Configuration
server settings and admin settings.
Two places: environment variables for the server (secrets, storage, port), and the admin for everything the desk and the landing page show. Admin changes need no rebuild.
01Two places, one rule
| Where | What goes there | Change needs |
|---|---|---|
Environment (.env on your server, or Vercel → Settings → Environment Variables) | Admin secret, database, Anthropic key, storage, port | A server restart (Vercel: a redeploy) |
| Admin → any section → save | Brand, landing copy, markets, AI limits, trading modes, risk caps, lab, templates, costs, builder fee, Pro plan, referral link | Nothing else. The desk and landing read it from GET /api/config on their next load. |
The pages have no build-time keys. The browser receives only public settings from /api/config. The Anthropic key stays on the server; the Telegram bot token each user enters stays in that user's browser.
02Server settings (environment)
The first nine are in .env.example. The last four are optional extras you normally leave unset.
| Variable | Purpose | Where to get it |
|---|---|---|
ADMIN_SECRET_KEY Required | 32 bytes, hex or base64. Encrypts the admin's stored secrets and signs Pro sessions. Unset: /admin answers 503 and the desk runs on default settings. | openssl rand -hex 32. Back it up. |
DATABASE_URL | Postgres for the admin. Required on Vercel (use the pooled connection string with sslmode=require). Unset on a Node server: SQLite in THESIS_DATA_DIR/admin.sqlite. | Neon or any Postgres 14+ |
ANTHROPIC_API_KEY Optional | Your key for chart reading. When set, it locks the key field in the admin. | console.anthropic.com |
THESIS_STORAGE | Aggregate counters: file or blob. Default: blob when BLOB_READ_WRITE_TOKEN is set, else file. | |
THESIS_DATA_DIR | Data folder for SQLite and file counters. Default ./data; on Vercel /tmp/thesis-data, which does not persist. | |
BLOB_READ_WRITE_TOKEN | Set by Vercel when you connect a Blob store. | Vercel → Storage |
THESIS_BLOB_ACCESS | private (default) or public; must match the Blob store. | |
THESIS_PORT | Node server port. Default 8787. | |
THESIS_TRUST_PROXY | 1 only behind a reverse proxy you control. Rate limits and the Secure cookie flag then use X-Forwarded-For / -Proto. | |
THESIS_HOST | Address the Node server binds to. Default: all interfaces. Set 127.0.0.1 behind a local proxy. | |
THESIS_DIST_DIR | Folder with the built pages. Default dist. Rarely needed. | |
THESIS_API | Development only: where pnpm dev sends /api and /admin. Default http://localhost:8787. | |
ANTHROPIC_AUTH_TOKEN | Advanced: an Anthropic bearer token, used only when no API key is set (neither in the admin nor in ANTHROPIC_API_KEY). Most operators never need it. | Anthropic |
With the admin on (ADMIN_SECRET_KEY set), the server uses the key saved under Integrations; ANTHROPIC_API_KEY, when set, fills and locks that field. With the admin off, it reads ANTHROPIC_API_KEY directly. The server re-reads the key about once a minute.
03Admin settings and their defaults
Every setting has a default and a hard range in src/shared/settings.ts; a typo in the admin cannot create an unsafe desk. Money settings start off or empty.
| Setting | Default | Range |
|---|---|---|
| Paper / testnet / mainnet trading | on / on / off | |
| Blocked countries (no testnet or mainnet runs) | US | ISO country codes |
| Max notional per order | 5,000 USD | 10 – 10,000,000 |
| Agent key validity | 7 days | 1 – 180 |
| Live order slippage cap | 30 bps | 1 – 500 |
| Max leverage · risk per trade · daily loss · trades per day | 10x · 2 % · 10 % · 20 | 1–20 · 0.1–5 % · 0.5–20 % · 1–50 |
| Minimum lab grade for live runs | C | A – F |
| Walk-forward folds · Monte Carlo runs | 4 · 1,000 | 2–10 · 100–5,000 |
| Backtest taker fee · slippage | 4.5 bps · 2 bps | 0–50 · 0–200 |
| AI chart reading · model · effort | on · claude-opus-5 · high | four models, four effort levels |
| AI requests per visitor per hour · daily cap | 20 · 500 | 1–500 · 1–100,000 |
| Builder fee | off, address empty, 0 | 0 – 100 tenths of a bp (0.1 %) |
| Pro plan · referral link | off · off |
04How a change reaches users
- Save in the adminEach section has its own save. The admin checks ranges and addresses and writes an audit entry.
- The server picks it upOn Vercel, another instance sees the change within about 2 seconds.
- The page reloads itThe desk and landing read
/api/configwhen they load. A user who has the desk open sees the change after a reload.
If a saved value is accepted by the admin but refused by the desk's own schema, the desk uses the default for that field and Status → Every saved value is valid for the desk fails, so you notice.