Skip to content
Pit Officer
Self-hosted pre-trade risk control

Check the order. Keep control of what happens next.

Built-in broker and exchange connections, automatic market prices and pre-trade risk checks. Operate accounts and order flow from a local panel, REST API or MCP tools.

See brokers and price feeds

Open source · Apache-2.0

Built-in trading connections
Interactive Brokers · Binance · Alpaca · eToro
Send approved orders and receive executions through the connections you enable.
Automatic market prices
Subscribe to instruments. Officer receives prices from connected sources and supplies them to the risk engine.
See the workflow

Connections

Connect your broker. Receive prices automatically.

Choose the connections you need in the panel. Trading connections send orders; price feeds keep the risk checks supplied with market prices.

Built-in trading connections

  • Interactive Brokers
  • Binance
  • Alpaca
  • eToro

Send approved orders and receive execution updates through the connection you enable.

Use your own broker account and credentials. Available instruments and test/live modes depend on the provider and connection settings.

Market-data feeds

  • Interactive Brokers
  • Binance
  • Kraken
  • Coinbase
  • Alpaca
  • OKX
  • Bybit
  • OANDA
  • Finnhub

Select a source and subscribe to instruments. Officer receives prices automatically for risk checks. You can also connect a custom feed.

Provider credentials, market-data permissions and subscriptions determine which prices are available. A price feed alone does not enable trading.

Start Officer and configure your connections

Use cases

Start with the job you need to do.

For the people building order flow, operating risk and writing trading automation. Each path starts with the controls you own and the integration you need.

  • Prop desks · risk teams

    Keep account limits outside the strategy

    Operate accounts, groups and risk policies from one panel. Block an account or group to stop new risk approvals without changing the strategy's code.

    • Review positions, policy decisions and account changes through the same control plane.
    • Blocking is a risk gate. It does not mean cancel-all, liquidation or reversal of trades already executed.
    Read the docs
  • Broker · exchange engineers

    Add a risk decision to your order flow

    Use REST to evaluate orders and report executions. In an approval-only integration, your execution component must verify a signed acceptance bound to the exact order before sending it.

    • Keep fills and account state current with execution reports; post-trade reporting alone cannot prevent a trade.
    • Use the built-in trading connections, or keep your existing executor and integrate the risk API.
    Read the docs
  • Agent builders · developers

    Give an agent only the tools it needs

    Connect over MCP with read-only tools enabled by default. An operator chooses which mutating tools to enable. The permissions you grant remain part of your risk boundary.

    • Account block and unblock are not MCP tools.
    • Checking is separate from sending. Trading through an enabled connection requires the trading path; a standalone agent with its own broker credentials can bypass an external gate.
    Read the docs
  • Quant teams · independent traders and developers

    Evaluate a strategy against explicit risk rules

    Connect a price source and subscribe to your instruments from the panel. Officer receives market prices automatically. Configure risk policies, inspect candidate-order decisions and add a built-in trading connection when you need execution.

    • OpenPit computes realized P&L from reported executions and uses configured FX data for account-currency conversion.
    • P&L barriers act on the state and data supplied to the engine. They are controls, not a guarantee against trading losses.
    Read the docs

How it works

One engine. Three ways to use it.

The panel, REST and MCP share Officer's control plane. Order evaluation, execution and reporting are distinct operations.

  1. 01 Evaluates

    OpenPit engine

    Evaluates an order against configured policies, account state and the market data it needs. Returns acceptance or rejection with a reason.

    Determinism means the same complete inputs and state, including positions, reservations and market data.

  2. 02 Coordinates

    Pit Officer control plane

    Stores accounts, groups, policies, orders and audit records in your local database. Restores the engine's state on startup.

    Built-in trading connections send approved orders and bring executions back into Officer. Market-data subscriptions supply the engine with prices automatically.

  3. 03 Operates

    Operator panel

    Review accounts, positions and orders, manage policies and MCP permissions, configure data sources and inspect audit history.

    Use the same control plane from REST or MCP. Endpoint access and the tools you enable are part of your deployment boundary.

From an order request to a risk decision

An approval-only integration returns the decision to your executor. With signing enabled, verify a signed acceptance and its exact order parameters before execution. Sending uses an enabled connection to the selected venue. Officer sends data to the trading and market-data destinations you configured.

Market data and trading connections

Market-data feeds
market prices
The same Pit Officer
approved orders
execution updates
Broker / exchange

Inside the panel

The controls, in one place.

Use the local panel to inspect and operate the same state exposed through the API. Start with the page that answers your next question.

Dashboard
Entity counts, the agent's enabled command surface, market-data health, and recent activity from the audit log.
Policies
Risk-policy barriers applied to the engine per account and asset. Each row is one constraint on order flow.
Accounts
Accounts and groups in one place. Block an account or group to prevent new risk approvals, then unblock when appropriate.
Orders
Report an execution against your own external order id, and confirm or cancel the orders waiting on a person.
Audit
Inspect recorded actions and their source. The audit API does not edit individual records; backup restoration and data reset are separate operations.
MCP access
Choose which commands an AI agent may call, then connect it over MCP. Protected commands need an explicit opt-in.
Signing keys
Configure approval signing. An external executor must verify a signed acceptance and its bound order parameters before sending the order.
Market data
Connect a price source and subscribe to instruments. Officer receives quotes automatically, supplies them to the risk engine and shows timestamps and feed diagnostics.
Read the docs

Open source

Inspect the controls you depend on.

The source, configuration and API contract are available for your own evaluation.

  • Apache-2.0

    Officer and OpenPit are open source. Inspect the implementation, build your own copy and verify the behavior against your integration requirements.

  • Audit history

    Control-plane actions append audit records. The ordinary audit API does not edit individual records. Backup restoration and service data reset can replace or remove stored history; this is not immutable external archival.

  • Your process and database

    Run Officer on infrastructure you control. Market-data sources and enabled trading connections contact the destinations you configure. Checking an order does not send it to a venue.

Inspect the engine

OpenPit evaluates the order using policies, account state, positions, reservations and market data. Reproducing a decision requires those complete inputs, not only an order and a limit value.

Explore OpenPit

Quickstart

Start Officer with one command.

Install Docker once. Then paste one command and open Officer in your browser. No programming skills are needed.

Not using Docker yet? Install Docker

Start Officer

Start Docker Desktop. Open PowerShell on Windows or Terminal on macOS/Linux, paste this command and press Enter.

docker run -d --name pit-officer --restart unless-stopped -p 127.0.0.1:8787:8787 -v pit-officer-data:/data ghcr.io/openpitkit/officer

Docker downloads Officer and runs it in the background. Your data stays on your computer when the container restarts.

Open the panel. Come back to the same address.

Wait for the first startup, then open the link below. Bookmark it to return to your accounts and settings.

Open the panel
http://127.0.0.1:8787
Commands to open the panel or restart Officer
Windows · PowerShell
Start-Process http://127.0.0.1:8787
macOS
open http://127.0.0.1:8787
Linux
xdg-open http://127.0.0.1:8787

If you stopped Officer, start the existing container with the command below. Do not repeat the first-install command or delete your data.

docker start pit-officer

In the panel, add an account, an instrument, a price source and risk limits. Generate or import a signing key for decisions, then add a trading connection when you are ready to send orders.

Get started

Make the first decision visible.

Run Officer locally, configure a policy and inspect an accepted or rejected order with its audit record. Then choose how your execution system will use that decision.

Apache-2.0 · self-hosted · source available

FAQ

Know the boundaries before integrating.

Execution, permissions, market data and deployment are part of the integration contract.

Where does my data live?
Accounts, policies, orders and audit records live in your local SQLite database. Configured market-data adapters and enabled trading connections communicate with their providers. Checking an order does not itself send that order to a venue.
Which markets and connections can I use?
Built-in trading connections include Interactive Brokers (TWS / IB Gateway), Binance, Alpaca and eToro. Price-source adapters include Interactive Brokers, Binance, Kraken, Coinbase, Alpaca, OKX, Bybit, OANDA and Finnhub, plus a custom source. Check each connection's supported instruments, data entitlements and paper or live modes. A price-source adapter does not itself provide order execution.
Can Officer obtain market prices automatically?
Yes. Configure a source and subscribe to instruments in the panel. Officer receives prices automatically and supplies them to OpenPit for risk checks. Inspect quote timestamps, source status and diagnostics from the panel. Provider credentials, data entitlements and the subscriptions you configure determine which prices are available.
Does Officer send orders?
Yes. Officer sends approved orders through the built-in trading connections you enable and receives execution updates into its accounting. You configure the provider, credentials and destination. You can also use Officer only for risk decisions and keep execution in your own system; evaluating an order and sending it are separate actions.
How does it relate to OpenPit?
OpenPit is the risk engine. Officer adds the local database, operator panel, REST API and MCP surface around it. Reproducible evaluation requires the same complete engine inputs and state, including market data and reservations.
Can an AI agent bypass my limits?
The default MCP surface is read-only; mutating tools require operator opt-in. Account block and unblock are not exposed over MCP. An external executor must enforce Officer's signed acceptances, and an agent must not have an alternative route to the broker if you want that gate to be mandatory. Tool permissions are not a defense against every misuse of granted access.
How do I start, and can I expose it on a network?
Install Docker, start Officer with the single quickstart command and open http://127.0.0.1:8787. REST, HTTP MCP and the API reference use the same service. The endpoints have no built-in authentication; keep the service local unless you provide an access boundary.
What does an approval signature guarantee?
With signing enabled, pre-trade accept and reject decisions carry an Ed25519 signature. An unsigned mode also exists; a signature is not guaranteed for every API error. The executor must verify the signature, the acceptance decision and the bound order parameters. Reservations are not released by a timer; their lifecycle is completed through the applicable confirmation, execution-report or cancellation flow.