Concepts
Organizations, modules, submodules, apps, limits, access, tokens and jobs.
Organizations
An organization is one Discord server. Almost every route is under the organization's prefix, for example /api/compute/robotics/pods. Members are the people in the server. Officers hold the officer role the organization configured. Superadmins manage every organization on the deployment.
Modules
Each feature is a module under modules/. Each module is in one category: Core, Storage, AI and agents, Webhooks, Automations, Bots or Compute. An org also subscribes to submodules: domains of content in submodules/, such as ASU (campus pages and live queries) or careers (job and hackathon feeds). Each module that is on gets its part, and a submodule's pages are crawled once for every org that subscribes. A module has its routes in api.py, its tables in models.py, and its logic in a Flask-free service.py that the REST API, the MCP server, jobs and the bot all reuse. modules/registry.py mounts them.
Core modules, such as auth, submodules and the MCP server, are always on. The other modules, such as points, storefront, calendar, LeetCode, Godfather and Feeds, switch on or off per organization. A new organization starts with each of them off. A module that is off returns 404 for that organization, and the dashboard hides it. The agent, knowledge and account modules are reached through tokens the organization issues, so an organization that issues none never uses them.
Apps
An app is the organization's own project, such as a Discord bot or an agent: a container or a pod, never a Platform process. The Hosting page deploys an app to RunPod with the organization's own key, from a manifest or a template, and rolls it back. A linked app runs outside Platform; the Hosting page lists it and Uptime checks its URL. An app reaches Platform over MCP with a token of its organization.
Limits
All organizations share the same processes and database. Each module declares limits, such as knowledge sources, pods or tool calls a minute, and each limit says who pays: the organization's own data, or a shared service it uses. Each container also has a memory and CPU cap. The superadmins see each organization's use and the server's health, and set the limits of each organization. See Limits.
Access
People sign in with Discord. Every organization route checks whether the caller is a member, an officer or a superadmin before it runs. Changes made by officers and tokens are written to the audit log.
Programs use machine tokens instead of a login. A token starts with plat_, is stored only as a hash, belongs to one organization, and carries scopes such as knowledge:read or godfather:connect. Agents, deploy pipelines and the godfather CLI each hold one.
Secrets
Per-organization credentials (a RunPod key, a Google service account, OAuth grants) are encrypted with SECRETS_KEY and stored in the database. They are never returned by the API.
Jobs
Background work is declared with @job in each module's jobs.py. On Postgres a separate worker process runs them from a Procrastinate queue. On SQLite they run in threads inside the API process. Examples are the daily LeetCode post, crawls, pod session start and stop, and token cleanup.
Processes
| Process | Entry point | Port |
|---|---|---|
| API | main.py under gunicorn | 8000 |
| Dashboard | dashboard/ (Vite, React) | 5001 |
| Web, the old officer app | web/ (Create React App) | 5000 |
| Discord bot | bot_main.py | |
| Job worker | worker_main.py | |
| MCP server | mcp_main.py | 8001 |
| Docs site | site/ (Next.js) | 3010 |