DESKFEED
Agent API
Desk · Compile · Journal · Admin
Demand-state feed for bots. Same fields the desk shows. Binance tape quality — not venue mids, not executable prices. Flip and Lab live in their own apps.
curl -s '/api/desk?window=8&sort=score' curl -s '/api/regime'
GET /api/desk
Query: window=4|8|12|24, sort=score|cap. One list, capped at 12. Score is default (cap breaks ties). sort=cap ranks by CoinGecko market cap, then score.
Returns the last snapshot. Compile clock or Admin Run now scores tape and POSTs the compile package to compile webhooks. Desk Refresh updates cache only. GET never pulls live klines unless the compile slot is due.
Stable ids: ENA, state, score, rsVsBtc, reportedNotReal.
GET /api/regime
Locked regime.v1 card. Implemented by src/modules/compile/regime.ts from the Regime prompt. Scored on the desk clock and Admin Run. Not a webhook. No tape dump.
GET /api/core
Up to 6 names. Admin POST { id, core } adds or removes one. A state change on a core name is written to the journal on the clock and Admin Run. Does not send webhooks.
POST /api/desk
Force a tape rescore and replace the snapshot. Same as the desk Refresh button. Does not send webhooks.
GET /api/journal
Cron ticks and webhook posts. Query limit (max 200). Host only — no secrets, no payload bodies. API callers: GET /api/journal/access (IPs + recent paths). Journal page has Events and API IPs tabs.
Webhooks
Admin registers compile endpoints. Compile cron GET|POST /api/cron/compile (also /api/cron/desk) scores tape, builds a 3-rung ladder from Admin settings (default 3×$50, −2% to −0.5%), then POSTs the compile package if not idle and the fingerprint changed. Idle packages are not sent. Desk Refresh never fires.
GET /api/compile → same JSON the webhook POSTs Header x-deskfeed-event: compile
Header x-deskfeed-event. Grok Bot routines: paste crsr_… — sender adds Authorization: Bearer and X-Automation-Key (HTTP 200). Grok Automations: paste whsec_…. Sender then uses Standard Webhooks (webhook-id, webhook-timestamp, webhook-signature: v1,…). Legacy HMAC stays x-deskfeed-signature: sha256=<hex> when the secret has neither prefix. Grok Automations return 202. Idle packages are not sent to Grok Automations.
GET /api/compile
Ranked long-only package from the last desk snapshot. At most 6 candidates by score. Short Flip-card fields: event: "compile.now", id, live, buyFrom, buyTo, invalidation. Query window, format=card. Clock/Admin: cache tape, POST if fingerprint changed. Idle is not sent. Not an order.
curl -s '/api/compile?format=card'
Holdings + spend
Writer API only — Admin has no holdings/spend UI. POST /api/compile/holdings with { holdings:[{id,qty,avg,quote_usd}] } or text CSV. IDs map through the desk universe. No Revolut X keys. Snap older than 24h is still used (reliability haircut). Day/run used: GET|POST /api/compile/spend or ledger/day_used.json { day, used_usd, run_used_usd } (Madrid calendar). SOD resets both. Remaining day cap under $30 → no new buys. Writer fills later.
GET /api/health
{ ok, asOf, live, names, cached, nextRefreshAt, compileTick }GitHub Actions GET this every 15 min. That ping is the compile clock on a cold host — it ticks compile if due, then returns cache.