Run the local beta and prepare a self-hosted deployment. This guide is for the person operating the service.
Run the local application
Campaigns, participant memberships, immutable referral attribution, qualifying events, reviews, appeals, and a private reward ledger work locally. The website includes owner and participant workspaces. A native desktop client uses the same service. External accounts, assessments, subscriptions, and reward transfers need provider configuration.
rtk proxy devenv up --strict-ports
The preferred development origin is http://127.0.0.1:5193. A different allocated port is a different account-provider origin. Confirm the process address before signing in; another application may already occupy a familiar port.
rtk proxy devenv processes list
rtk proxy devenv processes status site
Development explicitly enables a local operator credential saved privately at .state/operator.token. Use it at /auth. The settings page creates ten-minute, single-use participant test invitations; no email is sent. Local access requires a loopback origin and actual loopback peer, and cannot be enabled on a public HTTPS origin.
Build and edit
Edit site/src/ for landing pages, guides, styles, and rendered application pages. The generated website lives in site/dist/. Service source lives in service/; the native client lives in desktop/.
rtk proxy devenv tasks run frenzy:build
rtk proxy devenv tasks run frenzy:service-build
rtk proxy devenv tasks run frenzy:desktop:check
rtk proxy devenv tasks run frenzy:desktop:run
Devenv watches source changes and rebuilds before restarting. Dependency locks and pinned compiler provisioning are checked in. A failed compile must not be treated as a successful build of an older executable.
Manage the development process
rtk proxy devenv up --detach --strict-ports
rtk proxy devenv processes logs site
rtk proxy devenv down
The health endpoint checks the actual campaign worker. A ready process does not prove external login, payment delivery, or production capacity. Refresh the browser after a source rebuild.
Host one durable service
The supplied container and launcher run one campaign worker with a durable snapshot and an encrypted provider/session database. They do not install a distributed cloud cluster. Indexed production storage, large-dataset pagination, and 100,000-participant load capacity have not been verified.
Container configuration and a reverse-proxy example are in deployment/, with secrets placeholders in .env.example. The container runs without root and stores private state on a persistent volume. Keep the service port private behind your HTTPS proxy.
Runtime licensing, this product's distribution terms, and operating costs are separate. A public hostname and remote host have not been chosen.
Protect and recover state
Choose an owned HTTPS origin and preserve it through the proxy. Only explicitly allowlisted actual proxy peers can attest to TLS termination. Forwarded client addresses never grant local operator authority. Public configurations disable local operator access and live transfers.
Stop the service before taking a consistent backup of the entire state directory. Preserve its encryption key, campaign snapshot, database, and payment receipts together. Start only one writer for a snapshot; an existing writer is refused. Unknown schema versions fail startup instead of discarding data.
Before an upgrade, back up, rebuild, and verify a replacement against the same persistent volume. A tested local restart is not evidence of remote disaster recovery. Operator contact details, retention decisions, jurisdiction, and review of the draft legal notices remain publication requirements.
Configure external services
Account sign-in uses Not Organic with server-side credentials, authorization checks, and metering. Its product registry includes frenzy, but the exact application origin must also map to that product in its client catalog. The generic development-origin fallback selects another product and is rejected. Informative client metadata is not origin approval.
Configure both provider URLs and the per-request inference budget. Participants separately consent to public profile collection and assessment. Bluesky observations work without collecting a social password; ownership of a supplied handle remains unverified. Other networks require approved social clients.
Assessment results remain inferred judgments. Forecasts use numerical observations frozen before future qualifying actions and require at least 30 completed seven-day windows. Missing facts remain missing; cold starts return a learning state. Forecasts have no verified confidence interval and never approve or increase a reward automatically.
Subscription checkout requires the server payment key, signed webhook secret, and exact recurring price identifiers. Annual billing is the default; capacities reset monthly. A checkout return does not grant paid access. Reward recipients use the payment provider's hosted identity and bank setup, with verification fetched from the provider.
Live transfers require explicit operator enablement and an approved reward. A transfer is separate from a bank payout. Individual settlement requires exact attributable live provider evidence; test, grouped, manual, or fee-reduced payouts cannot silently become paid rewards. Later verified failure clears paid status, retains the audit and budget commitment, and blocks accidental second transfers.
Beta and quote requests are saved with delivery: not_sent. No outbound mail service is configured.
Add Cap walkthroughs and campaign examples
Keep recording links in cap/walkthroughs/ for product tutorials and cap/campaigns/ for campaigns you run with your own products. Use one Markdown file per recording:
# Setting up a campaign
https://cap.so/s/VIDEO_ID
A walkthrough of the offer, qualifying event, reward rules, and budget.
Replace VIDEO_ID with the recording's real ID. The planned library reader takes the first Cap share link, uses the first heading as the title, and treats the remaining text as the description. Subfolders group recordings. The library README is not a recording.
Cap documents playback at https://cap.so/embed/VIDEO_ID. An explicitly configured self-hosted Cap origin would be retained when deriving the embed address. Private and password-protected recordings retain their Cap access requirements.
The folders exist; a Frenzy library reader and embedded player do not. Adding a file today stores the source link without publishing it into the product. Automatic thumbnails and duration are deferred. Do not place private campaign data in a public walkthrough.
Frenzy CLI and MCP
Run campaigns, manage referral rewards, pin websites, and research people from your terminal or an AI assistant. The CLI and MCP server share 35 operations and use your Frenzy account permissions.
Install Bun (1.4.2 or later) and RTK, with both executables on your PATH. These examples use RTK's proxy wrapper to pass commands through unchanged. Then download the standalone Frenzy CLI. The CLI includes the MCP server. A dedicated MCP bundle, version and checksums, and third-party notices are also available.
rtk proxy mkdir -p ~/.local/share/frenzy
rtk proxy curl --fail --location https://frenzy.zone/assets/frenzy.mjs --output ~/.local/share/frenzy/frenzy.mjs
rtk proxy bun ~/.local/share/frenzy/frenzy.mjs auth login
rtk proxy bun ~/.local/share/frenzy/frenzy.mjs campaigns list
rtk proxy bun ~/.local/share/frenzy/frenzy.mjs discoveries start --help
Login opens a browser approval page. Sign in and enter the confirmation code printed in your terminal. Use auth login --no-open to open the link yourself. The resulting device session is stored in a private directory and is shared by the CLI and MCP process. auth logout revokes it.
Configure your MCP client with the absolute path to your downloaded bundle:
{
"mcpServers": {
"frenzy": {
"command": "bun",
"args": ["/absolute/path/to/frenzy.mjs", "mcp"]
}
}
}
Add --read-only to the arguments to expose only read tools. Ask your assistant to list campaigns, inspect referral graphs, pin research sources, start discovery searches, or review candidates. The server communicates over stdio and uses the same saved session as the CLI.
Each command has its own --help. Use --json for structured output and --input @file.json for saved inputs. Writes return a retry key; reuse --idempotency-key when repeating the same action. For a self-hosted service, set --origin on the CLI and the matching FRENZY_ORIGIN in your MCP process.
Verify each boundary separately
Compiled service tests exercise attribution, qualification, duplicate events, budget caps, isolation, held rewards, appeals, settlement reconciliation, and restart durability. Gateway tests use the real compiled worker and encrypted sessions. Provider adapter tests use controlled responses; they do not establish a live login or purchase.
A local browser run exercises two participant accounts through referral, qualification, hold, appeal, approval, reload, and privacy checks. Both themes passed viewport checks at 320, 390, and 1440 pixels. These are desktop-browser viewports, not physical-device proof.
The container has separate creation/replacement and HTTPS proxy checks. Real DNS/TLS, funded assessments, paid invoices, bank settlement, social-client approval, large-scale load, and remote restore require independent evidence before a public launch.