.
Optional Cloudflare orange-cloud can sit in front of a website while Zipper stays the origin. Grey-cloud db, pool, and *.cellar. Guide: /docs/cloudflare-in-front.
Read /docs/honest-production for the pathways.
How to use The Armory
Spent-cartridge warrants, hatch-bound sessions, musters, kit, and an SSE roll on this Zipper node.
The Armory is a backend for iOS, Android, and the web on this Zipper node. Create an app in Dashboard → Services → The Armory. Copy the endpoint, anon key, and service key. The service key stays on the server.
Sign in with POST /api/v1/armory/{id}/auth/signup and X-Armory-Key: za_anon_…. The JSON includes a session plus warrants.write and warrants.read.
Write with POST /musters/{name}, Authorization: Bearer za_sess_…, and X-Armory-Warrant. A write warrant fires once (spent_cartridge). Mint the next at POST /warrants.
Browser Origin is the hatch. Native apps omit Origin. Kit uploads and JSON string fields pass Palace Guard. The roll is SSE on this process, not FCM.
Read Docs → Using The Armory for words, kits, headers, and copy-paste curl.
Is Zipper down?
Health probes and the dashboard edge pulse.
GET /api/health and /api/ready are the public probes. The dashboard header shows Edge healthy when the last keep-alive succeeded.
If the control plane returns 503, wait a few seconds — it auto-retries and is never cached by the browser. Clearing Chrome cache should not be required.