Sign In

Niche Intelligence Dashboard

Create an account

psolution
KDP Niche Intelligence

Know the niche will sell — before you write it.

psolution is the Niche Intelligence Dashboard for self-publishers: score any book idea against live Amazon demand and competition, dig through 48 research sources, then take a validated niche all the way to outline and launch plan in one workspace.

Free tier included · Premium is $19/mo · No credit card to start

Weekly low-competition niche picks. No spam, unsubscribe anytime.

48research sources per niche
$19per month, everything unlocked
4 stepsvalidate → research → write → launch
Freelibrary browsing to start

How it works

Four steps from fuzzy idea to launch day — the boring, repeatable path that actually ships books.

1

Validate

Score any niche on the Mastering-KDP-in-2025 rubric: demand, competition, pricing. PASS, CONDITIONAL or AVOID — with the numbers behind it.

2

Research

Pull 48-source deep reports, competitor analysis and keyword maps. Everything lands in your Research Vault, searchable later.

3

Write

Turn the niche into a structured outline, then draft chapters in the Author Studio with AI copyediting built in.

4

Launch

A launch plan plus a pipeline board for the full funnel: keywords, categories, pricing and promotion checklists.

Everything in one workspace

Point tools make you stitch five tabs together. psolution bundles the whole workflow.

Niche Library

A pre-scored corpus of KDP niches with verdicts, competition levels and keyword angles — filter and shortlist in seconds.

Live Validation

Run a full rubric check with live market signals. Premium turns a hunch into a documented go/no-go.

Deep Research & Omni Search

48 sources per query with citations — competition, pricing and reader demand, synthesized into one brief.

Research Vault

Save every report, brief and capture. Your research compounds instead of evaporating in browser tabs.

Author Studio

Outline → chapters → copyedit with chat history per book. From validated niche to manuscript without leaving the app.

Playbook & Pipeline

Launch checklists and a kanban funnel so book two, three and ten reuse what worked the first time.

Simple pricing

Start free. Upgrade the moment live data pays for itself.

Free

$0/forever

  • Browse the scored Niche Library
  • Manual validations
  • Picks, Memory and Playbook
  • Export niches as JSON / CSV

FAQ

What exactly is psolution?

A Niche Intelligence Dashboard for Amazon KDP. It validates book ideas against demand and competition, runs deep research, and turns a validated niche into an outline and launch plan — one workspace instead of five browser tabs.

Is there really a free plan?

Yes. Browse the scored niche library, run manual validations, and keep your picks and playbook for free. Premium ($19/mo) unlocks live validation, market updates, unlimited deep research and AI authoring.

Where does the data come from?

Public Amazon market signals plus 48 research sources per deep query, synthesized with citations. Your picks and research stay private to your account.

Can I cancel anytime?

Yes — cancel from the billing portal whenever you like. Premium stays active until the end of the paid period, and your data remains yours.

How do I reach a human?

Email psolutioncred@gmail.com — we reply within one business day.

Stop guessing. Validate.

Your next book is either a data-backed bet or an expensive hunch.

Niche Intelligence Dashboard

Mastering KDP in 2025 — validate before you write.

Market Intelligence ▾

Competition Mix

Best Categories (PASS niches)

Recent Validations

Export

Export your niches, picks, or memory as JSON or CSV.

NicheScoreVerdictCompetition

Quick Niche Validation

Red-Light Scanner

Live Market Check

Manual Validation (book protocol) ▾

ROI Calculator ▾

My Publication Pipeline

Add to Memory

Upload a PDF to Memory

Stored Memory

Validation History

Author Studio

Plan a book from any niche or topic, write it chapter by chapter in a human-sounding style, copy-edit it, and audit the draft with local quality metrics. Uses the OpenAI API when a key is configured; otherwise runs in offline demo mode.

New Book

Series Planner

Turn a niche into a 3-book series (foundation, workbook, advanced). Uses the configured LLM; otherwise a deterministic demo plan.

Books

Book Assistant

A KDP publishing assistant with the dashboard's knowledge baked in — niches, picks, playbook rules and the book you're working on. Ask it to outline, write, or critique. With "Ground AI" on and a tool-capable backend it can call any tool and MCP server live (web/deep search, Amazon demand, MCP). Uses OpenAI when a key is configured; otherwise responds in demo mode.

Start a conversation — for example, "Draft a 30-day sobriety journal plan."

Research Vault

Upload source books (TXT / MD / PDF, text extracted locally) or save web pages into a private corpus. The vault is searched to ground chapters and assistant answers: the Author Studio "Ground with research" toggle feeds matching passages into the writing prompt, and the assistant never invents facts when research is available.

Corpus Search

Ask the Vault Q&A

Ask any question about the books you uploaded. Answers are grounded strictly in your vault and cite the exact source with numbered references [1] [2] — nothing invented.

Build Authoring Brief combine sources

Combine every uploaded source on a topic into one professional, referenced brief (overview + key material + gaps). Use it as the backbone for authoring — save it back to the vault so chapters ground on it.

Web Search

Keyless DuckDuckGo lookup (or your configured provider). Results can be fetched and saved straight into the vault.

Deep Web Search beta

Multi-source research across every free engine you enabled in Setup → AI Services → Deep Search (DuckDuckGo, Wikipedia, SearXNG, free-tier Brave/Tavily/Serper keys, MCP servers). It searches, opens the top pages, and can have the active AI read and summarize them into a research brief.

Vault Contents

Every upload and web fetch is auto-analyzed the moment it lands (summary, key facts, concepts, structure, quotes) and the analysis is saved with the book so anything related to it can be recalled. View an entry for the full analysis, or run an AI deep analysis for a synthesized profile.

Keywords & Title Ideas from Research

Mining the vault for the strongest keywords and fresh title angles on a topic — great for sharpening a niche's keyword list before writing.

Omni Search everything

AI Services

Add OpenAI-compatible providers (OpenAI, Groq, Mistral, Gemini, Ollama, etc.) — pick one as the active backend for Author Studio and Book Assistant. Keys are stored locally and masked on save.

Configured Services

Tool Catalog — scrape · scan · search ▾

ToolCategoryWhat it doesFree tierStatus

Deep Search Sources ▾

Full Pipeline

validate → book → launch plan

Validate a niche, generate the book draft, and build a launch plan in one step.

or

Pipeline Board

Advanced System Diagnosis

Read-only health check of server, database, AI config and on-disk files.

Checks

Automated Test Suite

Run the full test suite in an isolated subprocess — engine, API, frontend and integrations.

Results

About KDP Niche Intelligence Dashboard

Overview

New here? Open the User Manual (PDF) — a plain-English, picture-filled guide to every feature.

The KDP Niche Intelligence Dashboard is a self-contained, offline-first research tool for Kindle Direct Publishing (KDP). It evaluates 130 curated low-content / journal niches against the scoring rubric of Mastering KDP in 2025, scores each niche out of 14, decides a verdict (PASS / CONDITIONAL / AVOID), and turns every decision into an actionable publishing roadmap. Everything runs locally in pure Python — no pip packages, no frameworks, no tracking. The niche engine, database, and playbook work 100% offline; only the optional Author Studio (OpenAI-compatible LLM) and Web Search (keyless DuckDuckGo or your own provider) make outbound calls, and only when you trigger them. Phases 1–5 complete: token counting, streaming, chapter editor, HTTPS, multi-user auth with admin panel, encrypted API keys, service worker, and 557 automated tests.

Features

  • Niche Library — browse all 130 niches with live search, category, verdict and competition filters; drill into a niche for keywords, title ideas, its full score breakdown, and a one-click live market check with per-niche history.
  • Live Market Data — one-click live Amazon checks per niche: search-result counts, average reviews, average price, and a Best Sellers Rank probe of the top result, all scored against the same rubric so a clean market can reach PASS. Choose the source with a persisted toggle — Auto (PA-API when keys are configured, else keyless), PA-API, or Keyless (Amazon autosuggest + search-page scrape). Results are cached for an hour, fetches are throttled and retried with backoff to avoid bot detection, and every check is recorded in the niche's market history.
  • Validator — type any niche or phrase. Known niches get their master-report score; brand-new ideas get a provisional score computed on the fly by the same scoring engine.
  • Red-Light Scanner — checks a keyword against the global avoid-list (saturated niches, review-farm niches, "Get Rich with YouTube" niches, generic keywords) and explains the flag.
  • Playbook — the distilled ruleset: golden rules, BSR target bands, review/search/price rules, royalty examples, content tiers, the global avoid list and a pre-publish checklist.
  • My Picks — build a publication pipeline of niches you plan to write.
  • Pipeline — the full funnel in one place. Pick a validated niche (or type a new one) and click Run Full Pipeline: it validates against the live market, creates the book draft with its keywords and title ideas, and generates a 4-phase launch & marketing plan — then tracks every pick, its books and its launch progress on one board.
  • Launch Plan Generator — one button inside a book turns the niche into a concrete 4-phase selling plan (Pre-Launch: title/cover/description keywords, categories, ARC reviews · Launch: pricing, KDP Select free runs, review velocity · Post-Launch: rank defence, listing tweaks · Scale: ads, ACOS, series). Generated by the configured LLM and grounded on live market data; a deterministic KDP-grounded plan is used offline.
  • Memory — store notes, rules, decisions and PDFs (including the master validation report) for future reference.
  • History — audit trail of every validation you run, with verdict and score.
  • Author Studio — plan a book from any niche or topic, write it chapter by chapter with an inline editor, copy-edit it, audit the draft with local quality metrics, plan a series, track the launch pipeline, and export a KDP-ready manuscript as EPUB / DOCX / PDF / HTML / MD / TXT. Uses the OpenAI API when a key is configured; otherwise runs in offline demo mode. Chapters can be streamed via SSE in real time.
  • Book Assistant — an embedded chat assistant with the dashboard's knowledge baked in (niches, picks, playbook rules and your open book). It can outline, draft, critique, or answer KDP questions. Supports SSE streaming, function-calling (the AI can call web search, market check, and MCP tools itself), and chat history that persists across page refreshes.
  • Research Vault — upload source books (TXT / MD / PDF, text extracted locally) or fetch web pages into a private corpus; auto-analysis on upload; "Ask the Vault" Q&A with numbered citations; "Authoring Brief" for multi-source briefs; and "Ground with research" so chapters and assistant answers are built only from your vetted material.
  • Deep Web Search — one query across every source you enable in Services → Deep Search Sources (keyless DuckDuckGo, DuckDuckGo AI answers, Wikipedia, public SearXNG, free-tier Brave / Tavily / Serper keys, MCP search/fetch servers, OpenAlex academic, Hacker News, Internet Archive, GitHub). It merges and dedupes results, and in Read & brief mode it opens the strongest pages and has the active AI summarize them into a research brief.
  • Omni Search — type a word or paste a URL; one query fans out to every deep-search provider, MCP server, web search, the browser-scrape chain, and optional AI synthesis. Results are merged and deduped.
  • AI Toolbox — when the active LLM supports function-calling, the Book Assistant can autonomously call any tool (web search, deep research, market check, Amazon suggest, vault search, fetch URL) and any configured MCP server.
  • SVG Cover Builder — generate a print-ready book cover as SVG directly in the browser, with customizable title, subtitle, author name, and background colour.
  • Diagnosis — a read-only health check of the whole tool with an overall HEALTHY / WATCH / NEEDS-ATTENTION verdict.
  • Testing — one-click re-run of the entire automated test suite (557 checks) with a live progress bar.
  • Multi-User Auth — PBKDF2 password hashing, secure session cookies, admin panel for user management (create, edit, deactivate, promote). Registration is closed after the first user.
  • Undo System — soft-delete with a 30-second undo toast on destructive actions.

The Scoring Model (out of 14)

ComponentPointsWhat it measures
Competition0–5Saturation of the search results, top-5 strength and differentiation headroom
Demand0–3BSR strength and sustained monthly search demand
Price0–3Ability to price at the profitable $6.99–$9.99 band with competitive review counts
Series0–3Sequencing potential — can the niche be turned into a book series

Verdicts: PASS (score ≥ 10 and no red lights), CONDITIONAL (needs an angle check before writing), AVOID (saturated, red-flagged, or below threshold).

Architecture & Tech Stack

  • Pure Python 3 standard library — no pip packages, no frameworks.
  • engine.py — scoring, validation, keyword generation, title ideas, red-light scan, provisional scoring, ROI, roadmap and the playbook ruleset.
  • market.py — live Amazon market data: PA-API v5 SigV4 signing, keyless search-page scraping, autosuggest, a Best Sellers Rank probe, short-TTL result caching, and throttled/retrying HTTP with backoff.
  • db.py — SQLite persistence (niches, books, research, users, sessions, audit, undo, market cache, migrations).
  • ai.py — LLM client + offline demo, book pipeline, token estimation, prompt sanitization, SSE streaming.
  • tools.py — AI toolbox: core tools + dynamic MCP tools, ToolRunner for function-calling.
  • research.py — text extraction, corpus search, web search, URL fetching.
  • deepsearch.py — multi-source deep search aggregation + research briefs + provider settings.
  • omnisearch.py — word-or-URL fan-out across every search/scrape/MCP source.
  • mcp.py — MCP client (stdio + HTTP) with health monitoring and process-group cleanup.
  • local_mcp.py — Local MCP service manager with watchdog and auto-restart.
  • diagnosis.py — 30+ read-only health checks.
  • manuscript.py — Manuscript assembly + KDP-ready exports (EPUB / DOCX / PDF / HTML).
  • server.py — Threaded HTTP server with session auth, audit logging, rate limiting, encrypted keys, optional HTTPS.
  • Frontend — hand-written HTML / CSS / vanilla JS (no build step). Includes service worker, SVG cover builder, virtual scrolling, drag-and-drop, inline chapter editor.

How to Use

  1. Start the server: cd app && python3 server.py — it listens on port 8765, seeds the database and admin user on first start.
  2. Open http://localhost:8765 in a browser. Log in with the admin credentials (auto-created on first run).
  3. Start on Dashboard for the headline numbers, then Niche Library to shortlist categories.
  4. Use Validator + Red-Light Scanner before committing to any new idea.
  5. Read the Playbook to internalise the rules, then add winning niches to My Picks.
  6. Feed your research into Research Vault — upload or fetch; auto-analysis runs on upload. Use Ask the Vault for Q&A with citations, or Deep Web Search + Read & brief for fresh material.
  7. In Author Studio, create a book, tick Ground with research, and generate the outline and chapters. Use the inline editor to revise any chapter.
  8. Use Omni Search for quick research across all sources, or the AI Toolbox for autonomous research.
  9. Re-verify quality from the Testing page — 557 checks run green in an isolated subprocess.

API Reference

EndpointMethodPurpose
Auth & Users
/api/auth/loginPOSTLog in: {email, password} → session cookie
/api/auth/logoutPOSTLog out: invalidates session
/api/auth/registerPOSTRegister (open by default; admin/env can close it)
/api/auth/meGETCurrent user from session cookie or API token
/api/admin/usersGET/POSTList / create users (admin only)
/api/admin/users/updatePOSTUpdate a user (admin only)
/api/admin/users/deletePOSTDeactivate a user (admin only)
Dashboard & Niches
/api/overviewGETDashboard stats, competition mix, best categories, recent runs
/api/nichesGET/POSTFull niche list (enriched) with filters; add custom niche
/api/niches/customGETCustom niche list only
/api/niches/livePOSTRun a live Amazon market check for a niche
/api/niches/live/<id>DELETEClear a niche's live verdict
/api/niches/live/historyGETMarket-check history (niche_id, limit)
/api/niches/master-updatePOSTRe-score all niches from master dataset
/api/niches/master-update/progressGETPoll master-update progress
/api/niche/<id>GETSingle niche with parsed keywords and title ideas
/api/niche/revenuePOSTRevenue estimation for a niche
/api/niche/bsr-historyPOSTBSR history with trend sparkline data
/api/categoriesGETDistinct Amazon categories
Validation & Research
/api/validatePOSTScore a query (matched or provisional)
/api/validate/manualPOSTManual BSR-based validation
/api/validate/enhancedPOSTEnhanced validation with Reddit + Trends + Book signals (8 checks)
/api/validate/enrichedGETFull enriched validation: provisional + live intelligence signals
/api/validate/liveGETLive market validation (all tools: web, autosuggest, market)
/api/niche/intelligenceGETLive intelligence report: Reddit + Trends + Book data for a query
/api/ai/booktypesGETBook type guidance: low/medium/high content + paperback formatting tips
/api/roiPOSTROI calculator
/api/roadmapPOSTWeek-by-week publishing roadmap
/api/suggestGETKeyword suggestions for the validator
/api/redlightGETRed-light scan for a keyword
/api/playbookGETThe full ruleset
/api/historyGETRecent validation runs
Memory & Picks
/api/memoryGET/POSTList / add memory entries
/api/memory/<id>DELETEDelete a memory entry (soft-delete, 30s undo)
/api/memory/pdfPOSTSave a generated PDF report into memory
/api/picksGET/POST/DELETEManage the publication pipeline
/api/undoGETList recent soft-deleted items
/api/undo/restorePOSTRestore a soft-deleted item
Author Studio & Pipeline
/api/ai/statusGETLLM configuration status
/api/ai/books / /api/ai/book/<id>GET/DELETEList / inspect / delete books
/api/ai/book/<id>/outlinePOSTRegenerate a book's outline
/api/ai/outlinePOSTCreate a book: topic + specs → chapter outline
/api/ai/chapterPOSTWrite the next unwritten chapter; ground:true injects vault research
/api/ai/copyeditPOSTCopy-edit the assembled draft
/api/ai/chatPOSTBook Assistant conversation; ground:true enables AI toolbox
/api/ai/chat/streamPOSTSSE streaming Book Assistant (real-time token streaming)
/api/ai/chat/historyGETPersisted chat messages for the current book
/api/ai/chat/history/clearPOSTClear chat history for the current book
/api/toolsGETAI toolbox: core tools + MCP servers + function-calling support
/api/ai/quality/<id>GETLocal quality report (Flesch, repetition, filler, grade A–D)
/api/ai/export/<id>GETExport book as Markdown or TXT
/api/ai/manuscript/<id>GETKDP-ready manuscript (EPUB / DOCX / PDF / HTML)
/api/ai/seriesPOSTPlan a book series
/api/ai/launch/<id>GET/POSTTrack the launch pipeline with stage notes
/api/ai/launchplan/<id>POSTGenerate a 4-phase launch & marketing plan; ground:true for live research
/api/pipelineGETPipeline board with chapter and launch-plan progress
/api/exportGETExport niches/picks/memory as JSON or CSV
/api/report/pdfGETServe the master validation PDF
/api/manual/pdfGETServe the user manual PDF
Research Vault
/api/researchGETList vault entries
/api/research/uploadPOSTUpload a source file — auto-analysed on upload
/api/research/fetchPOSTFetch a web page and store in the vault
/api/research/search?q=GETRanked corpus search with highlighted snippets
/api/research/<id>GET/DELETERead or remove a vault entry
/api/research/analyzePOSTRun analysis on a vault entry
/api/research/analyze/<id>GETRead the auto-analysis for a vault entry
/api/research/qaPOSTAsk a question grounded in the vault — numbered citations
/api/research/briefPOSTGenerate an authoring brief from multiple vault entries
/api/research/linkPOSTLink a vault entry to a book chapter
/api/research/keywordsGETExtract keywords from vault content
Web & Deep Search
/api/search/web?q=GETKeyless web search (DuckDuckGo)
/api/search/deepGET/POSTMulti-source deep search (search | research mode)
/api/search/deep/settingsGET/POSTDeep-search sources: providers, keys, MCP servers
/api/search/deep/testGETProbe one provider → OK/FAIL, hit count, latency
/api/search/deep/test-mcpGETTest an MCP server preset
/api/omnisearchGET/POSTOmni Search — word or URL fans out to every source
Market Data & Captures
/api/settings/market-sourceGET/POSTLive data source: auto | pa-api | keyless
/api/market/capturePOSTCapture an Amazon search page
/api/market/capture/browserPOSTCapture via browser automation
/api/market/capture/urlPOSTCapture any URL
/api/market/capturesGETList saved captures; ?id= for detail + stats
/api/market/captures/rawGETDownload a capture's raw page source
/api/market/captures/refinePOSTLLM-refined market presentation for a capture
/api/market/captures/deepPOSTDeep-scan: probe product pages for BSR, reviews, rating
/api/market/captures/<id>DELETEDelete a saved capture
/api/market/minePOSTNiche miner: capture → reviews → mine → validate
/api/market/cache/clearPOSTClear the in-memory market cache
Services & System
/api/servicesGET/POSTList or update configured services
/api/services/catalogGETFull catalog of available services
/api/services/catalog/addPOSTAdd a custom service
/api/services/activatePOSTActivate a service by ID
/api/services/testPOSTTest a service
/api/audit-logGETAudit trail of POST/DELETE actions
/api/schema/versionGETDatabase schema version
/api/diagnosisGETSystem health: 30+ checks with verdict
/api/tests/runPOSTLaunch the test suite in a subprocess
/api/tests/progressGETPoll test progress and per-test results
/api/debug/live-smokeGETDebug: live smoke test of key endpoints

File Map

PathRole
app/engine.pyScoring, validation and ruleset logic
app/market.pyLive Amazon data (PA-API + keyless scrape, BSR probe, cache, throttling)
app/db.pySQLite persistence (niches, books, research, users, sessions, audit, undo, market cache, migrations)
app/ai.pyLLM client + offline demo, book pipeline, token estimation, prompt sanitization, SSE streaming
app/tools.pyAI toolbox: core tools + dynamic MCP tools, ToolRunner for function-calling
app/manuscript.pyManuscript assembly + KDP-ready exports (EPUB / DOCX / PDF / HTML)
app/research.pyText extraction, corpus search, web search, URL fetching
app/deepsearch.pyMulti-source deep search aggregation + research briefs + provider settings
app/omnisearch.pyGeneric Omni Search — word-or-URL fan-out across every source
app/mcp.pyMCP client (stdio + HTTP) with health monitoring and process-group cleanup
app/local_mcp.pyLocal MCP service manager with watchdog and auto-restart
app/diagnosis.py30+ read-only health checks
app/ai_config.jsonRuntime config: AI services, API keys (encrypted), market source, deep-search settings
app/server.pyHTTP API + static serving + session auth + audit + rate limiting + optional HTTPS
app/static/index.htmlHTML shell: auth overlay, all view sections, admin panel, service worker registration
app/static/style.cssStyles: dark/light theme via CSS variables, responsive layout
app/static/app.jsFrontend logic: SPA routing, all views, inline editor, virtual scrolling, drag-and-drop, SVG cover
app/static/sw.jsService worker: static-asset caching (network-first for API)
app/tests/17 test modules: 557 checks covering engine, DB, API, AI, market, research, MCP, tools, manuscripts
niche_validation_data.pyThe 130-niche master dataset
amazon_category_map.pyCategory mapping
2026-KDP-NICHE-VALIDATION-REPORT.pdfThe master validation report

Testing & QA

The suite in app/tests/ contains 557 checks across 17 test modules, all green:

  • test_engine_db.py — scoring, validation, keyword generation, title ideas, red-light scan, revenue estimation, BSR history, configurable bands, roadmap, undo system, pick dedup, memory PDF, niche CRUD, custom niche evidence/category
  • test_api_security.py — API behaviour, auth flow, session cookies, admin user management, ID validation, CSV formula-injection, rate limiting, static containment
  • test_ai.py — AI Author Studio in demo mode: outline, chapter, copy-edit, quality, grounding, chat history, streaming, error paths, 429 retry
  • test_market.py — Amazon scrape parsing, PA-API preference, caching, throttling, BSR probing, multi-source fallback
  • test_market_settings.py — Market data source settings persistence
  • test_research.py — PDF/TXT extraction, corpus ranking, web search, URL fetching, auto-analysis, Q&A with citations
  • test_deepsearch.py — Multi-source aggregation, provider merging, research brief loop
  • test_omnisearch.py — Omni search word/URL fan-out, dedup, AI synthesis
  • test_mcp.py — MCP server presets: integrity, tool-pick mapping, stdio/http e2e, preset-mode tests
  • test_local_mcp.py — Local MCP service manager: start/stop/watchdog/process cleanup
  • test_tools.py — AI toolbox: core tools, dynamic MCP tools, ToolRunner dispatch, function-calling
  • test_diagnosis.py — System health checks: server, DB, dataset, AI config, engine probes
  • test_manuscript.py — Manuscript exports: EPUB, DOCX, PDF, HTML, MD, TXT
  • test_calibration.py — Scoring calibration
  • test_master.py — Master update pipeline
  • test_service_catalog.py — Service catalog and provider management
  • test_live_smoke.py — Live smoke test (expected skip in offline mode)

Run them anytime from the Testing page — the suite executes in an isolated subprocess so your live data is never touched, and the web/AI calls are stubbed so the run never leaves your machine.

Security & Data

  • Multi-user authentication — PBKDF2-HMAC-SHA256 password hashing (260k iterations), secure session cookies (HttpOnly, SameSite=Strict, 7-day expiry), admin-only user management. Registration is closed after the first user.
  • HTTPS — optional via self-signed certificate: set KDP_HTTPS=1 env var; cert auto-generated on first start. Requires openssl on PATH.
  • Encrypted API keys — stored with machine-derived XOR + HMAC (not plaintext in ai_config.json).
  • Rate limiting — per-endpoint rate limits, stricter for /api/ai/* endpoints.
  • Audit logging — all POST/DELETE actions logged to audit_log table with timestamp, user, action, detail.
  • Prompt sanitization — user inputs stripped of control chars, length-capped at 8k, wrapped in delimiters to prevent injection.
  • Static file containment — realpath guard prevents path traversal; malformed IDs return 400.
  • Local data only — all data in a single SQLite database; nothing leaves the machine unless you configure an outbound service.
  • Opt-in outbound calls — Web Search hits DuckDuckGo's keyless API (or your provider), Deep Search hits only sources you tick, Author Studio talks to an LLM only when a key is configured. URLs fetched server-side with scheme allowlist, size cap, no cookies/credentials.
  • Service worker — caches static assets for offline access; network-first for API ensures freshness.

Limitations & Roadmap

Resolved (Phases 1–5, 40 items):

  • Token counting, prompt sanitization, chat persistence, demo banner, toast notifications, theme toggle, DB auto-backup, configurable chapter word count, audit log, revenue estimation, BSR history, configurable BSR bands, chapter drag-and-drop reorder
  • DB migration system, market cache in SQLite, MCP health monitoring, connection pooling, Playwright retry/fallback, DB busy timeout, undo system (soft-delete + 30s restore)
  • SSE streaming chat, inline chapter editor, niche edit UI, virtual scrolling for large lists
  • HTTPS with self-signed cert, encrypted API key storage, service worker, SVG cover builder
  • Multi-user auth (PBKDF2, session cookies, admin panel, user CRUD, role-based access)

Remaining (future roadmap):

  • High priority: Niche time-series tracking (trend charts), PDF Markdown rendering, multi-provider market fallback chain
  • Medium priority: Search result caching, top-3 BSR probing, citation management, KENP manual entry
  • Low priority: Search history sidebar, ES module split of app.js, bulk operations, keyboard shortcuts, live integration test suite

Full details: INTEGRATION.md in the project root.

User Management

Manage users, roles, and permissions for your dashboard.

Add New User

All Users