Operator console
every section of /admin.
The console is the MIKODES Admin Kit, served by the operator server at /admin. It changes what your site shows and charges without a rebuild. It can never touch a token, a trade or anyone's funds.
01How the console reaches the dApp
- You save a sectionThe server validates every field (caps, addresses, formats) and writes a new configuration version to
server/data/admin.sqlite, with an audit entry. - The server publishes the public part
GET /api/public-configreturns only public values (brand, legal, access, fee and fee wallet, referral shares, trading safety, sponsored and hidden tokens) with a version hash. Secrets, the Pro pay-to address and referral payout wallets are never in it. - Open tabs pick it upEvery browser re-reads the public config every 5 minutes; the server lets it be cached for 30 seconds. A reload applies it at once.
The console is declared in src/admin/manifest.ts; the kit itself is vendored in vendor/mikodes-admin/ (do not edit it there; fixes arrive with item updates). The navigation groups are Setup, Money, Product, Content, System and Monitor.
There is no user list, no wallet search and no per-user screen. The server has no user table and does not log wallets. Referral codes stay in each trader's browser.
02Sign-in, roles and two-factor
- The first owner is created with the one-time setup code from the server log (Installation). Passwords need at least 12 characters.
- Roles: Owner (everything, including secrets, team, reveal of addresses, exports and rollbacks), Manager (changes settings, not secrets or the team), Viewer (reads).
- Two-factor uses a 6-digit code from an authenticator app. Security & alerts can require it for owners and managers.
- Wallet addresses are masked in the console; revealing one is owner-only and audited.
03Overview
The home screen: maintenance and announcement shortcuts, today's realised revenue and events, open blockers, a configuration health score (blocker checks, settings that agree, setup finished, terms and privacy URLs, support email, two-factor for every owner, alert webhook), recent audit entries, and the metrics PARACHUTE registers:
- Swaps that paid your fee: distinct transactions in which the Universal Router paid your fee wallet.
- Where the fee applies: the measured share of pons volume in Uniswap v4 pools (a fee can apply) and on bonding curves (no fee possible). These come from
node scripts/admin/volume-split.mjs 7, which reads the chain and writesserver/volume-split.json. Until you run it, they show "—" and the Status check says "not measured yet".
04Get started
Three setup steps: Product name, Accent colour and Support email. Finish setup is refused while a blocker check fails.
05Brand
| Field | What it changes in the dApp |
|---|---|
| Product name | The name in the header, the browser tab title (<name> · exit desk for Robinhood Chain memes) and the footer line <name> · built on PARACHUTE by MIKODES. Empty = PARACHUTE. |
| Tagline | Published in the public config, but not shown by the dApp in 1.0.0. |
| Accent colour | Becomes the dApp's signal colour in both themes, but only where it passes the contrast checks (WCAG AA 4.5:1 on the backgrounds, a readable label on the Eject button, clearly apart from the "down" colour). A failing theme keeps the default orange. |
| Logo | The header logo (an https:// image or an uploaded PNG, JPEG, WebP or GIF). Empty = public/logo.png. |
| Support email | A "Support" link in the footer. |
| Website | A "Website" link in the footer. |
06Legal
Terms of service URL and Privacy policy URL become footer links. Disclaimer replaces the default footer text ("Non-custodial: your keys stay in your wallet and you sign every transaction yourself. Nothing here is investment advice. Memecoins are highly risky; most lose value."). The product never writes your terms for you.
07Swap fee
| Field | Default | Rule |
|---|---|---|
| Charge a swap fee | Off | Nothing is charged while off. |
| Fee | 0 bps | Basis points of the ETH or USDG leg of Uniswap v4 swaps. Hard cap 100 bps (1%): 101 is refused. |
| Fee wallet (Robinhood Chain, EVM) | empty | Receives the fee as WETH or USDG. A valid, non-zero address you control. It is shown to every trader in the review, as it is on-chain anyway. |
The fee only takes effect when all three are valid. How it is charged and where it cannot be: Earnings.
08Referrals
| Field | Default | Rule |
|---|---|---|
| Referral programme | Off | Needs the swap fee on; otherwise there is nothing to share. |
| Referrer share of your fee | 0 | In bps of the fee (3000 = 30% of your fee). Hard cap 50%. Rounded down to whole bps of the trade. |
| Referred-user discount | 0 | How much lower the fee is for a referred trader, in bps of the fee (1000 = 10% off). Hard cap 50%. |
| Disclosure shown with referral links | empty | Stored and published, but not shown by the dApp in 1.0.0. |
One tier only. Share plus discount may not exceed the whole fee.
09Referral codes
Eight slots, each a Code and a Payout wallet. Codes are 3 to 24 characters of a–z, 0–9 and -, each used once. The link you give a partner is https://<your-site>/?ref=<code>. The trader's browser keeps the code and asks the server for that one code's payout wallet (GET /api/referral/<code>); the full list is never published.
10Plans (Pro)
Fields: Paid plans (off), Monthly price, Currency (USDG), Pay-to address, Free trial (days).
The dApp has no Pro paywall or Pro-only feature. This section only lets the revenue view record USDG payments that reach your pay-to address, for a Pro offering you sell and deliver yourself. Leave it off unless you have such an offering.
11Access
| Field | What it does |
|---|---|
| Maintenance mode | Shows a maintenance banner and pauses trading on your site (like read-only mode). Prices and Trust stay visible; funds stay in traders' wallets. |
| Maintenance message | Your text in the banner. Empty = a default text. |
| Announcement banner | A one-line banner at the top of every page while maintenance is off. |
| Blocked countries | Added to the issuer's restricted list for the stock self-declaration. It does not geo-block the site. |
12Trading safety
| Field | Default | What it does |
|---|---|---|
| Maximum price impact | 1500 bps (15%) | The review refuses to sign a trade above this. Allowed range 50 to 5000 bps (0.5% to 50%). |
| Read-only mode (kill switch) | Off | Stops your site from building or signing any trade. Prices, Trust and portfolios stay visible. Traders keep their funds and can use any other interface. |
| Stock-token module | Off | Lets traders land exits in tokenized stocks. Also needs VITE_STOCKS_ENABLED=true in the build and each trader's self-declaration. Read Stock module before you turn it on. |
13Sponsored slots
Show sponsored slots (off) and Sponsored token addresses (one per line; only the first 3 are shown). Every slot carries the fixed label "Sponsored — not a recommendation", which you cannot change. A listed token is not shown when the chain shows a hard flag (an unknown v4 hook, a rescued graduation, or a lookalike of a stock token or a top meme), or when you hid it under Moderation.
The site only displays the slot. Any price for a slot is agreed between you and the project, outside PARACHUTE.
14Moderation
Hidden tokens: one per line, 0xTOKEN | public reason. A line without a reason is refused by the status check and ignored. A hidden token disappears from your site's lists; its page stays reachable by address and says why. The token keeps trading everywhere else and nobody's funds are touched. Up to 500 hidden tokens are published.
15Integrations
Robinhood Chain RPC URL (server): used by the operator server to read fee revenue and run status checks. Empty = the public RPC, which is rate-limited. It is never shown to traders and does not change the dApp's RPC (that is VITE_RPC_URL). PARACHUTE_RPC_URL in the server environment locks this field.
16Notifications and alerts
- Webhook URL and Webhook signing secret (owner-only, write-only): alerts are sent as JSON, signed with HMAC-SHA256 of
timestamp.bodyin thex-mikodes-signatureheader. - Security & alerts sets when to alert: when a blocker check starts failing, and when net revenue is zero for a number of days. Send test alert checks your webhook.
- Send alerts to (email) is stored, but the console sends no email in this version: use the webhook.
17Security & alerts
Your two-factor setup, the sessions where you are signed in (sign out one or all), the team rule that requires two-factor for owners and managers, and the alert rules above.
18Export / Import
Owner-only. Download JSON exports every setting except secrets; it contains wallet addresses in clear, so keep it private. Import shows exactly what would change before anything is applied. Use it to copy a configuration between installs.
19Revenue
Realised revenue only: fee payments read from WETH, USDG and USDC Transfer logs into your fee wallet, and USDG payments to the Pro pay-to address, each with its transaction. Nothing is estimated. The server reads from the pons v2 factory deploy block onward and keeps up every 60 seconds; the first read can take a while on the public RPC ("Fee revenue is still being read from the chain. Try again in a minute."). A CSV export is available.
20Status
| Check | Severity | Passes when |
|---|---|---|
| Robinhood Chain RPC answers (chain 4663, fresh blocks) | blocker | The server RPC returns chain 4663 with a recent block. |
| Fee, referral and moderation settings are valid | blocker | No contradiction (for example fee on with 0 bps or no wallet, referrals on without codes, a hidden line without a reason). With the fee off it says "fee off (safe default)". |
| Fee revenue is read up to the latest block | warning | The ledger is less than 3000 blocks behind, or no fee wallet and no Pro address are set. |
| Curve-vs-v4 volume split measured in the last 14 days | info | server/volume-split.json exists and is under 14 days old. Re-run node scripts/admin/volume-split.mjs 7. |
21Audit log and History
- Audit log: every sign-in and every change, with who made it and when. CSV export is owner-only.
- History: every saved configuration is a version. Rolling back (owner-only) creates a new version with the old values; nothing is lost.
22Team
Add members by email with a role (Viewer, Manager or Owner). Adding, changing and removing members is owner-only. Every change is in the audit log.
23Check it end to end
The package includes the script used before release. It creates an owner on a fresh local server, proves the 100 bps cap, a fee change reaching the dApp and the audit log, moderation, a sponsored slot and the read-only switch, then resets:
# 1. a fresh local server with its own data folder, log to a file
ADMIN_SECRET_KEY=$(openssl rand -hex 32) PARACHUTE_DATA_DIR=/tmp/pc-admin PORT=18787 npm run server > /tmp/pc.log &
# 2. the check (reads the setup code from the log)
PLAYWRIGHT=<path-to>/node_modules/playwright SETUP_LOG=/tmp/pc.log node scripts/qa/admin-e2e.mjs http://127.0.0.1:18787
It needs the Playwright package with its Chromium browser, which is not a dependency of the item (PLAYWRIGHT points at it). It writes screenshots to qa/v2/admin. Never point it at your production server. The author ran it before release (README.md, "Verified live"); it was not re-run for this documentation (unverified here).