Prediction Stack docs
v1.0.0
Live app Get help
● Set up · Every section

Operator admin
on your own computer.

The admin (version 1.0.0) is the MIKODES Admin Kit 0.3.0 wired to this product. It runs on 127.0.0.1:8811, keeps its own SQLite database, and writes one public file: config/public.json. It is never deployed with the site.

01Roles and sign-in

RoleCan do
ownerEverything, including team, secrets, revealing a masked builder code (with a written reason of at least 8 characters, logged).
managerChange settings and decide pairs in the review queue.
viewerRead only.

The first owner is created with the one-time setup code (how). Passwords need at least 12 characters. Security & alerts adds two-factor sign-in with recovery codes and session management.

Admin overview on a fresh install: no revenue source connected, needs-you list and configuration health
Overview on a fresh 1.0.0 install (scratch database, default settings, placeholder owner email), 2026-09-29.

02Setup: Get started, Brand, Legal

  • Get started: a checklist of what is still empty (product name, accent colour, support email).
  • Brand: product name, tagline, accent colour, logo, support email, website. See Rebranding.
  • Legal: terms URL, privacy URL, disclaimer. The Stack ships none of these texts; you write your own. An empty field shows nothing, never a placeholder link.

03Money: Builder fee (Polymarket)

A planner, not a control panel. Fields: the toggle "Use my builder code (attribution now; order flow not in this release)", builder code, planned taker fee (cap 100 bps), planned maker fee (cap 50 bps) and the UTC date you scheduled a change on Polymarket. The caps are enforced in the form and on the server. Everything ships off and empty. Full guide: Builder code.

What the toggle does in 1.0.0

Turned on with a valid code, it writes your code into config/public.json so the Terminal highlights fills that carry it and Status counts them. It attaches the code to no order, because the Terminal places none; the admin's help texts say the same ("This release places no orders"). The Terminal only displays fees read from the chain.

Builder fee (Polymarket) section as shipped: off, no code, 0 bps
Builder fee as shipped in 1.0.0: off, no code, 0 bps.

04Product: Access, Venues, Alert bot

SectionSettingsEffect
AccessMaintenance mode, maintenance message, announcement banneraccess.* in the public file.
VenuesShow Kalshi, show Polymarket, Polymarket CLOB hostHides a venue's rows on the pages. The refresh job still fetches both; to stop fetching one, change the job.
Alert botBot username, channel link, send rate, stale-alert limitUsername and channel become footer links. The rate settings are for a bot runtime that does not ship in this release.

Blocked countries is left out on purpose: a static page does not know the visitor's country, so the field would block nothing. If you need to restrict access by location, do it at your host.

05Scanner run & pair review

The Scanner never treats two contracts as the same because a machine said so. A pair is priced as a cross-venue spread only after a person confirms it.

  1. Open Scanner run & pair reviewIt shows the last run from board.json and the queue of machine-scored pairs, strongest first.
  2. DecideRead both contracts' titles, outcomes and expiry. Choose Same contract or Not the same. Needs the manager or owner role.
  3. CommitThe decision is written into scanner/data/pairs.jsonl (as admin (owner) or admin (manager); the audit log keeps who). Pull first, then commit and push: the refresh job also commits this file.

If a matched market's text, sources or expiry change later, or the matcher version changes, the pair is flagged for re-review.

Scanner run and pair review inside the admin
Scanner run & pair review reading the committed board (runner run of 2026-09-25): both venues reachable, matcher 0.3.0, 768 pairs in the database.

06System: Integrations, Notifications, Security, Export

  • Integrations: Polygon RPC URL and Telegram bot token. Write-only (stored encrypted with ADMIN_SECRET_KEY, never shown again), owner only, each with a Test button. Used by the Status checks only, never written to the public file. The refresh job does not read this field: give the job its RPC as the GitHub secret POLYGON_RPC_URL (how).
  • Notifications: webhook URL and signing secret for the Kit's alerts. There is no email delivery.
  • Security & alerts: two-factor, sessions.
  • Export / Import: move settings between installs.

07Status checks

CheckSeverityWhat it reads
publicConfigblockerconfig/public.json equals what the saved settings produce.
builderCodeblockerA valid, non-zero bytes32 whenever the builder fee is on.
feeScheduleinfoFrom your scheduled date: when it takes effect (3 days) and when the next change is allowed (7 days).
feeLivewarningThe live rate from GET {clobHost}/fees/builder-fees/{code} compared with your plan. Calls Polymarket from your machine.
attributioninfoFills in the committed tape.json that carry your builder code.
polygonRpcwarningYour RPC URL answers eth_chainId with 137.
telegramBotwarninggetMe works and the bot's menu button is not a Mini App.
scannerBoard, terminalTapeinfoThe data files exist and when they were produced.
Status page on a fresh install with two optional warnings
Status on a fresh 1.0.0 install: the two warnings are the optional RPC URL and bot token.

08Monitor: Revenue, Audit log, History, Team

  • Revenue shows "No revenue source is connected. Nothing is estimated." This is deliberate: builder payouts cannot be read from the chain (why).
  • Audit log: who changed what, with before and after. Wallet-like values are masked.
  • History: roll a setting back.
  • Team: invite members with a role.

09Under the hood

  • admin/src/app.ts (createAdmin()) mounts the Kit and this product's own routes under /admin-product/: the Scanner run page, the pair database and pair decisions. Every product route needs a signed-in session; deciding a pair needs the manager or owner role and the Kit's CSRF header, and each decision is written to the audit log.
  • admin/src/server.ts only reads .env, opens the SQLite store and listens on loopback.
  • Storage in Admin Kit 0.3.0 is asynchronous. If you add your own routes, await the Kit's authenticate() and audit() calls, as app.ts does.
  • Do not edit admin/vendor/mikodes-admin/; it is a vendored copy (see its KIT.md).

10Running the admin on another machine

The admin is meant for your own computer. Never deploy admin/ with the public site; .vercelignore already excludes it. If you must reach it remotely, put it behind your own TLS reverse proxy, set HOST, and turn on required two-factor in Security. Not tested here