OUTRIDER docs
v1.0.0
Live demo Get help
● Start · /admin

Operator console
owner, team, settings.

The console at /admin is where you sign in, invite your team, change the desk's main settings, store keys and read the audit log. It is built on the MIKODES Admin Kit and runs inside the desk's own server.

01Create the owner account

  1. Start the desknpm start (or npm run dash). On the first start the terminal prints:
    [admin] No owner account yet. Open /admin and create it with this one-time setup code:
    
        <setup code>
  2. Open the consoleGo to http://127.0.0.1:8790/admin on the same machine.
  3. Create the ownerEnter the setup code, your email and a password of at least 12 characters. You are signed in as owner and the setup code stops working.
  4. Finish setupThe console walks you through the setup fields (mode, product name, accent colour, support email). Anything you skip can be changed later.
Lost the code?

Restart the desk. Every start before the owner exists prints a new code, and any printed code works until the owner is created.

Before the owner exists

The dashboard answers only requests made on the machine itself (a loopback address such as 127.0.0.1), so create the owner there or through an SSH tunnel. /admin stays reachable, and creating the owner needs the setup code printed in the server log. After the owner exists, every dashboard page and API needs a console session: the dashboard sends you to /admin/ to sign in.

02Team and roles

RoleCan
viewerSign in and watch: the dashboard, settings, health, history and audit log. Viewers cannot change settings or use the kill switch.
managerEverything a viewer can, plus: change settings, engage and release the kill switch, test keys, see the team list.
ownerEverything, plus: add and remove members, change roles, set or replace secret keys, roll back to an older settings version, export and import settings. The last owner cannot be demoted.

An owner adds a member in Team with an email and a role. The console shows a one-time password for that member once; send it to them over a private channel. They change it after signing in.

03Sign-in security

  • Two-factor. Every member can turn on an authenticator app (TOTP) in Account. You get 8 one-time recovery codes; keep them offline. The owner can require two-factor for owners and managers in the kit settings; members without it are then asked to enrol before they can act.
  • Lockout. After 5 failed sign-ins within 15 minutes, that account waits before it can try again.
  • Sessions. A session lasts 12 hours. You can see your sessions and sign them out, one by one or all at once. The cookie is HttpOnly, SameSite=Strict, and Secure when the console is reached over HTTPS.
  • Password change signs out your other sessions.

04Settings sections

Settings are grouped as defined in src/admin/manifest.ts. The desk sections are read by the running desk at start and applied again right after every save: no restart needed, except where noted.

SectionFieldsEffect on the desk
DeskMode (paper / alerts only), paper bankroll (SOL, default 10), max open memecoin positions (5), daily loss stop (10 %)Live
Memecoin lanesOn/off and ticket size (% of paper equity) for moonshot (1 %), graduation (1.5 %), revival (1 %) and smart money (1 %). Ticket range 0.1–5 %.Live (Memecoin lanes)
Smart walletsRounds before a wallet can be smart (8), minimum mean hold in seconds (60), live candidate feed URLs, smart wallets needed for a consensus (3)Live (Smart wallets). Feed URLs must start with https://.
Liquidation mapBackground refresh on/off, coins, accounts read per refresh (2,000), refresh every N minutes (30), alert distance (1.5 %), minimum cluster size for alerts (USD 5,000,000)Live (Liquidation map)
Trend & leverageLeverage profile: safe, growth (default), aggressiveLive (Leverage)
IntegrationsAnthropic API key, Telegram bot token, TypeSafe Jev API key, Solana RPC URL — all four are secrets (encrypted, owner-only)Applied at start and on save. The RPC URL sets solanaRpc and the pump.fun WebSocket (details).
Brand, Legal, AccessProduct name, tagline, accent, logo, support email, website; terms, privacy, disclaimer; maintenance mode, announcement, blocked countriesStored by the console. The desk and dashboard in this version do not read them.
NotificationsAlert email, webhook URL, webhook signing secretThe console can POST signed alerts to your HTTPS webhook when a blocker health check fails (turn it on in the kit settings). The email field is Not active in this version. Desk trade alerts go to Telegram.
config.json is the base

A Desk, Memecoin lanes, Smart wallets, Liquidation map or Trend field overrides config.json only once you change it from its console default. The full mapping is in Configuration.

05Keys and secrets

  • Secret fields are write-only: they can be replaced or cleared (owner) and tested (manager or owner; the Telegram token test calls Telegram's getMe), never read back.
  • If the matching environment variable is set (ANTHROPIC_API_KEY, TELEGRAM_BOT_TOKEN, TYPESAFE_API_KEY), it wins and the field is locked in the console.
  • Stored secrets are encrypted with the console's secret key: ADMIN_SECRET_KEY from the environment, or a key generated once into data/.admin-secret-key (file mode 600). Without that key, stored secrets cannot be read. Back it up with data/ (Backups).

06Health, metrics and the live desk

CheckSeverityPasses when
Solana RPC answersblockergetHealth returns ok on your solanaRpc
Hyperliquid API answersblockerThe info API returns prices
pump.fun stream is livewarningAn event in the last 5 minutes
Trade journal hash chain intactblockerThe journal verifies (verify)
Liquidation map refreshed in the last 2 hinfodata/liqmap.json is younger than 2 hours
Telegram bot token is validwarningTelegram accepts the token

Metrics: paper equity (SOL), closed paper trades, win rate, wallets tracked, smart wallets, and positions on the liquidation map. These are paper figures, not earnings. The Live desk page shows the dashboard inside the console.

07Audit log, history and export

  • Audit log. Every sign-in, sign-out, password change, settings change (secrets shown only as set/cleared), secret test, team change and alert is written with who, when and what. Every member can read and filter it; an owner can download it as CSV.
  • History. Every save is a version. An owner can compare two versions and roll back; secrets and environment-locked values are not rolled back.
  • Export and import. Owners can export the settings to a file and import them on another install (with a preview first).

08Running without the console

DESK_ADMIN=0 npm start starts the desk and dashboard without the console. Then config.json is the only source of settings, and the dashboard has no sign-in: protect it with DASH_TOKEN and keep it on 127.0.0.1. DASH=0 turns off both dashboard and console.