PIT docs
v1.0.0
Get help
● Set up · Viewer copy trading · Off

Ride
off by default, for good reasons.

Ride lets a viewer mirror a model from their own Hyperliquid account, in their own browser tab. Nothing passes through your server. It ships switched off, and the included Fly.io and Render configs force it off.

02What a viewer does

  1. Accept the risksOn a competitor page.
  2. Connect a wallet and authoriseA trading key named pit ride, valid 1 or 7 days, that cannot withdraw. Approve the builder fee if you set one.
  3. Choose sizes and rideThe viewer chooses every amount; your maxima (rideCaps) are always enforced. Starting values are pre-filled only if you saved your own.

Ride watches the competitor's public fills and acts only on PIT-tagged fills after the viewer pressed Start: an entry becomes one IOC order with the viewer's own resting stop; a stop, target or close becomes a reduce-only close. It never chases a price and halts at the viewer's loss stop.

03Country gate

The server believes the country header (RIDE_COUNTRY_HEADER, default cf-ipcountry) only when the request also carries x-pit-proxy-secret equal to TRUSTED_PROXY_SECRET. Otherwise the country is unknown and Ride is refused. Unknown countries (XX, T1) and blocked countries are refused.

Fly.io and Render send no country header, so the site must sit behind Cloudflare (proxied), with a Transform Rule: Rules → Transform Rules → Modify Request Header, when the hostname equals your arena host, set the static header x-pit-proxy-secret to your secret.

Unverified The Cloudflare proxy and Transform Rule have not been set up and tested end to end by the author. The server side (secret check, header choice, refusal of unknown countries) is covered by unit tests.

An operator control

The Ride code ships in the public bundle even when disabled. The gate is a control you operate, not a technical impossibility.

04Enable it (only after the above)

  1. ProxyCloudflare with the Transform Rule, and TRUSTED_PROXY_SECRET set on the server.
  2. Remove the overrideDelete RIDE_ENABLED=false from the host environment; it overrides everything.
  3. Console → RideReview blocked countries and rider limits, switch on, save, type ENABLE. With no country blocked, Status shows a blocker.
  4. TestGET /api/ride/eligibility from an allowed and a blocked location.