
IRL Gateway
io.github.horkos-labsv0.2.1Updated Oct 6, 2026
An AI agent's trading mandate it can't break: checked before every order, reasoning sealed in IRL.
Overview
Lets an AI agent place spot market orders through a policy-checked gateway that seals each trade's rationale and reconciles fills.
- What it does
- IRL Gateway sits between an AI agent and an exchange account. Its execute_trade tool runs an order through authorize, place and bind: the order is checked against the agent's mandate (active status, notional cap, allowed assets and venues) before reaching the venue, the agent's stated rationale is hashed and sealed into a tamper-evident trace, and the authorized intent is compared with the actual fill as MATCHED or DIVERGENT. Supporting tools read the mandate and kill-switch state, quotes, balances, a sealed trace by id, and a local journal of recent trades.
- When to use it
- Use it when an assistant should be able to trade but only inside a pre-registered mandate, and when you want a verifiable record of what it was allowed to do, what it said it was doing, and what executed. Paper trading is the default, so it can be evaluated without exchange keys.
- Requirements
- Runs locally over stdio, installed from PyPI as irl-gateway or run with uvx. Needs an IRL server plus a registered agent: IRL_BASE_URL, IRL_API_TOKEN (bearer secret), IRL_AGENT_ID and IRL_MODEL_HASH are required. GATEWAY_BROKER selects paper (default) or exchange; exchange mode needs EXCHANGE_API_KEY and EXCHANGE_API_SECRET. Network access to the IRL server and the venue is required.
Installation
In SourceWeft
- Open IRL Gateway in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
IRL Gateway
Give your AI agent a trading account it can't misuse, and a record of every decision it can't rewrite.
IRL Gateway is an MCP server that sits between an AI agent (Claude, ChatGPT, or your own) and an exchange account. Every order the agent places goes through the IRL Engine:
- Policy before execution. IRL checks the order against the agent's mandate (active status, notional cap, allowed assets and venues) before anything reaches the exchange. Out of mandate means no order.
- The rationale is sealed. The agent must say why it is trading. The gateway hashes that rationale together with the trade inputs and seals the hash into IRL's tamper-evident trace, anchored daily to Bitcoin. The plaintext stays in your local journal.
- Intent is reconciled with the fill. After the exchange fills the order, IRL compares what was authorized with what executed and records
MATCHEDorDIVERGENT.
When something goes wrong, you can prove what the agent was allowed to do, what it said it was doing, and what actually happened.
Tools
Behaviour the agent can rely on:
- Fail closed. If IRL is unreachable or denies the intent, no order is sent.
- Kill switch. Create the file
~/.irl-gateway/KILLand every trade is refused before IRL is even called. Delete it to resume. - No silent fills. If the exchange fills but the IRL bind fails, the result still reports the fill and flags it for reconciliation.
Quick start (paper trading)
You need an IRL server and an agent registered on it. Paper trading is the default: fills are simulated at live public Binance prices, and no exchange keys are needed.
Register the agent once, with its mandate:
Then add the gateway to your MCP client, for example Claude Code or Claude Desktop:
Ask the agent to check get_policy, then trade.
Configuration
The venue IRL sees is the exchange id (binance), or paper-<exchange> for paper trading, so a mandate can allow paper trading while denying the real account.
How the rationale is sealed
For each trade the gateway builds a context of the rationale, symbol, side, quantity, reference price, venue, model id and client order id. It hashes that context as canonical JSON (sorted keys, no whitespace) with SHA-256 and sends the hash to IRL as prompt_version = "ctx-sha256:<hex>", which IRL seals into the trace's reasoning_hash.
The journal stores the full context next to its hash, so anyone holding a journal line can recompute the hash and match it to the sealed trace. IRL itself never sees the rationale's text.
Development
Status
Early (0.1). Spot market orders only. Paper trading and ccxt exchanges are supported; Alpaca is next. Not investment advice, and no strategy is included: the gateway controls and records what your agent does, it does not decide.
MIT licensed.
Source: README.md at commit 84461bb
Tools
0Version history
1- v0.2.1LatestOct 6, 2026


