What is CryptoExchange?
CryptoExchange is a self-hosted cryptocurrency trading and finance platform. Users can register, complete KYC, fund a wallet through a payment gateway or an on-chain deposit, and trade. You run the platform on your own Linux server: there is no hosted tier, and nothing sits between you and your customers’ balances.
Self-hosting means owning operations. The database, encryption keys, withdrawal queue, TLS certificate and day-to-day security are the operator’s responsibility. Read the requirements before you buy a server.
What core ships with
A fresh install includes the following platform capabilities without installing addons:
- Accounts and access control. Four seeded roles — Super Admin, Admin, Support and User — over 715 permission keys, plus API keys and account blocking.
- KYC. An application queue with configurable verification levels. Approving or rejecting an application follows one decision path and emails the applicant.
- Wallets and money movement. Spot, fiat and ecosystem wallets; deposits through 16 built-in payment providers, including Stripe, PayPal, Adyen, Paystack, Mollie and PayU; a withdrawal queue that can stay manual or switch to auto-approval; and internal transfers.
- Trading. Spot markets against a connected exchange account — Binance, KuCoin or XT through ccxt — and binary options.
- Investment plans. Plans with durations and payout tracking.
- Content and support. A blog, media library, homepage sliders, a landing-page builder and a support-ticket desk.
- Operations. Platform settings; email, SMS, push and in-app notification templates; announcements; geo restrictions; an append-only audit trail; scheduled-task monitoring; and an update checker.
Addons
Capabilities such as Ecosystem, Futures, P2P, Staking, NFT, ecommerce, MLM, Forex, copy trading and
algo-trading bots are separately licensed addons. The source documentation notes that 23 extensions are
registered in the extensions table and identifies the seed file as
backend/seeders/20240403000503-extensions.js. Addons install into the same project tree and
appear under Extensions in the admin panel.
Ecosystem and Futures addons also require ScyllaDB. It is an additional data store and is not installed for you.
How the pieces fit
A standard running deployment uses three PM2 processes over two data stores. Addons can introduce an additional store.
Frontend
Next.js 16 and React 19 on port 3000. The port is fixed in
production.config.js; setting NEXT_PUBLIC_FRONTEND_PORT does not move it. In
production, Next does not proxy /api to the backend, so the web server must do that.
Backend
Node on uWebSockets.js, port 4000 by default (NEXT_PUBLIC_BACKEND_PORT). It
speaks plain HTTP and binds every interface: TLS terminates at your proxy, and the port must be
firewalled. REST routes and all 30 WebSocket endpoints live under /api; nine sockets are
core and 21 come from addons.
Cron
The same backend build runs with CRON_MODE=only on port 4001. It serves no
traffic; never point a load balancer at it.
MySQL
Sequelize accesses MySQL, and the schema is auto-synced on boot. The installer does not install MySQL. A reachable database server and credentials are prerequisites.
Redis
Redis is required for sessions, CSRF tokens, rate limits, locks, job queues and the settings bus that keeps processes in agreement. If Redis is unreachable, the backend exits at boot rather than starting in a degraded state.
Addons
Addons contribute routes, models and menus in the same repository tree and are switched on per row in the extensions table. Ecosystem and Futures add ScyllaDB as a third data store.
Processes and runtime
The three processes are PM2 apps. Run these commands from the project root:
pnpm start
pnpm stop
pnpm restart
The installer deliberately deletes any CryptoExchange.service it finds because that unit
restarted the whole platform every ten seconds. Its closing summary may still print old
systemctl commands; ignore them.
uWebSockets.js ships prebuilt binaries for exactly three Node ABIs. On another major version, the backend
prints a boxed message and exits with code 78 rather than crash-looping. Check
node -v before debugging further.
Where to start
1. Get a working server
Start with the requirements. The installer needs root privileges, does not install MySQL and writes no web-server configuration. The source guide’s first setup topics are Requirements, Running the installer, Nginx, SSL and First boot.
2. Configure the environment
Wire up the environment file, the settings managed through the admin panel and outbound mail. If
.env is wrong, the platform may boot but be unable to take payments.
3. Learn day-to-day operations
Review the queues, apply updates without losing data, understand what a backup must cover, and know what to check when something breaks. The source documentation also points to Permissions and Processes and ports as reference topics.
Initial admin account
The source documentation says the installer seeds superadmin@example.com with password
12345678 and prints both in its summary. This account has every permission on the platform,
including the Super-Admin-only settings that control withdrawal auto-approval.
Security note: Treat these as public bootstrap defaults, not production credentials. Change the password immediately after first login and secure the Super Admin account before exposing the server.