Prediction Stack docs
v1.0.0
Live app Get help
● Set up · .env and public.json

Configuration
two files, one rule.

The admin's start-up settings live in admin/.env. Everything the public pages show comes from config/public.json, which the admin writes. This page lists both.

01How a setting reaches the public site

  1. Save in the adminThe Kit records the change in its audit log and history.
  2. The admin rewrites config/public.jsonOnly when the content changed.
  3. Commit and deployCommit config/public.json and push. If your host deploys on push, the site updates.

Each page fetches config/public.json with cache: "no-store". If the file is missing or has another schema, the page keeps its built-in defaults. Do not edit the file by hand: the Status check publicConfig flags a file that differs from the saved settings.

02Admin environment variables

Put them in admin/.env as KEY=value lines, or export them in the shell (a shell value wins). Source: admin/src/server.ts (key, data folder, port, host) and admin/src/app.ts (file paths).

VariableDefaultPurpose
ADMIN_SECRET_KEY RequirednoneEncrypts the secrets stored in the admin. Written by npm run init; openssl rand -hex 32 also works. Without it the admin refuses to start.
PORT8811Admin port.
HOST127.0.0.1Listen address. Change only behind your own TLS reverse proxy.
ADMIN_DATA_DIRdataFolder (inside admin/) for admin.sqlite.
PUBLIC_CONFIG_PATHconfig/public.jsonWhere the public config is written, relative to the repository root.
PAIRS_DB_PATHscanner/data/pairs.jsonlThe pair database the review page writes decisions into.

03Refresh job variables

The data jobs run on the GitHub runner (or on your computer, see Running the jobs locally). They read three optional variables:

VariableWhere you set itPurpose
POLYGON_RPC_URLGitHub → Settings → Secrets and variables → Actions → repository secret. The workflow passes it to the tape step.Your own HTTPS Polygon RPC (chain 137), tried before the public RPCs. Several URLs may be comma-separated. Never written to tape.json, the page or an error message; they say own RPC (POLYGON_RPC_URL) instead. Source: terminal/src/onchain.js.
POLYGON_RPC_ONLYShell or workflow env: (not set by the shipped workflow)1 drops the public fallback RPCs and uses only yours.
POLYMARKET_CLOB_HOSTShell or workflow env: (not set by the shipped workflow)Polymarket order-book read host for the Scanner job. Default https://clob.polymarket.com (scanner/src/venues/polymarket.js).

04config/public.json reference

Schema mikodes-prediction-public/1. Every field is always present. An empty string means "not set" and the page hides that element. As shipped, the builder fee is off, the code is empty, the rates are 0 and every brand and legal field is empty.

FieldDefaultMeaning
schemamikodes-prediction-public/1Contract version. A page that sees another value ignores the file.
brand.name, brand.tagline""Product name and short line. Empty keeps the page's built-in name.
brand.accent""#rgb or #rrggbb. Empty keeps the theme accent.
brand.logo""An http(s) image URL or a data:image/…;base64 URL (png, jpeg, gif, webp).
brand.supportEmail, brand.website""Footer contact and link.
legal.termsUrl, legal.privacyUrl""Footer links "Terms" and "Privacy".
legal.disclaimer""Footer text, inserted as text (no HTML).
access.maintenancefalseReplaces page content with the maintenance message.
access.maintenanceMessage""Empty with maintenance on shows "Temporarily unavailable."
access.announcement""One-line banner at the top.
venues.kalshi, venues.polymarkettruefalse hides that venue's rows on the pages. The data files still contain them.
venues.clobHosthttps://clob.polymarket.comPolymarket order API host, used by the admin's feeLive check.
builder.enabledfalsetrue only when you turned the fee on and the code is a valid, non-zero bytes32.
builder.code""0x + 64 hex characters when enabled.
builder.signatureType0Always 0: the user's own wallet would sign.
builder.plannedTakerBps, builder.plannedMakerBps0Your planned rates (0–100 and 0–50). A plan, never a fee shown to a user.
bot.username, bot.channelUrl""Footer link to Telegram (https://t.me/…).

The file never contains secrets (RPC URL, bot token, webhook secret), member or audit data. The admin's test suite checks this.

05Which page uses which field

  • Scanner: brand, legal, access, venue toggles, bot links.
  • Terminal: brand, legal, access, venues.polymarket, bot links, and builder.code when enabled: fills carrying your code are highlighted.
  • Landing page: brand, legal, access, venues, the builder code badge ("builder code: not set" until you set one), bot link.

venues.clobHost, builder.signatureType and the planned rates are not read by any public page in this release. They are there for a future order flow, which is not built in this release.