SUBJECT / field manual
Observe first.
Never confuse a draft with a fill.
A public window onto a subject reading real Solana markets. The interface shows what the service actually reports. Missing prices are unavailable, paper balances are virtual, and chain confirmation is a separate event from submission.
Current workspace safety: the startup workflow has real signing disabled. Neither adding credentials nor signing in activates live trading. No funded swap has been verified.
01 / operating modes
| Mode | Book | Execution |
|---|---|---|
| observe | Optional watched public wallet | Hypotheses only. No signer. |
| paper | Separate virtual ledger | Explicitly simulated fills. |
| live | Funded dedicated wallet | Requires separate startup opt-in and every risk gate. |
Observe uses the disclosed rules baseline. Paper uses the same baseline unless a real OpenRouter model is configured. Rule-based notes are not presented as AI reasoning. Paper starts with 3 virtual SOL by default and includes configured adverse slippage plus a virtual transaction fee. These are observed-price simulations, not executable quotes or predictions of live performance.
Real market observations run automatically. No configured wallet means no portfolio valuation; it does not mean a wallet with zero assets. A public WATCH_ADDRESS enables read-only wallet observation.
02 / private controls
Open the operator console and sign in through Clerk. Workspace authentication settings live in the Auth pane. Your account must also be explicitly listed in OPERATOR_USER_IDS. An access-denied screen shows your account ID; add it to workspace configuration and restart. The first signup never becomes an operator automatically.
Allowlisted controls include observe/paper switching, one-session run, pause/resume, buy suspension, validated risk limits, reconciliation and emergency stop. Mutations are authenticated, same-origin, CSRF-protected and rate-limited. Public visitors have no controls over the subject.
Emergency stop persists. “Resume” cannot clear it. Type CLEAR STOP to clear the latch explicitly, then resume. Presentation pause is unrelated and cannot stop the worker.
There is no web control to enable live trading. Do not remove the safe startup flag or configure live activation without an explicit request to execute autonomous real trades.
03 / limits the subject cannot change
| Limit | Default |
|---|---|
| Position | 0.25 SOL |
| Daily loss | 0.5 SOL |
| Reserve | 0.05 SOL |
| Total exposure | 0.75 SOL |
| Daily turnover | 2 SOL |
| Fee and rent allowance | 0.005 SOL |
| Slippage | 150 basis points / 1.5% |
| Price-impact boundary | 3% |
At most one execution attempt per session. Sizing includes fees, marked exposure and remaining allowance. The minimum trade is never rounded above a position cap. Wallet and quote raw units use integers.
The loss boundary uses UTC days and adjusts observed external deposits and withdrawals. Once crossed, new buys remain stopped even if prices recover. Exits remain possible. Unknown valuations and unvalued transfers cannot authorize execution.
Live guards additionally validate quote identity, expiry, fees, mint/freeze authorities and restrictive Token-2022 extensions. Before signing, they check payer/signers/instructions and simulate balances, reserve, minimum output, token ownership and every owned token account. Inputs and operator safety switches are rechecked immediately before signing and submission. These protections are not a formal security audit.
04 / source and freshness
Pump.fun supplies token discovery and new launches; DexScreener supplies indexed prices and an independent discovery fallback. Token detail shows the source, timestamp, quote unit and external verification links. Liquidity is USD. SOL-denominated valuations use independently observed SOL/USD; native quote prices are never blindly assumed to be SOL.
Held assets remain part of valuation outside discovery thresholds. Dollar balances require verified quotes. The public view uses neutral placeholders for pending values and retains observation timestamps; operational diagnostics belong in the private operator console and logs. The service never invents tokens, prices, executions or reasoning.
Provider calls have bounded timeouts/retries and circuit protection. /healthz is service liveness. /readyz checks real-market freshness and returns 503 when stale. A connected browser stream is not proof of fresh market data.
05 / durable recovery
The existing JSON ledger is retained. Snapshots are atomically replaced and fsynced. Separate order, session and operator-audit journals are append-only and fsynced. A worker lock prevents two local schedulers from sharing the same ledger.
The service stores an intent, then the locally derived transaction signature before sending. An uncertain network result is unresolved, not a guessed failure. New live submission remains blocked until the chain status is reconciled. Actual fills and fees come from confirmed metadata; recovery cannot apply the same fill twice.
Repeated finalized absence checks are required before declaring an expired order. Never delete the data folder to get rid of a pending transaction. Corrupt storage refuses startup instead of silently resetting balances. Back up the complete data directory while stopped.
Only one worker with durable disk is suitable for this ledger. Ephemeral or replicated deployment storage has not been verified and is unsuitable for unattended funded execution.
06 / viewer controls
- Pause, speed and skip alter the presentation only.
- Replay archived notes; return to live cancels replay and resynchronizes the screen.
- Follow scrolling can be turned off while you inspect older notes.
- Reduced-motion and hidden-tab behavior avoid unnecessary animation.
- Token rows open source/risk details. Escape closes the dialog.
- Inspect charts with pointer or arrow keys, or use the observation table.
- Search and filter the durable archive by mode and outcome. JSON and CSV downloads retain execution labels.
The SSE feed uses event IDs, heartbeats, reconnect catch-up and a complete authoritative snapshot. Paper fills never receive fake transaction links. Pending live submission is not counted as a confirmed fill.
07 / verification and remaining setup
npm test npm run check node scripts/browser-smoke.js
Offline tests cover configuration, model validation, sizing, daily loss, integer balances, mode isolation, restart recovery, duplicate workers, operator access/CSRF, exports and SSE. Test fixtures never become public fake market data.
Authenticated browser screens, funded execution, OpenRouter decisions and Jupiter provider integration require separate configuration and verification. Live credentials belong in workspace Secrets, never code or chat. Consult README for all settings and operating constraints.
Nothing here is financial advice. Autonomous trading can lose the entire funded balance. Solana, Jupiter, DexScreener, OpenRouter and Clerk are independent providers.