Mainframe Path Start learning free
Core10 min readLesson 1 of 3

What Zowe is and how it connects

Zowe is an open-source project that lets modern tools work with z/OS. Its client tools run on your PC and talk to REST services on the mainframe, usually z/OSMF, so you can work with datasets, jobs and Unix files without a 3270 screen.

Why Zowe exists

For decades the only way to work on z/OS was a 3270 terminal running TSO and ISPF. It works, but new developers arrive knowing VS Code, terminals, scripts and Git, and the green screen is hard to automate. Zowe was started in 2018 under the Open Mainframe Project, part of the Linux Foundation, so that the mainframe could be driven by the same kind of tools as any other server. IBM, Broadcom, Rocket Software and others contribute to it, and the code is open source.

Zowe does not replace ISPF. Many experienced people use both: ISPF for quick browsing and utilities, Zowe tools when they want an editor with search, side-by-side compare, or scripting.

The main pieces

Zowe is a family of tools, not one product
Client side (your PC)
Zowe Explorer for VS CodeZowe CLIClient SDKs for Node.js, Python and others
Server side (on z/OS, optional)
API Mediation Layer (gateway and single sign-on)Application Framework (web desktop)Supporting services
What the clients call
z/OSMF REST APIs (most common)Other back ends through extensions, such as FTP or vendor APIs

An important point that confuses people: you can use Zowe Explorer and the Zowe CLI without installing the Zowe server components at all. All they need is a REST service on z/OS that understands requests such as 'list these datasets' or 'submit this job'. At most sites that service is z/OSMF.

z/OSMF as the back end

z/OSMF (z/OS Management Facility) is part of z/OS. It runs as started tasks on a Liberty web server and provides REST interfaces for files, jobs and system tasks. When you click a dataset in VS Code, Zowe Explorer sends an HTTPS request to z/OSMF, which reads the dataset with your user ID and sends the content back.

One request, end to end
VS Code / CLIZowe client
HTTPSREST request
z/OSMFLiberty on z/OS
RACF checkyour user ID
Dataset, job, fileMVS, JES, USS

Because every request runs under your own identity, RACF (or ACF2 or Top Secret) checks it exactly as it would in TSO. Zowe gives you no extra authority. If you cannot read a dataset in ISPF, you cannot read it in VS Code either.

Profiles and the team configuration

Zowe needs to know the host name, port and how to sign on. Since Zowe version 2 this is kept in a team configuration file called zowe.config.json. It holds profiles: a z/OSMF profile for the REST connection, a base profile with shared values, and optionally SSH or TSO profiles. A team can keep the shared file in a project folder or Git repository, and each person keeps their own overrides in zowe.config.user.json.

Part of a zowe.config.json (illustrative)
{
  "profiles": {
    "lpar1": {
      "properties": { "host": "mvs1.example.com" },
      "profiles": {
        "zosmf": { "type": "zosmf", "properties": { "port": 443 } }
      },
      "secure": ["user", "password"]
    }
  },
  "defaults": { "zosmf": "lpar1.zosmf" }
}

The secure array lists properties that must not be written to the file. Zowe stores them in the operating system's credential store instead (Windows Credential Manager, macOS Keychain or a Linux keyring).

Common first-day problems

SymptomUsual cause
Connection refused or times outWrong host or port, or a firewall or VPN between you and the LPAR
Certificate or self-signed errorThe site uses an internal certificate authority your PC does not trust; ask how to install the site CA rather than switching verification off
401 UnauthorizedWrong password, expired password, or a revoked user ID
Signed on, but every list is empty or forbiddenYour user ID has not been given z/OSMF access, or lacks access to those datasets

zowe zosmf check status is a quick way to test the connection from the CLI: if it works, the profile, network and sign-on are all correct.

Common mistakes

Thinking Zowe needs its own server install

Zowe Explorer and Zowe CLI only need a REST back end such as z/OSMF. The Zowe server components add things like a gateway and single sign-on, but are optional.

Putting passwords in zowe.config.json

That file is often shared or committed. Keep user and password in the secure array so they go to the operating system credential store.

Turning off certificate checking to make the error go away

It removes protection against someone intercepting your password. Install the site's certificate authority as your security team describes.

What you will see at work

Key terms

Check your understanding.
Take this lesson's quiz and save your progress. Free.

Take the lesson quiz
Datasets, jobs and USS files from your PC →