HL-Spot — User guide
Version 1.0.0
HL-Spot is a trading bot for Hyperliquid: spot and perpetual (perp) markets, several pairs, automatic and manual orders. It runs on your own computer (Windows, Linux or Docker) and you control it from your web browser.
Website: https://hlspot.com
Download: https://github.com/Olivier1246/HL-Spot-Bot
Support: cryptohouse@cmails.eu
1. Before you start
You need:
- a computer with a 64-bit x86 processor (x86_64) running Windows or Linux, or any machine with Docker;
- a Hyperliquid account with funds (your main wallet);
- a wallet able to "sign a message" with your main wallet address. A browser extension (MetaMask, Rabby…) is the simplest: the bot opens it for you. Any other wallet works by copy and paste;
- an Internet connection.
2. Security: what you must know
- HL-Spot only accepts an API wallet key from Hyperliquid. Never enter the private key of your main wallet. An API wallet can trade for you but cannot withdraw your funds.
- The API wallet key is encrypted on your computer. It is never sent to the license server.
- Your main wallet is used only to sign messages (account creation, forgotten password, BTC address, account deletion). A signed message is not a transaction: it costs nothing and moves no funds.
- The bot's web page is protected by your password. Prefer to use it from the bot's machine (
http://localhost:60000): from another machine of your network, the page is not encrypted (see section 15).
3. Create your Hyperliquid API wallet
- Go to https://app.hyperliquid.xyz/API and connect your main wallet.
- Give the API wallet a name, then generate it.
- Copy the private key shown and keep it in a safe place: Hyperliquid shows it only once.
- Authorize the API wallet (signature with your main wallet).
- Note the expiry date of the API wallet shown by Hyperliquid.
You will enter in HL-Spot: your main wallet address (0x…) and the API wallet private key.
4. Install HL-Spot
Download the file for your system and its .sha256 file from https://github.com/Olivier1246/HL-Spot-Bot. The .sha256 file lets you check that the download is intact.
Windows
- Unzip
HL-Spot-1.0.0-prod-windows-x64.zip. - In the unzipped folder, run
HL-Spot.exe. A console window opens: keep it open while the bot runs. - Open http://localhost:60000 in your browser.
Linux (Ubuntu 22.04, 24.04, 26.04, Debian 12 or newer)
unzip HL-Spot-1.0.0-prod-linux-x64.zip
cd HL-Spot-1.0.0-prod-linux-x64
./hl-spot
Then open http://localhost:60000 in your browser.
Docker
docker load -i HL-Spot-1.0.0-prod-docker-x64.tar.gz
docker run -d --name hl-spot --restart unless-stopped -p 60000:60000 \
-e TZ=Europe/Paris -v hl-spot-data:/data hl-spot:1.0.0
-p 60000:60000is required to reach the web page.TZsets the time zone (UTC if omitted).- Your data stay in the
hl-spot-datavolume, even if the container is removed or the image updated. docker stop hl-spotstops the bot cleanly.
Then open http://localhost:60000 (or http://<machine address>:60000).
Where your data are kept
Your data (settings, encrypted key, database, log) are kept outside the program:
| System | Folder |
|---|---|
| Windows | %LOCALAPPDATA%\HL-Spot |
| Linux | ~/.local/share/hl-spot |
| Docker | the /data volume |
Reinstalling or updating the program never touches them.
5. First launch
The first page is First launch. Choose:
- Create an account if you are new;
- I already have an account if you already have an HL-Spot account (new computer, reinstallation).
Create an account
- Wallet address: your main wallet address (0x…).
- API wallet private key: the key copied in section 3. It is checked with Hyperliquid before anything else.
- Password: at least 8 characters, with an uppercase letter, a lowercase letter, a digit and a special character. It protects both your HL-Spot account and the bot's web page.
- Main wallet signature:
- Sign with my wallet: the bot opens your wallet extension; check the address and confirm the signature;
- or Get the message to sign: copy the message as is into your wallet, sign it, and paste the signature (0x…). The message is valid for 15 minutes.
- Click Create the account.
Your free trial of 7 days starts. It is granted only once per wallet and per installation. Trading starts once your Hyperliquid account is verified.
I already have an account
Enter your wallet address and your password. This installation is registered and the previous one is released (one installation change per 30 days).
6. Using the bot
The menu at the top gives access to:
| Page | Use |
|---|---|
| 📊 Dashboard | balances, market status, state of each pair |
| 📈 Statistics | spot and perp cycle results, by period |
| 🧩 Traded pairs | spot and perp pairs configured for the bot |
| 🟣 Perp cycles | entries, take-profits, stop-losses and closes of perp pairs |
| 🖐️ Manual orders | place an order by hand; the bot then follows the cycle like the others |
| 🌐 Hyperliquid pairs | list of Hyperliquid spot and perp pairs |
| ⚙️ Settings | all settings (applied without restart, except port and listening address) |
| 📝 Log | errors (and warnings if enabled) |
| 🔑 Hyperliquid account | wallet, API wallet key, expiry date |
| 📜 License | license, subscription, payment, installation, account deletion |
The bot trades only if your Hyperliquid account is verified and your license is valid. Without a valid license, only the Hyperliquid account and License pages are available.
When the bot stops trading (license ended, API wallet expired or refused), it does not touch orders and positions already open: they remain your responsibility.
7. License and subscription
Prices
| Subscription | Price |
|---|---|
| 7 days | 2 $ |
| 30 days | 6 $ |
The period paid is added to the end of your current license (or starts on the payment date if the license has ended).
How to pay
On the License page, Subscription and payment block:
- choose the subscription, the token and the network;
- the bot shows the exact amount, the receiving address and the address you must pay from. The amount is valid for 1 hour (less if the price moves by more than 10 %);
- send exactly this amount, on this network, from the wallet of your HL-Spot account;
- the payment is recognized automatically (a few minutes depending on the network) and the license is extended.
The tokens and networks offered are those shown on the License page.
Rules — read them before paying:
- pay exactly the amount requested, neither more nor less; network fees are yours;
- pay from your account's wallet (for BTC: from your declared BTC address);
- pay on the network shown, while the amount is valid;
- a payment that does not follow these rules (unknown address, different amount, other network, after the validity) is lost: no refund.
Paying in BTC
Before your first BTC payment, declare your BTC address on the License page (proof by a signature of your main wallet). The payment is recognized only if it is sent from this BTC address: in your BTC wallet, choose this address as the source of the payment ("coin control").
License checks
- The license is checked with the server every 6 hours.
- If the server cannot be reached, the bot continues until the known end date of the license.
- 24 hours before the end: warning on the web pages and by Telegram.
- After the end: 24 hours of grace (trading continues, with a warning), then trading stops.
- Do not set your computer's clock back: a clock moved back by more than 5 minutes stops trading until the next successful check.
8. API wallet: expiry and replacement
- The Hyperliquid account page shows the expiry date of your API wallet. You can enter it yourself if needed.
- During the last 7 days: banner on the web pages and a daily Telegram message.
- At the expiry date, trading stops. Create a new API wallet (section 3) and enter its key on the Hyperliquid account page: trading restarts without restarting the program.
- The new key must belong to the same main wallet: the wallet address cannot be changed.
- The bot checks with Hyperliquid at startup and every 24 hours that the API wallet still belongs to your wallet.
9. Telegram notifications
In Settings → Telegram notifications:
- create a Telegram bot with @BotFather and copy its token;
- get your chat ID (for example with @userinfobot);
- enter the token and the chat ID, then enable notifications and choose the messages (orders placed, buys filled, completed cycles, errors, daily summary).
10. Using HL-Spot on another computer
Install the bot on the new computer and choose I already have an account at first launch. The old installation is released. One change per 30 days. The License page shows the date of the next possible change.
11. Forgotten password
On the login page, click Forgot your password?. Prove that you own the wallet by a signature of your main wallet, then choose a new password.
12. Log
The 📝 Log page shows the errors recorded by the bot (and the warnings if Settings → Log file → Record warnings is enabled). The file is limited to 1 MB: the oldest entries are removed. You can filter, download the file (useful for support) and clear it.
13. Delete your account
License page, 🗑️ Delete my account: password + signature of your main wallet.
- Your HL-Spot account is deleted permanently.
- The remaining license time is lost and not refunded.
- The free trial is not granted again for this wallet.
- On this computer, the wallet address, the API wallet key and the password are erased; the trading history is kept.
14. Updates and backup
- Update: install the new version (unzip it, or load the new Docker image); your data are kept (section 4).
- Backup: copy the data folder (section 4). The
.envfile and thesecret.keyfile go together: the encrypted values of.envand of the database cannot be read withoutsecret.key. Ifsecret.keyis lost, these values (API wallet key, Telegram token…) must be entered again.
15. Access from another machine
By default the web page listens on all network interfaces, port 60000 (Settings → Web interface, applied at restart). From another machine of your network: http://<bot machine address>:60000.
On the network, the page is not encrypted: enter your API wallet key and your password preferably from the bot's machine. Never expose port 60000 directly to the Internet.
16. Support
- E-mail: cryptohouse@cmails.eu
When you contact support, attach the log file (📝 Log page → Download the file). Never send your API wallet key, your secret.key file or your password.