# World Monitor runs six sites and one desktop binary from a single codebase

> World Monitor is a TypeScript situational awareness dashboard covering news, geopolitics, infrastructure and markets, with an MCP server, a REST API, a CLI and three SDKs on top. The operational story is in its configuration files: every key is optional, and the compose file will not start without three you have to generate yourself.

**koala73/worldmonitor** — Real-time global intelligence dashboard that synthesizes 500+ curated news feeds into AI briefs, with dual map engines, country instability scoring, and a finance radar.

- Repository: https://github.com/koala73/worldmonitor
- Website: https://worldmonitor.app
- Stars: 87,566 · Forks: 13,354
- Language: TypeScript
- License: not declared
- Published: 2026-08-08 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/koala73-worldmonitor

## The MCP tool list is public, and the tool calls are not

The programmatic surface is unusually wide for a dashboard, and it is split along a deliberate line. The MCP server at `https://worldmonitor.app/mcp` speaks Streamable HTTP and publishes `tools/list` publicly, with no credential. Calling anything requires authentication through an `X-WorldMonitor-Key` header or OAuth. The server also publishes its Agent Skills through the draft `io.modelcontextprotocol/skills` extension, with `skills/list`, `skills/get` and `skill://` resource reads.

Being able to enumerate tools without a key is a real convenience for discovery, and it has an obvious consequence: you can see the entire surface the project offers and call none of it. Anyone evaluating this for an integration reads the list and has to judge the shapes without executing a request.

Around the MCP server sit a REST API at `https://api.worldmonitor.app` described by an OpenAPI spec, an official CLI, and zero-dependency SDKs for Python, Ruby and Go that mirror the CLI. The CLI is a normal npm package:

```sh
npx worldmonitor tools          # run ad-hoc — list every MCP tool (no key needed)
npm install -g worldmonitor     # or install the `worldmonitor` (alias `wm`) command
worldmonitor risk IR --api-key wm_xxx
```

Note that the key is a bearer credential passed on the command line, so it lands in your shell history and in any process listing while the command runs. The repo also ships agent discovery files at `llms.txt` and a `.well-known` skills manifest, which is the current convention for making a tool findable.

## Every key in .env.example is optional, so a broken deployment looks complete

The environment example opens with a promise that will save you a debugging session and will also mislead you. It reads that all keys are optional, the dashboard works without them, and the corresponding features will be disabled.

That is the failure mode to plan around. A deployment with a typo in a key name does not crash, does not print a warning, and does not show an error badge. It shows a dashboard with holes in it, and the only way to tell a deliberately disabled panel from a broken one is to know which keys you meant to set. There is a matching security script in the repository, `security:vite-env-secrets`, which suggests the project treats accidental exposure of these values as a real risk, and the example file is careful to note that `DEV_PORT` is read at config time in `vite.config.ts` and is deliberately not `VITE_`-prefixed so it is never injected into the client bundle.

The AI summarization keys also have a ceiling worth knowing. Groq is the primary provider at 14,400 requests a day on the free tier, OpenRouter is the fallback at 50 a day, and forecast enrichment can be routed per stage through `FORECAST_LLM_*` variables whose precedence runs from combined-stage override down to critical-signal override, global forecast override and finally built-in defaults. Past those caps, briefs get thinner rather than absent.

## docker compose refuses to boot without three secrets you must generate

Self-hosting starts with two commands, and they are not optional:

```bash
cp .env.example .env        # add your API keys
docker compose up -d --build
```

The compose file then stops you. Three environment variables are declared with a required-value guard rather than a default, each carrying its own generation instruction: `UPSTASH_REDIS_REST_TOKEN`, `WM_SESSION_SECRET` and `RELAY_SHARED_SECRET`, every one of them annotated as required and to be generated with `openssl rand -hex 32`. If any is missing the stack refuses to start.

So the two files disagree in a way that is worth internalising before you deploy. `.env.example` says every key is optional and the app runs without them, which is true of `npm run dev` and false of the compose stack. Under compose you also get Redis plus an AIS relay alongside the app, a port mapping of `${WM_PORT:-3000}:8080`, and `LOCAL_API_CLOUD_FALLBACK` set to `false`, which keeps the self-hosted instance from quietly calling the hosted one. Operator keys accepted through `X-WorldMonitor-Key` come from `WORLDMONITOR_VALID_KEYS`, which is optional and therefore defaults to accepting nothing.

## The instability index covers 31 countries, and its daily move is approximate

The Country Instability Index is the feature most likely to be over-read. It provides live CII v8 scores, bands, and an approximate 24-hour movement, for 31 Tier-1 countries. Two limits are stated in the project's own summary and both matter.

First, the coverage is 31 countries. It is not a global index, so a country outside that set is not reported as stable, it is simply absent. Any conclusion of the form nothing is happening there is unsupported by this data. Second, the movement figure is described as approximate, which makes it a display aid rather than an input to an alert. If you threshold on the 24-hour delta, you are thresholding on a number the project declines to call exact.

The rest of the dashboard is broader in reach and vaguer in claim, which is the right way round. It aggregates curated news feeds across global and regional categories and synthesises them into briefs, correlates military, economic, disaster and escalation signals across streams, and runs a finance radar covering stock exchanges, commodities, crypto and a market composite. The map is dual, a 3D globe built on globe.gl and a WebGL flat map on deck.gl, sharing one map-layer catalog so the two views show the same data rather than two implementations.

## One desktop binary serves all six variants, and there is no per-variant download

Six site variants ship from this codebase: world, tech, finance, commodity, happy and energy. The support table is explicit that all of them, and every desktop binary, are built from a single codebase and released through the same process, and marks both rows Stable.

The desktop decision is the one to note. There is a Tauri 2 application for macOS, Windows and Linux, and it is one binary for every variant. You install World Monitor once and switch to tech, finance, commodity, energy or happy inside the app. The project states plainly that there is deliberately no per-variant download.

The reasoning is sound, since six near-identical builds would be six things to patch. The consequence is that you cannot hand a colleague a finance-only build, because no such artifact exists, and the application you ship is the union of all six variants rather than the one you care about. Under the hood the desktop app is Tauri 2 in Rust with a Node.js sidecar, which is a second runtime to reason about next to whatever the agent integrations need. For local development the six variants have their own scripts, `npm run dev:tech` and its five siblings, and the base setup is three commands.

## AGPL-3.0-only, with much of the correctness policy living in lint scripts

The license is `AGPL-3.0-only`, stated in `package.json` and carried as the AGPL-3.0 badge in the README. If you intend to run a modified build as a network service, that identifier is the thing to read up on, and it is worth doing so before you fork rather than after. This is not a judgement about what the licence permits, only a note that the network use clause is the reason this particular licence is common for self-hosted server software.

The more immediately interesting detail is how this codebase enforces itself. The lint surface is not one linter but a long list of single-purpose enforcement scripts: `lint:boundaries`, `lint:api-contract`, `lint:safe-html`, `lint:panel-content-writes`, `lint:safe-local-storage`, `lint:overlay-reload-policy`, `lint:rate-limit-policies`, `lint:premium-fetch`, `lint:mintlify-slugs`, `lint:public-docs` and two variants of a unicode safety check, plus `security:local-env-dumps`, `security:vite-env-secrets` and an `agent:preflight`. API contracts are expressed as Protocol Buffers with sebuf HTTP annotations rather than hand-written validation.

The consequence for a contributor is that a large part of the project's rules are not visible in the types or the tests, they are in scripts, and an unfamiliar change can fail a gate whose rule you cannot infer from the diff. There is also an `allowScripts` map in `package.json` naming exactly which dependencies may run install scripts, which is the same supply-chain instinct seen in the Docker build, where the builder stage runs `npm ci --ignore-scripts` on a node:24-alpine image pinned by digest.

## Conclusion

World Monitor suits someone who wants a single self-hosted picture across news, markets and infrastructure and plans to drive it from a script rather than a browser, because the MCP server, OpenAPI spec, CLI and three SDKs are the most finished part of the project. Two things decide it. If you need coverage outside 31 Tier-1 countries, the Country Instability Index will not give it to you, and the 24-hour movement figure is described as approximate, so do not alert on the delta. And if you self-host, read `.env.example` and `docker-compose.yml` together, because one file promises every key is optional while the other refuses to boot without three generated secrets.

## FAQ

### Is World Monitor open source?

Yes. The package is licensed AGPL-3.0-only and the full source is in the koala73/worldmonitor repository, with the deployed sites at worldmonitor.app and variants at tech, finance, commodity, happy and energy. The default branch is main and the last push was on 2026-09-29.

### How do I install World Monitor?

For local development, clone the repository, run npm install and then npm run dev, and open localhost:3000. The app runs with no environment variables, and the port can be changed with DEV_PORT in .env.local. For self-hosting the compose stack, copy .env.example to .env and run docker compose up -d --build, after supplying REDIS_TOKEN, WM_SESSION_SECRET and RELAY_SHARED_SECRET.

### What is worldmonitor?

World Monitor is a real-time situational awareness dashboard written in TypeScript. It aggregates curated news into AI-synthesized briefs, correlates military, economic, disaster and escalation signals, tracks stock exchanges, commodities, crypto and a market composite, and renders the data on both a 3D globe and a WebGL flat map from a shared layer catalog.

### Is worldmonitor.app legit?

The project publishes worldmonitor.app from the koala73/worldmonitor repository under AGPL-3.0-only, and the README marks the public deployments and the desktop binaries as Stable and built from the same release process. It also references a Pro tier, so the hosted service and the open source repository are not the same thing, and which one you are using is worth establishing before relying on either.

### world monitor vs palantir

The repository does not document a comparison with Palantir. What it describes about itself is a self-hostable dashboard: six site variants and one Tauri desktop binary from a single codebase, an MCP server whose tool list is public, a REST API with an OpenAPI spec, a CLI and Python, Ruby and Go SDKs, all under AGPL-3.0-only.

## Sources

- [Official documentation](https://worldmonitor.app)
- [Official README](https://github.com/koala73/worldmonitor#readme)
- [Project repository](https://github.com/koala73/worldmonitor)
- [Release notes](https://github.com/koala73/worldmonitor/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/koala73-worldmonitor
