THESIS docs
v1.0.0
Live demo Get help
● Set up · Keys and settings

Configuration
server settings and admin settings.

Two places: environment variables for the server (secrets, storage, port), and the admin for everything the desk and the landing page show. Admin changes need no rebuild.

01Two places, one rule

WhereWhat goes thereChange needs
Environment (.env on your server, or Vercel → Settings → Environment Variables)Admin secret, database, Anthropic key, storage, portA server restart (Vercel: a redeploy)
Admin → any section → saveBrand, landing copy, markets, AI limits, trading modes, risk caps, lab, templates, costs, builder fee, Pro plan, referral linkNothing else. The desk and landing read it from GET /api/config on their next load.
Nothing secret reaches the browser

The pages have no build-time keys. The browser receives only public settings from /api/config. The Anthropic key stays on the server; the Telegram bot token each user enters stays in that user's browser.

02Server settings (environment)

The first nine are in .env.example. The last four are optional extras you normally leave unset.

VariablePurposeWhere to get it
ADMIN_SECRET_KEY Required32 bytes, hex or base64. Encrypts the admin's stored secrets and signs Pro sessions. Unset: /admin answers 503 and the desk runs on default settings.openssl rand -hex 32. Back it up.
DATABASE_URLPostgres for the admin. Required on Vercel (use the pooled connection string with sslmode=require). Unset on a Node server: SQLite in THESIS_DATA_DIR/admin.sqlite.Neon or any Postgres 14+
ANTHROPIC_API_KEY OptionalYour key for chart reading. When set, it locks the key field in the admin.console.anthropic.com
THESIS_STORAGEAggregate counters: file or blob. Default: blob when BLOB_READ_WRITE_TOKEN is set, else file.
THESIS_DATA_DIRData folder for SQLite and file counters. Default ./data; on Vercel /tmp/thesis-data, which does not persist.
BLOB_READ_WRITE_TOKENSet by Vercel when you connect a Blob store.Vercel → Storage
THESIS_BLOB_ACCESSprivate (default) or public; must match the Blob store.
THESIS_PORTNode server port. Default 8787.
THESIS_TRUST_PROXY1 only behind a reverse proxy you control. Rate limits and the Secure cookie flag then use X-Forwarded-For / -Proto.
THESIS_HOSTAddress the Node server binds to. Default: all interfaces. Set 127.0.0.1 behind a local proxy.
THESIS_DIST_DIRFolder with the built pages. Default dist. Rarely needed.
THESIS_APIDevelopment only: where pnpm dev sends /api and /admin. Default http://localhost:8787.
ANTHROPIC_AUTH_TOKENAdvanced: an Anthropic bearer token, used only when no API key is set (neither in the admin nor in ANTHROPIC_API_KEY). Most operators never need it.Anthropic
Where the Anthropic key comes from

With the admin on (ADMIN_SECRET_KEY set), the server uses the key saved under Integrations; ANTHROPIC_API_KEY, when set, fills and locks that field. With the admin off, it reads ANTHROPIC_API_KEY directly. The server re-reads the key about once a minute.

03Admin settings and their defaults

Every setting has a default and a hard range in src/shared/settings.ts; a typo in the admin cannot create an unsafe desk. Money settings start off or empty.

SettingDefaultRange
Paper / testnet / mainnet tradingon / on / off
Blocked countries (no testnet or mainnet runs)USISO country codes
Max notional per order5,000 USD10 – 10,000,000
Agent key validity7 days1 – 180
Live order slippage cap30 bps1 – 500
Max leverage · risk per trade · daily loss · trades per day10x · 2 % · 10 % · 201–20 · 0.1–5 % · 0.5–20 % · 1–50
Minimum lab grade for live runsCA – F
Walk-forward folds · Monte Carlo runs4 · 1,0002–10 · 100–5,000
Backtest taker fee · slippage4.5 bps · 2 bps0–50 · 0–200
AI chart reading · model · efforton · claude-opus-5 · highfour models, four effort levels
AI requests per visitor per hour · daily cap20 · 5001–500 · 1–100,000
Builder feeoff, address empty, 00 – 100 tenths of a bp (0.1 %)
Pro plan · referral linkoff · off

04How a change reaches users

  1. Save in the adminEach section has its own save. The admin checks ranges and addresses and writes an audit entry.
  2. The server picks it upOn Vercel, another instance sees the change within about 2 seconds.
  3. The page reloads itThe desk and landing read /api/config when they load. A user who has the desk open sees the change after a reload.

If a saved value is accepted by the admin but refused by the desk's own schema, the desk uses the default for that field and Status → Every saved value is valid for the desk fails, so you notice.