{"id":51862903,"url":"https://github.com/OpenByteInc/QuantDinger","last_synced_at":"2026-08-01T18:00:28.584Z","repository":{"id":330890754,"uuid":"1124295269","full_name":"OpenByteInc/QuantDinger","owner":"OpenByteInc","description":"AI quantitative trading platform for crypto, stocks, and forex with backtesting, live trading, market data, and multi-agent research.vibe-trading ,trading-agents,ai-trader,ai-trading","archived":false,"fork":false,"pushed_at":"2026-07-19T12:03:17.000Z","size":64764,"stargazers_count":9759,"open_issues_count":36,"forks_count":2057,"subscribers_count":63,"default_branch":"main","last_synced_at":"2026-07-19T12:14:15.885Z","etag":null,"topics":["agent","ai","alpaca","backtesting","binance","coinbase","crypto","exchange","finance","fintech","forex","mcp-server","python","quant","quantitative-finance","saas","stocks","strategy","trade","trading-toolkit"],"latest_commit_sha":null,"homepage":"https://www.quantdinger.com","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/OpenByteInc.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null},"funding":{"custom":["https://t.me/worldinbroker"]}},"created_at":"2025-12-28T18:39:26.000Z","updated_at":"2026-07-19T12:08:52.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/OpenByteInc/QuantDinger","commit_stats":null,"previous_names":["brokermr810/quantdinger","openbyteinc/quantdinger"],"tags_count":35,"template":false,"template_full_name":null,"purl":"pkg:github/OpenByteInc/QuantDinger","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/OpenByteInc%2FQuantDinger","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/OpenByteInc%2FQuantDinger/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/OpenByteInc%2FQuantDinger/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/OpenByteInc%2FQuantDinger/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/OpenByteInc","download_url":"https://codeload.github.com/OpenByteInc/QuantDinger/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/OpenByteInc%2FQuantDinger/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36165355,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-07-20T02:08:10.276Z","status":"online","status_checked_at":"2026-08-01T02:00:05.789Z","response_time":100,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["agent","ai","alpaca","backtesting","binance","coinbase","crypto","exchange","finance","fintech","forex","mcp-server","python","quant","quantitative-finance","saas","stocks","strategy","trade","trading-toolkit"],"created_at":"2026-07-24T11:00:23.196Z","updated_at":"2026-08-01T18:00:28.577Z","avatar_url":"https://github.com/OpenByteInc.png","language":"Python","funding_links":["https://t.me/worldinbroker"],"categories":["Agent Integration \u0026 Deployment Tools","Backtesting","القائمة الكاملة Top 200"],"sub_categories":["AI Agent Operating System"],"readme":"\u003cdiv align=\"center\"\u003e\n  \u003ca href=\"https://github.com/OpenByteInc/QuantDinger\"\u003e\n    \u003cimg src=\"docs/screenshots/logo.jpg\" alt=\"QuantDinger logo\" width=\"180\" height=\"180\"\u003e\n  \u003c/a\u003e\n\n  \u003ch1\u003eQuantDinger\u003c/h1\u003e\n  \u003cp\u003e\u003cstrong\u003eOpen-source AI Trading OS\u003c/strong\u003e\u003c/p\u003e\n  \u003cp\u003eTurn trading ideas into Python strategies, backtests, paper trading, live execution, and monitoring — all in one self-hosted stack.\u003c/p\u003e\n  \u003cp\u003e\u003cstrong\u003eQuantDinger is a product of Open Byte Inc.\u003c/strong\u003e\u003c/p\u003e\n  \u003cp\u003e\u003cem\u003eAI research → Strategy code → Backtest → Paper/Live execution → Monitoring\u003c/em\u003e\u003c/p\u003e\n\n  \u003cp\u003e\n    \u003ca href=\"README.md\"\u003e\u003cstrong\u003eEnglish\u003c/strong\u003e\u003c/a\u003e\n    ·\n    \u003ca href=\"docs/README_CN.md\"\u003e\u003cstrong\u003e简体中文\u003c/strong\u003e\u003c/a\u003e\n    ·\n    \u003ca href=\"docs/api/README.md\"\u003e\u003cstrong\u003eAPI\u003c/strong\u003e\u003c/a\u003e\n    ·\n    \u003ca href=\"docs/agent/README.md\"\u003e\u003cstrong\u003eAI Agents \u0026 MCP\u003c/strong\u003e\u003c/a\u003e\n  \u003c/p\u003e\n\n  \u003cp\u003e\n    \u003ca href=\"https://ai.quantdinger.com\"\u003e\u003cstrong\u003eLive App\u003c/strong\u003e\u003c/a\u003e\n    ·\n    \u003ca href=\"https://www.quantdinger.com\"\u003e\u003cstrong\u003eWebsite\u003c/strong\u003e\u003c/a\u003e\n    ·\n    \u003ca href=\"https://www.youtube.com/watch?v=tNAZ9uMiUUw\"\u003e\u003cstrong\u003eVideo Demo\u003c/strong\u003e\u003c/a\u003e\n    ·\n    \u003ca href=\"mailto:support@quantdinger.com\"\u003e\u003cstrong\u003eOfficial Support Email\u003c/strong\u003e\u003c/a\u003e\n  \u003c/p\u003e\n\n  \u003cp\u003e\n    \u003ca href=\"https://t.me/quantdinger\"\u003e\u003cimg src=\"https://img.shields.io/badge/Telegram-Join-26A5E4?style=flat-square\u0026logo=telegram\u0026logoColor=white\" alt=\"Telegram\"\u003e\u003c/a\u003e\n    \u003ca href=\"https://discord.com/invite/tyx5B6TChr\"\u003e\u003cimg src=\"https://img.shields.io/badge/Discord-Server-5865F2?style=flat-square\u0026logo=discord\u0026logoColor=white\" alt=\"Discord\"\u003e\u003c/a\u003e\n    \u003ca href=\"https://youtube.com/@quantdinger\"\u003e\u003cimg src=\"https://img.shields.io/badge/YouTube-%40quantdinger-FF0000?style=flat-square\u0026logo=youtube\u0026logoColor=white\" alt=\"YouTube\"\u003e\u003c/a\u003e\n    \u003ca href=\"https://x.com/QuantDinger_EN\"\u003e\u003cimg src=\"docs/badges/x-quantdinger.svg\" alt=\"X @QuantDinger_EN\"\u003e\u003c/a\u003e\n  \u003c/p\u003e\n\n  \u003cp\u003e\n    \u003ca href=\"LICENSE\"\u003e\u003cimg src=\"https://img.shields.io/badge/License-Apache%202.0-blue.svg?style=flat-square\" alt=\"Apache 2.0\"\u003e\u003c/a\u003e\n    \u003cimg src=\"docs/badges/python-3.12.svg\" alt=\"Python 3.12\"\u003e\n    \u003cimg src=\"https://img.shields.io/badge/PostgreSQL-18-4169E1?style=flat-square\u0026logo=postgresql\u0026logoColor=white\" alt=\"PostgreSQL 18\"\u003e\n    \u003cimg src=\"https://img.shields.io/badge/Redis-8-DC382D?style=flat-square\u0026logo=redis\u0026logoColor=white\" alt=\"Redis 8\"\u003e\n    \u003cimg src=\"docs/badges/docker-compose.svg\" alt=\"Docker Compose\"\u003e\n    \u003ca href=\"https://github.com/OpenByteInc/QuantDinger/releases/latest\"\u003e\u003cimg src=\"docs/badges/latest-release.svg\" alt=\"Latest release\"\u003e\u003c/a\u003e\n  \u003c/p\u003e\n\n  \u003cp\u003e\u003csub\u003eSUPPORTED BY\u003c/sub\u003e\u003c/p\u003e\n  \u003cp\u003e\n    \u003ca href=\"https://www.atlascloud.ai/\" title=\"Atlas Cloud — AI inference sponsor\"\u003e\n      \u003cpicture\u003e\n        \u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.atlascloud.ai/logo-white.svg\"\u003e\n        \u003cimg src=\"https://www.atlascloud.ai/logo.svg\" alt=\"Atlas Cloud\" width=\"142\"\u003e\n      \u003c/picture\u003e\n    \u003c/a\u003e\n    \u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\n    \u003ca href=\"https://aws.amazon.com/\" title=\"Amazon Web Services — cloud infrastructure sponsor\"\u003e\n      \u003cpicture\u003e\n        \u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://a0.awsstatic.com/libra-css/images/logos/aws_smile-header-desktop-en-white_59x35.png\"\u003e\n        \u003cimg src=\"https://upload.wikimedia.org/wikipedia/commons/9/93/Amazon_Web_Services_Logo.svg\" alt=\"Amazon Web Services\" width=\"70\"\u003e\n      \u003c/picture\u003e\n    \u003c/a\u003e\n  \u003c/p\u003e\n\u003c/div\u003e\n\n\u003e QuantDinger can submit real orders when live trading is explicitly enabled.\n\u003e Start with paper trading, use restricted API keys, and review the risk and\n\u003e compliance requirements for your jurisdiction. This project does not provide\n\u003e investment advice.\n\n## What QuantDinger is\n\nQuantDinger is an **open-source AI Trading OS** for independent traders, Python\nstrategy authors, and small teams. Its local-first, self-hosted design keeps\nmarket data, strategy code, broker credentials, and deployment under the\noperator's control.\n\nThe project combines:\n\n- multi-provider AI market research and analysis;\n- Python indicators and Strategy API V2 development;\n- server-side backtesting and experiment workflows;\n- paper and live execution across crypto exchanges and traditional brokers;\n- web, mobile H5, human API, Agent Gateway, and MCP access;\n- PostgreSQL-backed state, durable workers, audit logs, and optional monitoring.\n\nIt is not a black-box signal service. Strategy code, risk settings, credentials,\nand deployment remain under the operator's control.\n\n## What changed in v5\n\nThe v5 backend is organized around explicit runtime and operational boundaries:\n\n- the HTTP API no longer owns long-running trading or scheduler loops;\n- trading, scheduling, Celery jobs, and migrations run as separate processes;\n- Celery handles finite, retryable work while long-lived strategy runtimes stay\n  in the trading worker;\n- cache Redis and durable job Redis use separate instances and eviction policies;\n- high-risk API contracts are represented in OpenAPI and protected by tests;\n- JSON logs, request IDs, Prometheus metrics, dashboards, and alert rules are\n  available through an optional observability overlay;\n- the production overlay runs backend processes as a non-root user with a\n  read-only root filesystem, dropped capabilities, and resource limits;\n- CI checks syntax, lint, tests, release gates, Compose files, dependencies,\n  source security, secrets, API compatibility, version drift, and text encoding.\n\nThe source version is declared in [`VERSION`](VERSION). Git release tags use the\nsame semantic version with a leading `v`, for example `v5.0.1`.\n\n## Architecture\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"docs/screenshots/architecture-v5.png\" alt=\"QuantDinger v5 architecture covering clients, Agent Gateway, core platform, workers, infrastructure, observability, and the closed-loop trading workflow\" width=\"100%\"\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\u003csub\u003eThe editable source is available as \u003ca href=\"docs/screenshots/architecture-v5.svg\"\u003earchitecture-v5.svg\u003c/a\u003e.\u003c/sub\u003e\u003c/p\u003e\n\nThe diagram above shows the complete product and process architecture. The\nruntime topology below focuses on container-to-container ownership and data flow.\n\n```mermaid\nflowchart TB\n    C[\"Web / Mobile / API / MCP clients\"]\n    FE[\"Nginx frontend services\"]\n    API[\"Flask + Gunicorn API\"]\n    PG[(\"PostgreSQL\")]\n    CACHE[(\"Redis cache\")]\n    JOBS[(\"Redis jobs\")]\n    TW[\"Trading worker\"]\n    SW[\"Scheduler worker\"]\n    CW[\"Celery worker\"]\n    BEAT[\"Celery beat\"]\n    PROM[\"Prometheus\"]\n    GRAF[\"Grafana\"]\n    ALERT[\"Alertmanager\"]\n\n    C --\u003e FE --\u003e API\n    API --\u003e PG\n    API --\u003e CACHE\n    API --\u003e|\"durable commands\"| PG\n    TW --\u003e|\"leases, orders, heartbeats\"| PG\n    SW --\u003e|\"schedules, monitoring, heartbeats\"| PG\n    API --\u003e|\"finite async jobs\"| JOBS\n    BEAT --\u003e JOBS --\u003e CW\n    CW --\u003e PG\n    API -. metrics .-\u003e PROM\n    PG -. exporter .-\u003e PROM\n    CACHE -. exporter .-\u003e PROM\n    JOBS -. exporter .-\u003e PROM\n    PROM --\u003e GRAF\n    PROM --\u003e ALERT\n```\n\nOne backend image is reused by several containers with different commands:\n\n| Process | Responsibility |\n| --- | --- |\n| `migration` | Applies the database schema and exits before application services start. |\n| `backend` | Handles HTTP, authentication, validation, and durable command submission. |\n| `trading-worker` | Owns strategy runtimes, pending orders, broker sessions, and reconciliation. |\n| `scheduler-worker` | Runs portfolio, deployment, payment, and signal schedules. |\n| `celery-worker` | Executes finite AI, backtest, experiment, report, and maintenance jobs. |\n| `celery-beat` | Dispatches periodic Celery tasks. |\n\nSee [Backend process roles](docs/architecture/PROCESS_ROLES_AND_TASKS.md),\n[architecture](docs/architecture/ARCHITECTURE.md), and\n[concurrency model](docs/architecture/CONCURRENCY_MODEL.md) for the ownership rules.\n\n## Quick start\n\n### Option A: prebuilt images\n\nPrerequisites: Docker with Compose v2. Node.js and a local Python environment are\nnot required.\n\nLinux or macOS:\n\n```bash\ncurl -fsSL https://raw.githubusercontent.com/OpenByteInc/QuantDinger/main/install.sh | bash\n```\n\nWindows PowerShell:\n\n```powershell\nirm https://raw.githubusercontent.com/OpenByteInc/QuantDinger/main/install.ps1 | iex\n```\n\nThe installer asks for the initial administrator credentials, generates the\nrequired secrets, downloads the GHCR Compose stack, and starts it.\n\nOpen:\n\n- Web: \u003chttp://127.0.0.1:8888\u003e\n- Mobile H5: \u003chttp://127.0.0.1:8889\u003e\n- API health: \u003chttp://127.0.0.1:5000/api/health\u003e\n\n### Docker administrator and settings notes\n\nDetailed guides: [English](docs/deployment/ADMIN_AND_SETTINGS_TROUBLESHOOTING_EN.md) |\n[中文](docs/deployment/ADMIN_AND_SETTINGS_TROUBLESHOOTING_CN.md)\n\nOn a fresh database, the backend creates the initial administrator from\n`ADMIN_USER`, `ADMIN_PASSWORD`, and optional `ADMIN_EMAIL`. Passwords are stored\nas hashes, never as plaintext. An existing PostgreSQL volume is not overwritten:\nthe backend only replaces the untouched legacy `quantdinger` / `123456`\nadministrator when a non-default administrator is explicitly configured. It\nnever overwrites an account whose password was already changed, and it refuses\nto promote an existing account that already uses the requested username.\n\nManual Docker deployments retain `quantdinger` / `123456` only for backward\ncompatibility when the administrator variables are left at their defaults. This\ncredential is not suitable for an internet-facing deployment; change it before\nfirst start or immediately after the first login. The one-command installer does\nnot accept `123456` as the chosen password.\n\nThe Settings UI writes runtime configuration to `/app/.env`. In the GHCR stack\nthis is the host `backend.env`; in a source deployment it is\n`backend_api_python/.env`. Current backend images automatically give runtime UID\n`10001` ownership and keep mode `600`. Do not use `chmod 755` or recursive `777`:\nthese files contain passwords and API keys, and `755` still does not grant write\naccess to UID `10001` when root owns the file.\n\nVerify write access with:\n\n```bash\ndocker compose exec -u 10001:10001 -T backend \\\n  sh -c 'test -w /app/.env \u0026\u0026 echo writable=yes || echo writable=no'\n```\n\nThe hardened production override intentionally mounts `/app/.env` read-only.\nWhen using `docker-compose.production.yml`, manage configuration on the host and\nrecreate the services instead of saving it from the Settings UI. See the\n[English guide](docs/deployment/ADMIN_AND_SETTINGS_TROUBLESHOOTING_EN.md) or\n[中文指南](docs/deployment/ADMIN_AND_SETTINGS_TROUBLESHOOTING_CN.md) for\nlegacy-image recovery and rootless/NFS notes.\n\n### Option B: source checkout\n\n```bash\ngit clone https://github.com/OpenByteInc/QuantDinger.git\ncd QuantDinger\ncp backend_api_python/env.example backend_api_python/.env\ncp .env.example .env\n```\n\nBefore the first start, replace the example values in both environment files:\n\n| File | Required production values |\n| --- | --- |\n| `backend_api_python/.env` | `SECRET_KEY`, `CREDENTIAL_ENCRYPTION_KEY`, `ADMIN_USER`, `ADMIN_PASSWORD` |\n| `.env` | `POSTGRES_PASSWORD`, `REDIS_PASSWORD`, `CELERY_REDIS_PASSWORD`, `GRAFANA_ADMIN_PASSWORD` |\n\nGenerate independent secrets with:\n\n```bash\npython -c \"import secrets; print(secrets.token_hex(32))\"\n```\n\nStart the core stack from local backend source:\n\n```bash\ndocker compose up -d --build\ndocker compose ps\n```\n\nThe base stack does not start Prometheus, Grafana, or Alertmanager. This keeps\nthe default open-source installation smaller.\n\nFor detailed installation paths, Windows notes, China mirror settings, and\nPostgreSQL migration guidance, see\n[Installation troubleshooting](docs/deployment/INSTALL_TROUBLESHOOTING.md) and the\n[cloud deployment guide](docs/deployment/CLOUD_DEPLOYMENT_EN.md).\n\n## Production deployment\n\nValidate secrets before starting a production stack:\n\n```bash\npython backend_api_python/scripts/check_production_config.py \\\n  --env-file .env \\\n  --env-file backend_api_python/.env\n```\n\nStart the hardened runtime with optional observability:\n\n```bash\ndocker compose \\\n  -f docker-compose.yml \\\n  -f docker-compose.production.yml \\\n  -f docker-compose.observability.yml \\\n  up -d --build\n```\n\nOmit `docker-compose.observability.yml` when the host is resource-constrained or\nmonitoring is provided externally.\n\nProduction rules:\n\n- expose only a TLS reverse proxy on ports 80/443;\n- keep PostgreSQL, both Redis instances, Prometheus, Grafana, and Alertmanager\n  off the public internet;\n- do not deploy with example passwords or empty encryption keys;\n- back up PostgreSQL and the durable `redis-jobs` volume;\n- keep cache Redis disposable and never use it as the Celery broker;\n- review worker health and application readiness after every deployment.\n\nThe full checklist is in [Production hardening](docs/deployment/PRODUCTION_HARDENING.md).\n\n## Local endpoints\n\nAll published ports bind to loopback by default.\n\n| Service | Default URL | Purpose |\n| --- | --- | --- |\n| Web | \u003chttp://127.0.0.1:8888\u003e | Desktop web client and same-origin API proxy. |\n| Mobile H5 | \u003chttp://127.0.0.1:8889\u003e | Mobile web client and same-origin API proxy. |\n| Backend | \u003chttp://127.0.0.1:5000\u003e | Direct API access and health endpoints. |\n| Grafana | \u003chttp://127.0.0.1:3000\u003e | Dashboards; available only with the observability overlay. |\n| Prometheus | \u003chttp://127.0.0.1:9090\u003e | Metrics storage and queries; optional. |\n| Alertmanager | \u003chttp://127.0.0.1:9093\u003e | Alert grouping, silencing, and delivery; optional. |\n\nContainer-only ports such as the job Redis and exporters are not published to\nthe host.\n\n## Observability\n\nThe monitoring stack is optional by design:\n\n- **Prometheus** collects API, worker, PostgreSQL, and Redis metrics.\n- **Grafana** turns those metrics into operator dashboards.\n- **Alertmanager** groups alerts, manages silences, and sends notifications once\n  a receiver is configured.\n\nStart it for local diagnostics without the production overlay:\n\n```bash\ndocker compose \\\n  -f docker-compose.yml \\\n  -f docker-compose.observability.yml \\\n  up -d\n```\n\nMonitoring services stay on `127.0.0.1`. Use a VPN, SSH tunnel, or authenticated\nreverse proxy for remote administration. See\n[Observability](docs/deployment/OBSERVABILITY.md) for dashboards, alerts, retention, and\nreceiver configuration.\n\n## Security model\n\n- Broker credentials and MFA secrets are encrypted with a stable\n  `CREDENTIAL_ENCRYPTION_KEY`.\n- Agent tokens are hashed, scoped, rate-limited, and audit-logged.\n- Agent trading is paper-only by default; live access requires both token and\n  server-side authorization.\n- Long-running strategy ownership uses leases, heartbeats, and fencing tokens.\n- Production containers run without root privileges or Linux capabilities.\n- Host port defaults are loopback-only; public access should terminate at a TLS\n  reverse proxy.\n\nReport vulnerabilities privately according to [SECURITY.md](SECURITY.md). Do\nnot include credentials, account data, or exploitable details in public issues.\n\n## Strategy and integration surfaces\n\n| Area | Current surface |\n| --- | --- |\n| Indicators | Python chart overlays, markers, bands, and signals. |\n| Strategies | Strategy API V2 intents, sizing, risk, backtests, and live runtime. |\n| Crypto | Binance, OKX, Bitget, Bybit, Gate, HTX, and adapter extensions. |\n| Traditional brokers | IBKR and Alpaca workflows. |\n| AI providers | OpenRouter, OpenAI-compatible APIs, Google, DeepSeek, Grok, MiniMax, and custom endpoints. |\n| Automation | Human API, Agent Gateway, MCP server, Celery jobs, schedules, and notifications. |\n\nStart with the [Indicator guide](docs/trading/INDICATOR_DEV_GUIDE.md),\n[Strategy guide](docs/trading/STRATEGY_DEV_GUIDE.md), and\n[Extension guide](docs/architecture/EXTENSION_GUIDE.md).\n\n## AI agents and MCP\n\nThe Agent Gateway is exposed under `/api/agent/v1`. The included MCP server lets\nclients such as Cursor, Claude Code, and Codex call approved tools without\nreceiving broker credentials or administrator JWTs.\n\nLive trading through an agent requires all of the following:\n\n1. a token with trading scope;\n2. `paper_only=false` on that token;\n3. `AGENT_LIVE_TRADING_ENABLED=true` on the server;\n4. operator-configured limits and allowlists.\n\nSee [MCP setup](docs/agent/MCP_SETUP.md),\n[Agent quick start](docs/agent/AGENT_QUICKSTART.md), and the\n[Agent OpenAPI document](docs/agent/agent-openapi.json).\n\n## Development\n\nBackend development uses Python 3.12:\n\n```bash\ncd backend_api_python\npython -m venv .venv\npython -m pip install -r requirements-dev.txt\npython -m pytest -m \"not integration and not stress\" --ignore=tests/release_gate -q\nruff check app scripts tests\n```\n\nUseful repository checks:\n\n```bash\npython scripts/check_version.py\npython scripts/check_mojibake.py\ndocker compose -f docker-compose.yml config -q\ndocker compose -f docker-compose.yml -f docker-compose.production.yml -f docker-compose.observability.yml config -q\n```\n\nAPI changes should follow [API conventions](docs/architecture/API_CONVENTIONS.md), update the\nOpenAPI artifact when required, and pass the compatibility workflow.\n\n## Repository layout\n\nThis repository contains the backend, worker processes, deployment definitions,\noperations configuration, documentation, and MCP server. The desktop and mobile\nclient source code live in separate repositories; this repository consumes their\npublished images in the Compose stacks.\n\n```text\nQuantDinger/\n|-- .github/workflows/                 CI, security, compatibility, and release checks\n|-- backend_api_python/                Backend application and all backend processes\n|   |-- app/\n|   |   |-- __init__.py                Flask application factory and core wiring\n|   |   |-- startup.py                 Process-aware startup hooks and service singletons\n|   |   |-- celery_app.py              Celery application and task registration\n|   |   |-- commands/                  Migration, scheduler, trading, and health entrypoints\n|   |   |-- config/                    Environment-backed database, Redis, and provider config\n|   |   |-- routes/                    Human HTTP API route facades\n|   |   |   `-- agent_v1/              Scoped Agent Gateway API under /api/agent/v1\n|   |   |-- openapi/                   OpenAPI schemas, tags, registration, and export support\n|   |   |-- services/                  Domain workflows and third-party integrations\n|   |   |   |-- backtest_engine/       Backtest execution components\n|   |   |   |-- live_trading/          Normalized crypto exchange adapters\n|   |   |   |-- alpaca_trading/        Alpaca broker integration\n|   |   |   |-- ibkr_trading/          Interactive Brokers integration\n|   |   |   |-- strategy_runtime/      Strategy signals, intents, execution, and state\n|   |   |   `-- strategy_v2/           Versioned strategy contracts and runtime services\n|   |   |-- data_sources/              Raw market-data source adapters\n|   |   |-- data_providers/            Aggregated market, macro, news, and sentiment providers\n|   |   |-- markets/                   Market and symbol normalization\n|   |   |-- tasks/                     Finite, retryable Celery jobs\n|   |   |-- workers/                   Long-lived worker process shells\n|   |   |-- runtime/                   Process-role and ownership helpers\n|   |   |-- observability/             Request context, metrics, and HTTP instrumentation\n|   |   `-- utils/                     Shared low-level database, cache, auth, and logging helpers\n|   |-- migrations/                    PostgreSQL schema and seed migrations\n|   |-- scripts/                       Backend maintenance and validation commands\n|   |-- tests/                         Unit, contract, integration, and release-gate tests\n|   |-- run.py                         Local Flask and Gunicorn application entrypoint\n|   |-- Dockerfile                     Shared image for API and worker containers\n|   `-- docker-entrypoint.sh           Container command dispatcher\n|-- docs/\n|   |-- architecture/                  Boundaries, concurrency, API, and extension design\n|   |-- deployment/                    Installation, production, and observability operations\n|   |-- trading/                       Strategy and indicator development guides\n|   |-- api/                           Human API documentation\n|   `-- agent/                         Agent Gateway and MCP documentation\n|-- mcp_server/                        Standalone QuantDinger MCP server package\n|   |-- src/quantdinger_mcp/           MCP server and security implementation\n|   `-- tests/                         MCP contract and security tests\n|-- ops/                               Runtime operations configuration\n|   |-- prometheus/                    Scrape configuration and alert rules\n|   |-- grafana/                       Provisioned data sources and dashboards\n|   `-- alertmanager/                  Alert routing configuration\n|-- scripts/                           Repository-level version, encoding, and setup checks\n|-- docker-compose.yml                 Core local/source stack\n|-- docker-compose.ghcr.yml            Prebuilt-image installation stack\n|-- docker-compose.production.yml      Production hardening overlay\n|-- docker-compose.observability.yml   Optional monitoring overlay\n|-- install.sh / install.ps1           Linux/macOS and Windows installers\n`-- VERSION                            Canonical source version\n```\n\n### Main execution paths\n\n| Flow | Path through the repository |\n| --- | --- |\n| Synchronous API request | `app/routes` -\u003e `app/services` -\u003e database, cache, market-data, or trading adapter |\n| Durable strategy command | API route -\u003e PostgreSQL command record -\u003e `trading-worker` -\u003e strategy runtime and broker adapter |\n| Finite background job | API or Celery beat -\u003e job Redis -\u003e `app/tasks` in `celery-worker` -\u003e PostgreSQL result |\n| Scheduled domain work | `app/commands/scheduler.py` -\u003e scheduling services -\u003e durable state and notifications |\n| Monitoring | API and workers -\u003e `app/observability` metrics -\u003e Prometheus -\u003e Grafana and Alertmanager |\n| Agent or MCP call | MCP client -\u003e `mcp_server` -\u003e `/api/agent/v1` -\u003e the same service layer used by human APIs |\n\nLong-lived trading loops belong to the trading worker. Finite, retryable work\nbelongs to Celery. HTTP routes validate and delegate; they must not own trading\nloops, exchange-specific behavior, or large database workflows.\n\n### Where changes belong\n\n| Change | Primary location | Usually update as well |\n| --- | --- | --- |\n| Add or modify an HTTP endpoint | `backend_api_python/app/routes/` | `app/openapi/`, route/contract tests, API docs |\n| Add a business workflow | `backend_api_python/app/services/` | focused service tests |\n| Add an exchange or broker integration | `app/services/live_trading/` or the broker package | credential policy, adapter tests, docs |\n| Add a market-data source | `app/data_sources/` | provider aggregation, cache keys, tests |\n| Add dashboard, news, or macro aggregation | `app/data_providers/` | route facade and cache policy |\n| Add a finite asynchronous task | `app/tasks/` | `celery_app.py`, queue routing, task tests |\n| Add long-lived process behavior | `app/workers/`, `app/commands/`, or `app/runtime/` | Compose command, health checks, ownership tests |\n| Change the database schema | `backend_api_python/migrations/` | migration/release-gate tests and docs |\n| Add metrics or alerts | `app/observability/` and `ops/` | dashboard, alert rule, observability docs |\n| Add an MCP tool | `mcp_server/src/quantdinger_mcp/` | Agent Gateway scope, security tests, agent docs |\n\nThe web and mobile repositories publish their own GHCR images. Node.js is only\nneeded when building those clients from source. For deeper ownership rules, read\n[Architecture](docs/architecture/ARCHITECTURE.md),\n[Module boundaries](docs/architecture/MODULE_BOUNDARIES.md), and\n[Process roles](docs/architecture/PROCESS_ROLES_AND_TASKS.md).\n\n## Documentation\n\nThe maintained documentation index is available at [`docs/README.md`](docs/README.md).\n\n| Topic | Document |\n| --- | --- |\n| Contributor architecture | [Architecture](docs/architecture/ARCHITECTURE.md) |\n| Module ownership | [Module boundaries](docs/architecture/MODULE_BOUNDARIES.md) |\n| Process and task ownership | [Process roles](docs/architecture/PROCESS_ROLES_AND_TASKS.md) |\n| Production runtime | [Production hardening](docs/deployment/PRODUCTION_HARDENING.md) |\n| Metrics and alerts | [Observability](docs/deployment/OBSERVABILITY.md) |\n| Human API contracts | [API conventions](docs/architecture/API_CONVENTIONS.md) |\n| OpenAPI artifacts | [API documentation](docs/api/README.md) |\n| Strategy development | [Strategy guide](docs/trading/STRATEGY_DEV_GUIDE.md) |\n| Indicator development | [Indicator guide](docs/trading/INDICATOR_DEV_GUIDE.md) |\n| MCP and agents | [Agent documentation](docs/agent/README.md) |\n| Cloud deployment | [Cloud deployment](docs/deployment/CLOUD_DEPLOYMENT_EN.md) |\n| Installation problems | [Troubleshooting](docs/deployment/INSTALL_TROUBLESHOOTING.md) |\n\n## Contributing\n\nRead [CONTRIBUTING.md](CONTRIBUTING.md) and [DEVELOPMENT.md](DEVELOPMENT.md)\nbefore opening a pull request. Keep routes thin, preserve API compatibility,\nplace long-running behavior in the correct process, and include focused tests\nfor high-risk changes.\n\n## Exchange partner links\n\nThese are referral links. QuantDinger may receive a commission or trading-fee\nrebate when a user registers through one of them. This does not add a separate\ncharge to the user; eligibility and terms are controlled by each venue and may\nchange. Always verify the destination domain before creating an account.\n\nThe same links are available in the application under **Profile → Open account**\nand **Broker Accounts → Open account**.\n\n| Exchange | Signup link |\n| --- | --- |\n| Binance | [Register](https://www.bsmkweb.cc/register?ref=QUANTDINGER) |\n| Bitget | [Register](https://partner.hdmune.cn/bg/7r4xz8kd) |\n| Bybit | [Register](https://partner.bybit.com/b/DINGER) |\n| OKX | [Register](https://www.xqmnobxky.com/join/QUANTDINGER) |\n| Gate.io | [Register](https://www.gateport.business/share/DINGER) |\n| HTX | [Register](https://www.htx.com/invite/zh-cn/1f?invite_code=dinger) |\n\n## License and commercial terms\n\n- Backend source code is licensed under [Apache License 2.0](LICENSE).\n- QuantDinger is a product of **Open Byte Inc**. The name, logo, product\n  identity, and commercial licensing are managed separately from the code license.\n- Web frontend source is published in\n  [QuantDinger Frontend](https://github.com/OpenByteInc/QuantDinger-Vue) under\n  its own source-available license.\n- Mobile H5 and native client source is published in\n  [QuantDinger Mobile](https://github.com/OpenByteInc/QuantDinger-Mobile) under\n  its own source-available license.\n- Trademark, branding, attribution, and watermark use is governed by\n  [TRADEMARKS.md](TRADEMARKS.md). Apache 2.0 does not grant trademark rights.\n\nFor commercial licensing, frontend source access, branding authorization, or\ndeployment support:\n\n- Website: [quantdinger.com](https://www.quantdinger.com)\n- Telegram: [t.me/worldinbroker](https://t.me/worldinbroker)\n- Email: [support@quantdinger.com](mailto:support@quantdinger.com)\n\n## Legal notice and compliance\n\nQuantDinger is intended for **lawful research, education, and compliant trading\nonly**. It must not be used for fraud, market manipulation, sanctions evasion,\nmoney laundering, or other illegal activity. Operators are responsible for\nfollowing the laws, licensing requirements, tax rules, broker or exchange terms,\nand data regulations that apply in every jurisdiction where they deploy or use\nthe software.\n\n**This project does not provide legal, tax, investment, financial, or regulatory\nadvice.** Trading, including automated and leveraged trading, can result in the\nloss of some or all capital. Historical data, backtests, simulated results, AI\noutput, indicators, and strategy examples do not guarantee future performance.\nUsers must independently review strategies, permissions, order limits, and risk\ncontrols before enabling live execution.\n\nThe software is provided under the terms of the applicable license and is used\nat the operator's own risk. To the extent permitted by law, project maintainers\nand contributors disclaim liability for trading losses, data loss, service\ninterruption, third-party failures, security incidents, or regulatory consequences\narising from use or misuse of the software.\n\n## Community and support\n\n\u003cp\u003e\n  \u003ca href=\"https://t.me/quantdinger\"\u003e\u003cimg src=\"docs/badges/telegram-group.svg\" alt=\"Telegram\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://discord.com/invite/tyx5B6TChr\"\u003e\u003cimg src=\"https://img.shields.io/badge/Discord-Server-5865F2?style=for-the-badge\u0026logo=discord\" alt=\"Discord\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://youtube.com/@quantdinger\"\u003e\u003cimg src=\"https://img.shields.io/badge/YouTube-Channel-FF0000?style=for-the-badge\u0026logo=youtube\" alt=\"YouTube\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://x.com/QuantDinger_EN\"\u003e\u003cimg src=\"https://img.shields.io/badge/X-Follow-000000?style=for-the-badge\u0026logo=x\" alt=\"X\"\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n- [Website](https://www.quantdinger.com)\n- [Contributing guide](CONTRIBUTING.md)\n- [Contributors](CONTRIBUTORS.md)\n- [Report bugs or request features](https://github.com/OpenByteInc/QuantDinger/issues)\n- Email: [support@quantdinger.com](mailto:support@quantdinger.com)\n\n## Sponsors\n\nQuantDinger's continued development and open-source community are supported by:\n\n\u003ctable\u003e\n  \u003ctr\u003e\n    \u003ctd align=\"center\" width=\"50%\"\u003e\n      \u003ca href=\"https://www.atlascloud.ai/\"\u003e\n        \u003cpicture\u003e\n          \u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.atlascloud.ai/logo-white.svg\"\u003e\n          \u003cimg src=\"https://www.atlascloud.ai/logo.svg\" alt=\"Atlas Cloud\" width=\"190\"\u003e\n        \u003c/picture\u003e\n      \u003c/a\u003e\n      \u003cbr\u003e\u003cbr\u003e\n      \u003cstrong\u003eAtlas Cloud\u003c/strong\u003e\n      \u003cbr\u003e\n      \u003csub\u003eAI inference sponsor\u003c/sub\u003e\n    \u003c/td\u003e\n    \u003ctd align=\"center\" width=\"50%\"\u003e\n      \u003ca href=\"https://aws.amazon.com/\"\u003e\n        \u003cpicture\u003e\n          \u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://a0.awsstatic.com/libra-css/images/logos/aws_smile-header-desktop-en-white_59x35.png\"\u003e\n          \u003cimg src=\"https://upload.wikimedia.org/wikipedia/commons/9/93/Amazon_Web_Services_Logo.svg\" alt=\"Amazon Web Services\" width=\"100\"\u003e\n        \u003c/picture\u003e\n      \u003c/a\u003e\n      \u003cbr\u003e\u003cbr\u003e\n      \u003cstrong\u003eAmazon Web Services\u003c/strong\u003e\n      \u003cbr\u003e\n      \u003csub\u003eCloud infrastructure sponsor\u003c/sub\u003e\n    \u003c/td\u003e\n  \u003c/tr\u003e\n\u003c/table\u003e\n\nWe are grateful to [Atlas Cloud](https://www.atlascloud.ai/) for supporting AI\nmodel inference and to [Amazon Web Services](https://aws.amazon.com/) for\nsupporting the cloud infrastructure that helps QuantDinger serve its community.\n\n## Support the project\n\nIf QuantDinger is useful to you, a GitHub star, contribution, or donation helps\nfund ongoing development and infrastructure.\n\nCrypto donation address:\n\n```text\n0x96fa4962181bea077f8c7240efe46afbe73641a7\n```\n\nCrypto transfers are irreversible. Confirm the address and intended network with\nthe project maintainers before sending funds.\n\n## Acknowledgements\n\nQuantDinger stands on top of a strong open-source ecosystem. Special thanks to\nthe maintainers and contributors of projects including:\n\n- [Flask](https://flask.palletsprojects.com/)\n- [Gunicorn](https://gunicorn.org/)\n- [Celery](https://docs.celeryq.dev/)\n- [PostgreSQL](https://www.postgresql.org/)\n- [Redis](https://redis.io/)\n- [Pandas](https://pandas.pydata.org/)\n- [NumPy](https://numpy.org/)\n- [CCXT](https://github.com/ccxt/ccxt)\n- [yfinance](https://github.com/ranaroussi/yfinance)\n- [AkShare](https://github.com/akfamily/akshare)\n- [Vue.js](https://vuejs.org/)\n- [Ant Design Vue](https://antdv.com/)\n- [KLineCharts](https://github.com/klinecharts/KLineChart)\n- [ECharts](https://echarts.apache.org/)\n- [Capacitor](https://capacitorjs.com/)\n- [bip-utils](https://github.com/ebellocchia/bip_utils)\n- [Prometheus](https://prometheus.io/)\n- [Grafana](https://grafana.com/)\n\n## P.S. — A note on the name\n\n**QuantDinger** is a small tribute to\n**[Erwin Schrödinger](https://en.wikipedia.org/wiki/Erwin_Schr%C3%B6dinger)** —\nthe “-dinger” in our name is the tail of “Schrödinger”. The cat in the box was a\nthought experiment; every un-fired strategy is its own little version of it —\nsimultaneously winning and losing until the order actually fills. Backtests open\nthe box. Live trading collapses the wavefunction. Trade carefully.\n\n\u003cp align=\"center\"\u003e\u003csub\u003eIf QuantDinger is useful to you, a GitHub star helps the project a lot.\u003c/sub\u003e\u003c/p\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FOpenByteInc%2FQuantDinger","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FOpenByteInc%2FQuantDinger","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FOpenByteInc%2FQuantDinger/lists"}