IRL Gateway

io.github.macropulse-labv0.2.0更新於 Oct 6, 2026

An AI agent's trading mandate it can't break: checked before every order, reasoning sealed in IRL.

已驗證STDIO僅桌面FinanceSecurity & Monitoring

概覽

AI 產生的概覽

讓 AI 代理透過受政策檢查的閘道下現貨市價單,並封存每筆交易的理由、核對成交結果。

功能
IRL Gateway 位於 AI 代理與交易所帳戶之間。其 execute_trade 工具依授權、下單、綁定三步執行訂單:訂單在送達交易場所前先依代理的授權範圍(是否有效、名目金額上限、允許的資產與場所)檢查;代理必須說明交易理由,該理由會被雜湊並封存進防竄改的存證;之後再把授權意圖與實際成交比對,記錄為 MATCHED 或 DIVERGENT。其他工具可查詢授權範圍與本機終止開關狀態、最新價格、可用餘額、依編號查詢封存存證,以及本機近期交易日誌。IRL 無法連線或拒絕時會失敗關閉,本機終止開關檔案存在時一律拒絕交易。
適用情境
當允許助理進行交易,且你希望在訂單送出前強制執行硬性限額,並保留可驗證的授權、理由與成交紀錄時使用。預設是模擬盤,因此也適合在沒有交易所金鑰的情況下測試代理的交易行為。
執行需求
以 stdio 方式在本機執行,可從 PyPI 安裝 irl-gateway 或以 uvx 直接執行。需要一個 IRL 伺服器及在其上註冊的代理,透過 IRL_BASE_URL、IRL_API_TOKEN、IRL_AGENT_ID 與 IRL_MODEL_HASH 提供。GATEWAY_BROKER 選擇 paper(預設)或 exchange;exchange 模式還需要 EXCHANGE_API_KEY 與 EXCHANGE_API_SECRET。需要連線至 IRL 伺服器與交易場所的網路。
安裝前請注意
execute_trade 是唯一會動用資金的工具,在 exchange 模式下會用 EXCHANGE_API_KEY 與 EXCHANGE_API_SECRET 下真實訂單。IRL_API_TOKEN 是存取 IRL 伺服器的 bearer 憑證。理由原文留在本機日誌,但其雜湊與交易脈絡會傳送到 IRL 並在外部錨定。專案處於早期(0.1),僅支援現貨市價單,且不包含任何策略。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 IRL Gateway,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

IRL Gateway

Give your AI agent a trading account it can't misuse, and a record of every decision it can't rewrite.

IRL Gateway is an MCP server that sits between an AI agent (Claude, ChatGPT, or your own) and an exchange account. Every order the agent places goes through the IRL Engine:

  1. Policy before execution. IRL checks the order against the agent's mandate (active status, notional cap, allowed assets and venues) before anything reaches the exchange. Out of mandate means no order.
  2. The rationale is sealed. The agent must say why it is trading. The gateway hashes that rationale together with the trade inputs and seals the hash into IRL's tamper-evident trace, anchored daily to Bitcoin. The plaintext stays in your local journal.
  3. Intent is reconciled with the fill. After the exchange fills the order, IRL compares what was authorized with what executed and records MATCHED or DIVERGENT.

When something goes wrong, you can prove what the agent was allowed to do, what it said it was doing, and what actually happened.

AI agent ── MCP ──> irl-gateway ──> IRL: authorize (policy + sealed rationale)                         │                         ├──────> exchange: market order (client id = sealed intent)                         │                         └──────> IRL: bind fill -> MATCHED / DIVERGENT

Tools

ToolWhat it does
execute_trade(symbol, side, rationale, quantity | notional)The only tool that moves money. Spot market order through authorize → place → bind. Returns filled, denied, blocked or failed, with the IRL trace_id and verdict.
get_policy()The agent's mandate as IRL enforces it, plus the local kill-switch state.
get_quote(symbol)Last price on the gateway's venue.
get_balances()Free balances (paper or exchange).
get_trace(trace_id)IRL's sealed record of one trade.
list_recent_trades(limit)Local journal: rationale, context hash, trace id and outcome per trade.

Behaviour the agent can rely on:

  • Fail closed. If IRL is unreachable or denies the intent, no order is sent.
  • Kill switch. Create the file ~/.irl-gateway/KILL and every trade is refused before IRL is even called. Delete it to resume.
  • No silent fills. If the exchange fills but the IRL bind fails, the result still reports the fill and flags it for reconciliation.

Quick start (paper trading)

You need an IRL server and an agent registered on it. Paper trading is the default: fills are simulated at live public Binance prices, and no exchange keys are needed.

bash
pip install irl-gateway      # or run it without installing: uvx irl-gateway

Register the agent once, with its mandate:

bash
curl -X POST "$IRL_BASE_URL/irl/agents" -H "Authorization: Bearer $IRL_API_TOKEN" \  -H "Content-Type: application/json" -d '{    "name": "my-claude-trader",    "model_hash_hex": "<sha256 of your agent config>",    "max_notional": 100,    "allowed_assets": ["BTC/USDT", "ETH/USDT"],    "allowed_venues": ["paper-binance"]  }'

Then add the gateway to your MCP client, for example Claude Code or Claude Desktop:

json
{  "mcpServers": {    "irl-gateway": {      "command": "uvx",      "args": ["irl-gateway"],      "env": {        "IRL_BASE_URL": "https://irl.example.com",        "IRL_API_TOKEN": "…",        "IRL_AGENT_ID": "<agent_id from registration>",        "IRL_MODEL_HASH": "<the same model_hash_hex>",        "AGENT_MODEL_ID": "claude-opus-5-5",        "PAPER_BALANCES": "USDT=1000"      }    }  }}

Ask the agent to check get_policy, then trade.

Configuration

VariableDefaultMeaning
IRL_BASE_URL, IRL_API_TOKENrequiredIRL server and bearer token
IRL_AGENT_ID, IRL_MODEL_HASHrequiredThe registered agent and its model hash
AGENT_MODEL_IDunspecified-modelModel name sealed into each trace (the agent can override it per trade)
AGENT_CONFIG_CHECKSUMnoneOptional checksum of the agent's configuration, sealed into each trace
IRL_L2_MODEoffregime if your IRL server requires Layer 2 regime binding
GATEWAY_BROKERpaperpaper or exchange
EXCHANGE_IDbinanceAny ccxt exchange id; also the price source for paper trading
EXCHANGE_API_KEY, EXCHANGE_API_SECRETRequired for exchange
EXCHANGE_TESTNETtrueUse the exchange's testnet
PAPER_BALANCESUSDT=1000Starting paper balances (used only until paper_state.json exists; the paper account then persists across restarts)
IRL_GATEWAY_HOME~/.irl-gatewayJournal (journal.jsonl), kill switch (KILL) and paper account (paper_state.json) location

The venue IRL sees is the exchange id (binance), or paper-<exchange> for paper trading, so a mandate can allow paper trading while denying the real account.

How the rationale is sealed

For each trade the gateway builds a context of the rationale, symbol, side, quantity, reference price, venue, model id and client order id. It hashes that context as canonical JSON (sorted keys, no whitespace) with SHA-256 and sends the hash to IRL as prompt_version = "ctx-sha256:<hex>", which IRL seals into the trace's reasoning_hash.

The journal stores the full context next to its hash, so anyone holding a journal line can recompute the hash and match it to the sealed trace. IRL itself never sees the rationale's text.

Development

bash
python -m venv .venv && .venv/bin/pip install -e ".[dev]"pytest --cov=irl_gatewayruff check src tests && black --check src tests && isort --check-only src tests && mypy src

Status

Early (0.1). Spot market orders only. Paper trading and ccxt exchanges are supported; Alpaca is next. Not investment advice, and no strategy is included: the gateway controls and records what your agent does, it does not decide.

MIT licensed.

來源:README.md,提交 2cd9e0d

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.2.0最新Oct 6, 2026