MMashDiv

What is in the app

The feature map of the mobile app — the bottom tabs, the Home screen and its Trading Tools tiles, what a customer can do in each area, which modules are core and which follow the addons you licence, the three opt-in modules, and what is never in the app and why.

10 min readUpdated 26 September 2026mobile, features, modules, navigation, addons, dashboard

The app is a client for your customers. Everything in it is something a signed-in customer does with their own account: trade, move money, verify their identity, talk to support. There are no admin screens — the app calls no /api/admin route, and staff accounts use it exactly like customers (the Home header shows a role badge when the role is not "User"). Running the platform stays on the website.

Two rules decide what any one customer sees:

  • The build decides what exists. A screen that is not compiled into the app cannot appear, whatever the server says. A default build carries everything on this page except Merchant, AI Investment and Affiliate, which need a build flag — see Merchant, AI Investment and Affiliate.
  • The server decides what is shown. After sign-in the app reads GET /api/user/modules and draws each tile, the Futures tab and the order ticket according to the server's answer for this customer. An id the server does not list is hidden. The module manifest explains every check.

There is no guest mode. Signed out, the app shows only the sign-in and registration screens — no markets, no news, no charts. That matters for store review: see App review access for the reviewer account.

Getting around

The bottom tabs

The tab bar runs along the bottom of every main screen, in this order:

  1. Home — the dashboard, described below. Always shown.
  2. Market — the market list. A market opens its chart; the chart has a full-screen button that turns the phone to landscape. The screen also opens Market News. Always shown.
  3. Trade — the spot trading screen: chart, order book, the order ticket and the customer's orders. Always shown. The order ticket inside it is what the trade module gates — see below.
  4. Futures — the futures trading screen. Shown only when the futures module is reachable for this customer.
  5. Wallet — balances ("Total Portfolio"), with Deposit, Transfer, Withdraw and History. Always shown.

So a customer sees four tabs on a platform without Futures and five with it.

The Home screen

Top to bottom:

  1. The header — "Welcome back," and the customer's name; their KYC status ("Level N • KYC Verified", or a Complete KYC button that opens identity verification); the bell, which opens the notification inbox; and the gear (settings) icon, which opens Profile. Profile is only reachable from that gear.
  2. Announcements — a slider of the active rows from System → Communication Tools → System Announcements (/admin/system/announcement). They arrive over the signed-in user WebSocket, so if that socket cannot connect through your proxy the slider stays empty.
  3. Market Overview — total volume, average change, gainers and losers.
  4. Trading Tools — the row of tiles below.
  5. Trading pairs — Gainers, Losers and Volume lists.
  6. Market News — a card previewing trending headlines. It is drawn even when the rest of the dashboard failed to load.

The Trading Tools tiles

Tile Subtitle / badge Module Opens
P2P Trading Trade with peers / 24/7 p2p The P2P home: marketplace, offer details, create an offer, Smart match, My Trades, order chat, blocked people
Futures Leverage trading / Perps futures Switches to the Futures tab
Staking Earn rewards / Locked — or Delegate on-chain / On-chain when staking runs on-chain staking Pools, pool detail and terms, positions, statements
Launchpad New projects / Early ico The ICO Hub: browse offerings, detail, My ICO Portfolio, ICO Transactions — the investor side only
Market News Headlines and sources / Live news "Crypto News", the feed from your news providers
Blog Posts from the team / Articles blog Your blog: posts, comments, and the author application
E-commerce Shop crypto / Store ecommerce The shop: categories, products, cart, checkout, orders, wishlist
Bot Console Watch and stop / Monitor hummingbot Hummingbot bots and keys: watch, stop, disable or revoke
Merchant Accept payments / Business gateway Restricted builds only
AI Investment Investment plans / Plans ai-investment Restricted builds only
Affiliate Referral programme / Referral mlm Restricted builds only

A tile is listed only when its module is reachable for this customer, and opens only when it is fully available:

  • Available: the tile is drawn normally and opens its screen.
  • The product exists but this customer may not start anything in it — identity verification missing, country unknown, or your platform is not licensed where they live: the tile is drawn dimmed, and a tap shows the reason for five seconds. It stays on the screen so that someone who already holds a P2P escrow or a futures position keeps a way to it.
  • Not installed, switched off or not licensed on your platform: the tile is absent.

When no tile is reachable the whole Trading Tools section is hidden. When the app could not read the module list at all, the section says "We couldn't check which tools are available on your account." with a Retry button.

Profile

The gear on Home opens Profile: the customer's details and profile completion, the pencil icon for Edit Profile, a sun/moon button for light and dark (see Languages and appearance), then:

  • Settings — Security, KYC Verification, Notifications, Help & Support (support tickets), and Help Centre when the faq module is available.
  • Legal — Terms of Service, Privacy Policy and Open-source Licenses (which also shows the app's version).
  • Delete Account, then Logout.

The Terms of Service and Privacy Policy text is your website's default legal pages, fetched from the server — not text inside the app.

What a customer can do

Account and security

  • Register and sign in with email and password. Continue with Google signs in an account that is already linked to Google, when you have set Google sign-in up; it never creates one. Wallet sign-in is not in the app. What your server's captcha, email-verification and Google settings change is on Sign-in methods.
  • Two-factor authentication — set it up under Profile → Security (an authenticator app, SMS or email), and answer the code at sign-in, after a password or a Google sign-in. The sign-in code screen takes a six-digit code, or, through Can't get a code? Use a recovery code, one of the account's recovery codes.
  • Password — Forgot Password? on the sign-in screen, and Change Password under Security, which signs the customer out and runs the same reset. Both work while your server's captcha provider is the built-in proof-of-work (the default) or none: the app solves the proof-of-work challenge for a reset as it does for sign-up. With Turnstile, reCAPTCHA or hCaptcha configured on the server, sign-up and password reset from the app are refused, and the app tells the customer to do them on the website: the app supports only the built-in proof-of-work.
  • Identity verification (KYC) — the levels you configure, with document photos taken by the camera or picked from the gallery. Reached from Complete KYC on Home, Profile → KYC Verification, or Verify identity on a locked order ticket.
  • Edit Profile — name, username, phone, address and country. The country matters: with licence attestations enforced, it is one of the two places the server reads a customer's residence from.
  • Notifications — an inbox behind the bell, and email, SMS and push preferences under Profile → Notifications. After sign-in the app asks once per install, with its own Stay informed sheet ahead of the phone's prompt, whether to turn notifications on. A customer who agrees receives push notifications without turning anything else on, unless they have switched push off in their preferences, provided you have set up Firebase in the app and on the server — see Push notifications.
  • Delete Account — in the app, confirmed with the current password. It lists what is removed and what is kept, refuses while orders are open, and asks the customer to acknowledge any balance they are giving up. Accounts created on the website with Google have no password, so they cannot finish it in the app; they have to ask your support team to close the account. Your website's public /account-deletion page sends anyone who cannot use the app to support as well, though it does not mention password-less accounts.

Money

  • Wallet — balances across the customer's wallets.
  • Deposit — "Deposit Funds" asks for the wallet type first. Fiat options are hidden while the Fiat Wallets setting is off.
  • Withdraw — including the two-factor step when your server asks for one on withdrawals.
  • Transfer — Between My Wallets, or Send to Another User by their user ID.
  • History — "Transaction History" and "Transaction Analytics".

Trading

  • Markets and charts — the market list, each market's chart, and a full-screen landscape chart that can carry the spot order ticket.
  • Spot trading — the order ticket on the Trade tab and on the full-screen chart, gated by the trade module.
  • Futures — its own tab, when the Futures Trading addon qualifies. A customer who may no longer open positions still sees the tab, with the order form locked and the line "Positions you already hold can still be closed."

Addons

P2P, staking, token offerings (investing only), the shop, the Bot Console and the Help Centre each follow an addon you licence — the table in the next section says which.

Two limits are set by the server rather than the app. The shop never lists a digital download to the app — the server filters them out of every list it sends. The Bot Console can watch, stop, disable and revoke, but never create a key.

Content and support

  • Market News — stories from the providers you enable under System → Communication Tools → News Providers and the ones you write under Market News (see News for where the feed comes from), reached from the Home tile, the Home news card and the Market screen.
  • Blog — your own posts, with comments. Customers can report a comment.
  • Support — Profile → Help & Support opens support tickets (create, reply, report a conversation) and a live-chat button.

Core and addon modules

The server's module list names 21 modules. A core module ships with the platform and needs no addon; an addon module needs its addon installed, switched on and licensed on your platform. The last two columns only take effect when you turn the matching enforcement on — see The module manifest.

Module Server title What the app does with it Needs KYC feature Attestation
wallet Wallet Nothing reads it: the Wallet tab is always shown Core view_wallets No
markets Markets Nothing reads it: the Market tab is always shown Core — No
trade Spot trading Gates the order ticket on the Trade tab and the full-screen chart; the tab itself is always shown Core, and Enable Spot Trading on trade Yes
account Account Nothing reads it: Profile is always reachable Core — No
support Support Nothing reads it: Help & Support is always in Profile Core — No
blog Blog Blog tile Core — No
news Market news Market News tile (the Home news card and the Market screen's news link are not gated) Core — No
p2p P2P trading P2P Trading tile P2P Trading — Yes
staking Staking Staking tile Staking; on-chain staking also needs Exchange Engine and Web3 Wallet & On-Chain Trading — Yes
ico Token offerings Launchpad tile ICO Launchpad, with its Maintenance Mode off purchase_ico Yes
ecommerce Store E-commerce tile E-commerce view_ecommerce No
futures Futures Futures tab and tile Futures Trading and Exchange Engine futures_trading Yes
faq Help centre Profile → Help Centre FAQ & Knowledge Base — No
hummingbot Bot console Bot Console tile Hummingbot Connector — No
gateway Merchant Merchant tile — restricted builds only Payment Gateway use_gateway Yes
ai-investment AI Investment AI Investment tile — restricted builds only AI Investments and the server switch invest_ai Yes
mlm Affiliate Affiliate tile — restricted builds only MLM & Affiliate System and the server switch — No
nft NFT marketplace No screen in this app NFT Marketplace — No
ecosystem Ecosystem wallets No screen reads this entry Exchange Engine — Yes
copy-trading Copy trading No screen in this app Copy Trading — Yes
ai-support Support assistant No screen in this app AI Support Agent — No

Four modules are listed for completeness, because the server answers for the website's addons as well: NFT, copy trading and the support assistant have no screens in this app, so licensing them adds nothing to it. Ecosystem (ECO) wallets appear inside the Wallet tab like any other wallet type; nothing in the app consults the ecosystem entry.

The same goes for the core entries the app does not read. A customer whose KYC level lacks view_wallets still sees the Wallet tab; what your server refuses inside it follows the other features on their level, action by action — see the note below.

With KYC feature enforcement on, the server also refuses individual actions — deposits, withdrawals, transfers, opening a support ticket, staking, P2P offers and trades, blog comments — to a customer whose level does not include the feature, even inside a module that is shown. See KYC.

The opt-in modules

Merchant, AI Investment and Affiliate are left out of a default build: the three screens are not in the app at all unless it is built with --dart-define=STORE_RESTRICTED_MODULES=true. AI Investment and Affiliate also need the server switch Allow AI Investment & MLM in the Mobile App, which is off by default. Merchant needs only the build flag. Both locks, the store rules behind them and what each combination does are on Merchant, AI Investment and Affiliate.

What is never in the app

Some web products and actions cannot be offered in a published app under Apple's or Google's rules, and no setting brings them back. The app has no screen that reaches them, and your server refuses them when a request comes from the app. A request counts as from the app when it carries the platform header with a native value such as mobile, which the app sends on every call.

The refusals are HTTP 403, and the text is written to be shown to a person:

Not in the app What the server answers the app
Binary options "Binary options trading is not available in the mobile app. Google Play prohibits it outright and Apple treats it as gambling."
Forex investment plans "Forex investment plans are not available in the mobile app. The plan result is set by an operator rather than by the market, which app-store rules on financial products do not permit."
Token launch — the ICO creator side "Launching a token is not available in the mobile app. The launch fee is charged to a platform wallet, and app-store rules bar a cryptocurrency balance from being used to unlock a feature."
The trading-strategy marketplace "Trading strategies cannot be bought or sold in the mobile app. You can still create, configure and run your own bots here."
Creating, rotating or re-scoping an API key "API keys are managed on the web. The app can disable or delete a key and stop a running bot, but a new key and its secret are only ever issued in a browser. Sign in on the web to create, rotate or re-scope one."
Buying a digital download in the shop "“” is a digital download and cannot be purchased in the mobile app. Physical items are unaffected." — and "Digital downloads are not available in the mobile app." on the download routes

The strategy-marketplace message is the server's wording; the app itself has no screens for the Algo Trading Bots addon at all.

Also absent, with no refusal needed because no module or screen exists:

  • Investment plans (the platform's core Investment feature) — a fixed return over a fixed term. It was removed from the module list, and no switch puts it back.
  • Web3 Wallet & On-Chain Trading — not in the app: it needs a WalletConnect session inside the app, and the app carries no WalletConnect SDK. For the same reason there is no wallet sign-in.
  • Algo Trading Bots, Forex & Multi-Asset Trading, AI Market Maker, MailWizard, Chart Engine and Binary Trading AI Engine — no mobile screens; several are admin-only or engines rather than screens.

None of the product refusals points the customer to the website, on purpose: an in-app pointer to somewhere the banned product is available is treated by the stores as steering. The API-key message is the one exception, because creating a key is an account-security task, not a purchase. Your website keeps every one of these products. This is a statement about one build, not about your business.

What the app deliberately does not do

  • It does not administer the platform. No admin screens, no admin routes.
  • It speaks English only, with no language picker. See Languages and appearance.
  • It has no deep links. No website link, email link or custom URL scheme opens the app; the verification and password-reset links in emails open the website.
  • It has no crash reporting or analytics. No analytics, crash or attribution SDK is included, and nothing captures errors globally. Crashes surface only in the stores' own consoles.
  • It does not enforce a minimum version. The admin has "Minimum iOS App Version" and "Minimum Android App Version" settings, but the app never reads them and sends no version to the server. Old builds keep working until their users update from the store.
  • It does not lay out for tablets. It installs on iPad and Android tablets, but only the futures screen changes its layout on a wide screen.