Free tool · CentaurNexus

Build, test and export your PAC file

Import an existing PAC file or click together rules from simple building blocks. Test right in the tool which URLs route where, then export the finished file - for Zscaler hosting or self-hosting.

Your PAC file never leaves your machine: everything runs in the browser, no data transfer.

Import an existing PAC

Paste the text or choose a file. Standard rules (private networks, domains, glob patterns, weekday bypass) are recognized automatically.

Rules

Active rules in fixed rank order (private networks/realm first, default forward structurally last). Disable instead of delete.

Generated PAC source

// Rules or an import produce a preview here.

Check against test URLs

Uses the same evaluation engine as the PAC Tester.

Choose export variant

For Zscaler hosting (recommended)

The ${GATEWAY} variables stay in place and are automatically substituted by Zscaler with the nearest access point (geo-routing, subcloud pinning and failover are preserved). Upload under Administration → Hosted PAC Files.

For self-hosting

The gateway variables are replaced with fixed values.

This drops geo-routing, subcloud pinning and automatic failover - every user runs through the same gateway, regardless of location.

Build and test it here.

Need versioning, four-eyes approval and rollback? CentaurNexus is the sovereign cockpit for your Zscaler world. EU hosting, GDPR-compliant.

View live demo

Frequently asked questions

What does the PAC Builder do?

It lets you click together a PAC file from simple rules or import an existing PAC file, check the rules right in the tool against test URLs, and export the finished file - either for Zscaler hosting (gateway variables stay in place) or self-hosting (gateway values are substituted with fixed ones).

What happens to rules the import doesn't understand?

They aren't lost. Anything the import can't translate into a rule stays as an unchanged text block at its original position and is put back unchanged on export. The tool visibly reports how many lines this affects.

How is it ensured that an imported PAC still routes the same way after export?

Through an automated round-trip test: the imported and the newly exported version are both actually executed against the same list of test URLs. If all results match, the round trip is lossless. The tool shows the result right after import.

What's the difference between the two export variants?

Zscaler hosting leaves the ${GATEWAY} variables in place - Zscaler automatically substitutes them with the nearest access point when serving the file (geo-routing). Self-hosting replaces these variables with fixed values you supply - this loses geo-routing, subcloud pinning and automatic failover, which the tool clearly flags.

CentaurNexus is an independent product of SourcingBlox GmbH and the optimal complement to your Zscaler Security Stack - not an offering from Zscaler, Inc. Product and brand names belong to their respective owners. This tool is a non-binding self-assessment provided without warranty.