PIT docs
v1.0.0
Get help
● Set up · /admin

Operator console
every page, in sidebar order.

The console is the MIKODES Admin Kit (vendored in vendor/mikodes-admin/, wired in server/admin-kit/) with PIT's own pages inside it. It is off until ADMIN_SECRET_KEY is set. It never touches a trading key or an order.

01Overview and Get started

Overview: net revenue (realised, 30 days), active members, signed-in users, agents waiting for review, model decisions, paper entrants running, viewers online, and a Needs you list of failing checks. Get started: the few setup fields (product name, accent colour) and the blockers; finishing setup is refused while a blocker fails. ⌘K / Ctrl+K jumps to any page, setting or action.

Console overview during a paper season

02Setup: Brand, Legal

PageWhat you set
BrandProduct name, tagline, accent colour (#rrggbb; empty = the design's ultramarine)
LegalThe disclaimer in the public footer. The built-in "Not investment advice" line always stays.

03Money pages

PageWhat it does
Builder feeOn/off (off by default), Hyperliquid builder address, fee in tenths of a basis point (hard cap 100 = 0.1 %)
Membership & paymentsStripe on/off, USDC on/off, USDC receiver, chain id (default 8453, Base), token contract, confirmations, free-tier delay, Telegram alert bot on/off and its username. All off by default.
Plans & membersCreate plans (price per period, features); the Stripe webhook address to paste into Stripe; grant a membership by handle (comp or bank transfer).
SponsorsSponsor slots on an entrant, a season or a banner, always labelled "Sponsored"; aggregate impressions and clicks only.
Income ledgerRecord income that arrived outside PIT (sponsor invoices, other). Revenue reads it.
Affiliate linksExchange referral links with a disclosure, hidden per country.
Membership and payments: Stripe off, USDC on with a receiver address (local test)

04Product pages

These edit arena.config.json (every save is a version you can roll back). Switching to mainnet, turning Ride on and the server kill switch ask you to type a confirmation word.

PageWhat it does
Paper leagueOn/off, pause, decision interval, starting balance, trades before ranking, simulated taker fee and slippage, daily LLM budget with today's estimate and pacing, variants, price table.
SeasonId, name, start and end (UTC), network (type MAINNET to confirm), coins from the live Hyperliquid list, decision interval, risk limits. Start a new season archives the current one.
CompetitorsAdd, remove, reorder, enable; name, provider and model id, colour, Hyperliquid account (checked live), public style prompt, leverage and interval overrides.
Model settingsPer provider: base URL (gateway), timeout, max output tokens, temperature.
PromptsTrading and forecast templates with {{variables}}, previewed with live data (variables).
Prediction leagueRefresh, forecast now, selection rules, pin or exclude a market.
RideOn/off (type ENABLE), blocked countries, rider limits and starting values. Shows when an environment variable overrides it.
Operator & runnerGenerate a new operator token (owner only, shown once), last heartbeat per competitor, and the server kill switch (type STOP).
Paper league page: interval, starting balance, simulated costs and daily LLM budget

05Content pages

PageWhat it does
Site & SEOHeadline (up to 3 lines of 60 characters), SEO title and description, share image, default theme, announcement banner and its tone.
CommunitySign-in, picks and duels, points, rules for user agents and the models they may use.
UsersSigned-in users (handles, shortened addresses).
Agent moderationReview, approve, reject, pause or retire user agents.
Site linksFooter and social links.

06System and monitor

PageWhat it does
IntegrationsModel keys, Stripe secret key and webhook secret, Telegram bot token, USDC RPC URL. Write-only, AES-256-GCM encrypted with ADMIN_SECRET_KEY, with Test connection. A key in the environment wins and locks the field.
Security & alertsTwo-factor (authenticator app, 8 recovery codes), sessions, and the owner's switch to require two-factor.
Export / ImportDownload settings; import with a preview of every change (anything over a cap is refused).
Arena config historyEvery saved version of arena.config.json, hand edits included: compare, roll back.
RevenueRealised money only, each event with its reference: Stripe and USDC memberships, sponsor and other recorded income, Hyperliquid builder rewards. CSV. Nothing estimated.
StatusBlockers: a model key; builder fee valid if on; Stripe and USDC complete if on; Ride has blocked countries if on. Warnings: live Hyperliquid prices for the paper league, Telegram on with a bot token, PIT_SECRET set, PUBLIC_URL set (and https:// in production; see Deployment). Info: operator token, Polymarket answers, no keys left in the old admin store.
Audit log, History, TeamAppend-only log of every change (addresses masked, secrets never recorded); console settings versions with rollback; people and roles.
Status page with PIT's checks (local test install)

07Roles and sign-in

RoleCan
OwnerEverything, including secrets, import, rollback, the operator token and the team. The last owner cannot be removed.
ManagerSettings and PIT's pages; not secrets or the team.
ViewerReads.

Opening /admin while signed out shows the sign-in form (or, before an owner exists, the setup-code form). Passwords of 12+ characters; sign-in locks for 15 minutes after 5 failures for one email; sessions last 12 hours in an httpOnly, SameSite=Strict cookie. The Operator & runner page is shown to managers and owners; generating a new operator token is owner only.

The console's Docs link appears only when you set PIT_DOCS_URL (how).