> For the complete documentation index, see [llms.txt](https://nytshift.gitbook.io/nytshift-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://nytshift.gitbook.io/nytshift-docs/evidence-and-handoff-records/nightshift-live-readiness-continuation-2026-07-24.md).

# Live-readiness continuation · 2026-07-24

**Date:** 2026-07-24 **Production URL:** <https://nytshift.xyz/terminal> **Release:** `79fe54d273f9d2900942bda1e1a47497f2d3e44b` **Artifact SHA-256:** `ceb67c645db28f19a09b568fbcb1dfda8594ff505d66ff778df55e49a34477dd` **Scope:** Signed-in production PAPER QA, exact-release repository verification, PostgreSQL/backup audit, deployment audit and no-send Hyperliquid readiness. No testnet or mainnet venue mutation was performed.

## Result

The signed-in production PAPER terminal passed the repeated trader workflow on the exact verified public release. Market entries, risk rejection, immediate limits, persistent local GTC, stop-loss, take-profit, reduce-only constraints, persistence, and multi-venue PAPER behavior all worked. The browser was left with every tested position flat, zero active local GTC orders, zero reserved GTC notional and PAPER selected.

The public web foundation, customer PostgreSQL ledger and immutable release are healthy. The repository handoff gate passes on the exact deployed commit. Hyperliquid live execution is still deliberately blocked because the user-owned signer account/API wallet and the remaining private authority evidence are not configured. This is a truthful launch blocker, not a PAPER defect.

## Signed-in trader matrix

| Area                     | Production observation                                                                                                                         | Result |
| ------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------- | ------ |
| Identity                 | Existing Privy customer session loaded; private PAPER state recovered to PostgreSQL                                                            | PASS   |
| Database synchronization | PAPER state reported database recovery/synchronization through reloads                                                                         | PASS   |
| Hyperliquid market entry | Opened live-book SOL and BTC PAPER positions from visible depth                                                                                | PASS   |
| Stop-loss                | Invalid long stop rejected; valid SOL stop armed, survived navigation/reload and triggered from a newer venue mark while SOL was away-selected | PASS   |
| Take-profit              | Already-triggered levels rejected; valid BTC short take-profit triggered from a newer venue mark and closed reduce-only                        | PASS   |
| Immediate limit          | Non-crossing BTC limit returned no visible fill and did not invent a resting order                                                             | PASS   |
| Resting GTC              | BTC buy GTC at $60,000 reserved `$19.9998`, survived reload, then canceled locally and released the reserve without a venue cancel             | PASS   |
| Reduce-only wrong side   | Attempt to reduce a BTC long with another long was disabled                                                                                    | PASS   |
| Reduce-only over-close   | Quantity above the exact BTC position was disabled                                                                                             | PASS   |
| Partial reduce-only      | Partial BTC close succeeded and retained the exact remainder                                                                                   | PASS   |
| Exact reduce-only        | Remaining BTC, Arcus BTC-USD and Lighter ETH quantities closed to flat                                                                         | PASS   |
| Risk cap                 | A $300 BTC entry was blocked by the configured $250 one-market cap                                                                             | PASS   |
| Multi-venue PAPER        | Hyperliquid, Arcus and Lighter each completed a live-book open/close cycle                                                                     | PASS   |
| Authority modes          | APPROVAL remained no-send; LIVE remained locked; Lighter named its absent signer boundary                                                      | PASS   |
| Mobile smoke             | 390 x 844 signed-in terminal had no document/body horizontal overflow                                                                          | PASS   |
| Browser errors           | No warning or error originated from `https://nytshift.xyz` during the QA pass                                                                  | PASS   |

The Chrome profile has competing injected-wallet extension warnings outside the NightShift origin. They did not affect PAPER trading or Privy customer state and were not counted as NightShift application errors.

## Exact-release automated verification

`pnpm handoff:verify` passed on `79fe54d`:

| Gate                                                           | Result                                                     |
| -------------------------------------------------------------- | ---------------------------------------------------------- |
| Preflight and hosting boundary                                 | PASS                                                       |
| Contract artifact reproduction                                 | PASS                                                       |
| TypeScript tasks                                               | 16/16                                                      |
| Monorepo tests                                                 | 1,324 passed, 2 environment-gated PostgreSQL tests skipped |
| Dedicated PAPER readiness                                      | 127/127                                                    |
| Operational/runtime tests                                      | 157/157                                                    |
| Python signer tests                                            | 96/96                                                      |
| Python lint                                                    | PASS                                                       |
| Arcus signer supervisor integration                            | PASS                                                       |
| Hyperliquid testnet and capped-mainnet supervisor integrations | PASS                                                       |
| Signer-store backup/restore integration                        | PASS                                                       |
| Optimized Next.js build                                        | PASS                                                       |
| Local production smoke                                         | PASS                                                       |
| Handoff/secret scan                                            | PASS, zero errors                                          |

The two skipped monorepo tests require a configured PostgreSQL integration environment. The real production database path was verified separately below.

## Production and PostgreSQL audit

* `/api/health` reports `status=ok`, `releaseState=verified`, execution disabled, Arcus execution disabled and both mainnet flags false.
* The web service is active with zero restarts. The VPS had approximately 22 GiB free and 5 GiB available RAM during the audit.
* PostgreSQL is active and customer database health is `ready`.
* `CUSTOMER_ACCOUNT_DIGEST_KEY` health is `configured`.
* All four exact migration names and SHA-256 values match the repository, including `004_customer_identity_aliases.sql`.
* The encrypted PostgreSQL backup timer is enabled and active.
* The latest encrypted backup completed successfully and its SHA-256 sidecar verified.
* HTTP redirects to HTTPS with status 301.
* Public health retained one active customer PAPER session and three total PAPER sessions after QA. The active session was preserved instead of resetting user history.

The verified backup is same-host recovery only. Off-host replication and provider snapshot/PITR remain required before real-money launch.

## Signer infrastructure

The isolated Hyperliquid systemd service is installed, disabled and stopped. Its immutable signer-tools release was upgraded from `f1c135b` to the exact public commit `79fe54d`. The service remained inactive throughout.

The zero-network doctor fails closed because `HL_ACCOUNT_ADDRESS` is still the invalid template value. No account, API-wallet key, builder identity, signer token, eligibility token, venue request or capital mutation was introduced.

The redacted loopback readiness audit authenticated and revoked its temporary operator session and reported:

* `state=blocked`;
* `network=disabled`;
* `EXECUTION_MODE_DISABLED`;
* `SIGNER_NOT_CONFIGURED`;
* customer database and account-digest key ready;
* zero open orders expected/observed in the unconfigured scope;
* `capitalMutationAttempted=false`;
* no order, cancellation or fund movement.

## Remaining launch blockers

1. **Privy production rehearsal evidence:** Google login works in the signed-in browser, but the complete wallet-login, cookie DNS, origin rejection, chain-switch, expiry and dashboard checklist has not been truthfully completed. Health therefore keeps production identity evidence unconfigured.
2. **Dedicated Hyperliquid testnet signer identity:** The owner must register a fresh testnet API wallet and privately configure the exact master/subaccount, owner, key file, reviewed builder, signer token and account scope. The owner key must never enter NightShift.
3. **Private execution authority:** Issue current signed eligibility, configure independent confirmation/internal secrets, keep the kill switch active during setup and prove strict signer/BFF scope matching.
4. **Off-host database recovery:** Copy encrypted PostgreSQL backups to a separately credentialed destination and enable provider snapshot/PITR or an equivalent reviewed recovery policy.
5. **Testnet campaign:** With fresh action-time approval before each mutation, complete resting GTC/cancel finality, IOC fill, reduce-only close, TP/SL brackets, ambiguous-outcome reconciliation, scheduled-cancel rehearsal, restart and isolated restore.
6. **Campaign evidence:** Complete and independently retain a verified NS-446 redacted evidence digest with the account flat, all-DEX orders zero, kill switch active, signer stopped and backup verified.
7. **Mainnet-only controls:** Configure operator alert delivery and only then consider the separately authorized BTC-only, 1x, maximum-$12 first canary under the $50 allocation and $2 realized-loss stop.
8. **Public-product lanes:** Licensed Advanced Charts evidence and production Robinhood Chain HTTP/archive/WSS providers remain unconfigured. These do not invalidate the tested custom-chart Hyperliquid PAPER flow, but `publicLaunchReady` remains false until those advertised lanes are complete.
9. **Legal and jurisdiction review:** Record the operator decision before accepting customer real-money execution.

Every API-wallet registration, builder approval, faucet/funding action, dead-man mutation, leverage change, order and cancellation still requires fresh action-time authorization. A green no-send readiness report will not substitute for that authorization.

## Workstation handoff

* No task-owned server, watcher, test runner or browser-automation process remained after verification.
* Windows health: 27.3% sampled CPU, 3.82 GiB free of 15.71 GiB RAM.
* C: is healthy with 44.23 GiB free.
* Hardware temperature sensors remain unavailable to Windows.
* No critical storage event was reported. The external D: drive remains outside this NightShift workflow.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://nytshift.gitbook.io/nytshift-docs/evidence-and-handoff-records/nightshift-live-readiness-continuation-2026-07-24.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
