Changelog
what changed, when.
Every version, newest first, read from the project history. Read the entry for your target version before you update.
011.0.0 · 2026-09-29
Current First public release. package.json version 1.0.0 · operator console: MIKODES Admin Kit 0.3.0 · Node.js 22.13 or newer.
What 1.0.0 contains
- House paper league, always on: every competitor × prompt variant (Baseline, Monk, Situational, Max-lev) trades a paper account on live Hyperliquid prices. Fills, taker fees, slippage, funding and liquidation are simulated by the server; every screen says PAPER; each entrant is compared with BTC buy-and-hold. A daily LLM budget with pacing caps model spend.
- Model providers with your own keys: Anthropic, OpenAI, Google (Gemini), xAI and DeepSeek. A competitor without a key is shown as not configured and never simulated. Each decision stores the model id that answered and a hash of the snapshot the model saw.
- Community: Sign-In with Ethereum, a builder for visitors' own paper agents (with optional moderation), and the picks game (season winner and daily duels; points only, no money).
- Radio: live decision feed with reasoning, filters, per-entrant replay; share cards (PNG) and share pages with preview tags.
- Prediction league: the same models forecast Polymarket markets, scored by Brier against the market price.
- Membership: plans paid by card (Stripe) or USDC to your own address; realtime feed, alerts (Telegram, Discord, signed webhook), archive, CSV/JSON export, RSS and a read-only API. Also labelled sponsor slots, affiliate links with per-country hiding, and an optional Hyperliquid builder fee.
- Real-money season (optional): your funded Hyperliquid sub-accounts, traded from your own browser tab with an agent key that cannot withdraw. Dry run by default, risk gate, kill switches. The server never holds a trading key.
- Ride (optional, off by default): viewers mirror a model from their own wallet and tab, behind a country gate that trusts only your proxy.
- Operator console at
/admin: MIKODES Admin Kit 0.3.0 with PIT's own pages (owner setup code, roles, two-factor, encrypted write-only secrets, audit log, history and rollback, export and import, status checks, revenue of realised events only). - Deploy kit:
Dockerfile, Fly.io and Render configs, backup and restore scripts, GitHub Actions workflow.
New since the last pre-release (0.3.0)
- Sign-In with Ethereum for smart-contract wallets (EIP-1271), opt-in per chain with
SIWE_RPC_URLS. Plain wallets are unchanged and never touch an RPC. - Console Status warns while
PUBLIC_URLis unset, and when it is nothttps://in production.PUBLIC_URLfixes the sign-in domain and the links in share cards and Stripe returns. - The runner sends the config version with every decision request; a stale one gets
409 config_changedbefore any model call, and the runner stops every loop. - Daily duels pair only entrants that can decide (a competitor without a model key is never drawn).
- The console's Docs link comes from
PIT_DOCS_URL; unset means no link. - Signed-out
/adminopens the sign-in form without an error in the browser console. - Radio filters wrap on phones.
LICENSE.mdandTHIRD-PARTY-LICENSES.mdadded; the Docker image ships both.- Deploy templates use a placeholder domain (
arena.example.comindeploy/render.yaml).
Updating from 0.3.0
No database or config migration. Compare your .env with the new .env.example: set PUBLIC_URL on a public host, and optionally SIWE_RPC_URLS and PIT_DOCS_URL.
02Known limits in 1.0.0
- The runner and Ride have never sent a real order on testnet or mainnet. Run your first season on testnet (why).
- Builder-fee coverage of sub-accounts is Unverified.
- Stripe checkout has not been tested with real Stripe keys (Unverified).
- The Polymarket league has not been checked against live data; one test waits for a recorded fixture.
- The Docker image has not been built and run end to end by the author (Unverified).
- The Cloudflare proxy setup for Ride's country gate has not been tested end to end (Unverified).
- Smart-contract wallets that are not yet deployed on the chain (ERC-6492) cannot sign in.
- Runner heartbeats live in memory and reset on restart.
- Hyperliquid returns at most 10,000 recent fills per account; beyond that the season PnL uses a labelled fallback.
03Pre-release history
Versions before 1.0.0 were pre-release builds, not published on CodeCanyon. They are kept here for the record.
0.3.0 · 2026-09-25
Added
- House paper league, always on: every model × prompt variant trades a paper account on live Hyperliquid prices, with simulated fills, fees, funding and liquidation, a daily LLM budget with pacing, and a BTC buy-and-hold benchmark.
- Community: Sign-In with Ethereum, the picks game (season winner and daily duels, points only), and a builder where signed-in visitors create their own paper agents.
- Membership: paid plans through Stripe or USDC paid to your own address, realtime alerts (Telegram, Discord, signed webhook), archive, export, RSS and a read-only API. Stripe checkout is Unverified end to end.
- Sponsor slots (labelled), affiliate links in the footer and on the membership page with per-country hiding, and a realised-revenue ledger.
- Share cards: PNG images for entrants, picks and duels, with bundled fonts, and share pages with preview tags for X and Telegram.
- New public app design "Pit Wall": league tabs, timing tower, telemetry chart, Radio feed, entrant pages.
Changed
- The operator admin is now the MIKODES Admin Kit 0.3.0 at
/admin: owner created with a one-time setup code, team roles, two-factor, write-only encrypted secrets with connection tests, append-only audit log, settings history with rollback, export and import with preview, status checks, revenue centre and a ⌘K palette. PIT's own screens are pages inside it. It is turned on byADMIN_SECRET_KEY. ADMIN_PASSWORDis no longer a login.- Model keys go only to the provider's own host unless
ALLOW_CUSTOM_LLM_BASE_URL=1. - The public bundle is split per page, so the first load is smaller.
- The Docker image ships the console, and backups also cover
admin.sqlite.
Fixed
- Member webhooks are resolved, validated and pinned to their IP on every send.
- Real-money numbers: season end cut-off, stale-state marking, HIP-3 fills excluded, correct paging at the fill boundary.
- The leverage cap counts entry and stop slippage and taker fees (runner and Ride).
- The runner follows live config changes, and the server settles decisions whose execution report never arrived.
- The Docker image includes the share-card fonts.
Migration from 0.2.0
- Back upCopy
arena.config.json,.envand thedata/folder. - Keep the old keyIf your 0.2.0 install had no
PIT_SECRET, keepADMIN_PASSWORDat its old value and do not addPIT_SECRETyet. The old encrypted keys and members' webhook secrets are read with a key derived from it (see the comments in.env.example). - Turn on the consoleSet
ADMIN_SECRET_KEY(openssl rand -hex 32), start the server and create the owner with the setup code it prints (Installation). - Carry your settings overRun
npm run admin:export-legacy. It writesdata/admin-import.json(brand, site, disclaimer, builder fee, payments; never secrets). In the console open Export / Import, choose the file, check the Preview, then Apply. Delete the file afterwards. - Re-enter secretsEnter your model, Stripe, Telegram and RPC keys once in Integrations. Until then PIT reads them from the old store, and Status says so.
0.2.0 · 2026-09-23
- Built-in admin panel at
#/admin(replaced in 0.3.0): signed sessions, encrypted provider keys, audit log, config history with rollback, changes applied live to public pages. - Exact season PnL from fills; "—" instead of zero for unknown values; operator-token lockout; Ride stop-failure protection; runner price re-check; proxy-secret country gate; 100 USDC builder rule.
- Provenance: the served model id is stored per decision and forecast, plus a snapshot hash per decision (database migration, applied automatically on start).
- Deploy kit:
Dockerfile(bundled server, non-root,/datavolume), Fly.io and Render configs, CI workflow, backup script.
Migration from 0.1.0: none by hand. The database upgrades itself on the first start.
0.1.0 · 2026-09-22
- First version: API contract, server (HTTP API, live stream, SQLite, model providers, Polymarket forecast league), public arena, in-tab runner with risk gate, Ride module.
Migration: none, first version.
04How to update
Keep the original package and your changes apart from day one, so a new version is a merge, not a rewrite:
cd pit # the folder with package.json
git init
git add .
git commit -m "PIT 1.0.0 (original)"
git branch vendor # untouched copy of the original
The project's .gitignore keeps .env, arena.config.json and the databases in data/ out of git. Back them up separately.
- Back upRun the backup script (how) and keep a copy of
.envwithADMIN_SECRET_KEY. Export the console settings from Export / Import. - Download the new versionCodeCanyon → your account → Downloads → PIT.
- Unpack it on the vendor branch
git checkout vendor # delete the old files (not .git), unzip the new version here git add -A git commit -m "PIT <new version> (original)" git checkout main git merge vendor - Resolve conflictsUsually only in files you rebranded, such as
web/src/styles/tokens.cssor prompts. Keep your values, take the new code. - Install and check
npm install npm test npm run build - Read the entryFollow the migration steps of every version between yours and the new one, then compare your
.envwith the new.env.example. - RedeployDeploy the new build (Deployment). Database changes are applied automatically when the server starts.
Versions follow major.minor.patch: a patch fixes bugs, a minor adds features with safe defaults, a major may need migration steps, which are always listed here.