
IRL Gateway
io.github.norve-labsv0.3.0更新於 Oct 7, 2026
An AI agent's trading mandate it can't break: checked before every order, reasoning sealed in IRL.
概覽
讓 AI 代理透過受政策檢查的閘道下現貨市價單,並把每筆交易的理由封存成防竄改紀錄。
- 功能
- IRL Gateway 位於 AI 代理與交易所帳戶之間,在訂單送到交易所之前,先依代理已註冊的授權(啟用狀態、名目金額上限、允許的資產與交易場所)進行檢查。主要工具 execute_trade 依序執行授權、下單與綁定,並回傳 filled、denied、blocked 或 failed 以及 trace id。其他工具可讀取授權與本機終止開關狀態、報價、餘額、某筆交易的封存紀錄,以及本機近期交易日誌。交易理由經雜湊後封存進 IRL 紀錄,明文只留在本機日誌中。
- 適用情境
- 當助手被允許交易,但需要受預先註冊的授權約束,並留下可驗證的紀錄——證明它被允許做什麼、聲稱在做什麼、實際成交了什麼——時適用。模擬盤模式不需要交易所金鑰,適合低風險試用。
- 執行需求
- 以 stdio 方式在本機執行,從 PyPI 安裝並用 uvx 啟動。需要 IRL_BASE_URL、IRL_AGENT_ID、IRL_MODEL_HASH 以及密鑰 IRL_API_TOKEN,並能連線到 IRL 伺服器。GATEWAY_BROKER 選擇 paper(預設)或 exchange;exchange 模式還需要 EXCHANGE_API_KEY 與 EXCHANGE_API_SECRET。僅支援桌面端。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 IRL Gateway,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
IRL Gateway
Give your AI agent a trading account it can't misuse, and a record of every decision it can't rewrite.
IRL Gateway is an MCP server that sits between an AI agent (Claude, ChatGPT, or your own) and an exchange account. Every order the agent places goes through the IRL Engine:
- Policy before execution. IRL checks the order against the agent's mandate (active status, notional cap, allowed assets and venues) before anything reaches the exchange. Out of mandate means no order.
- The rationale is sealed. The agent must say why it is trading. The gateway hashes that rationale together with the trade inputs and seals the hash into IRL's tamper-evident trace, anchored daily to Bitcoin. The plaintext stays in your local journal.
- Intent is reconciled with the fill. After the exchange fills the order, IRL compares what was authorized with what executed and records
MATCHEDorDIVERGENT.
When something goes wrong, you can prove what the agent was allowed to do, what it said it was doing, and what actually happened.
Tools
Behaviour the agent can rely on:
- Fail closed. If IRL is unreachable or denies the intent, no order is sent.
- Kill switch. Create the file
~/.irl-gateway/KILLand every trade is refused before IRL is even called. Delete it to resume. - No silent fills. If the exchange fills but the IRL bind fails, the result still reports the fill and flags it for reconciliation.
- Sealed = sent. Order sizes are rounded to the venue's step and checked against its minimums before IRL seals them, so the sealed quantity is exactly what reaches the exchange. An order the venue would reject is blocked with a plain reason instead.
Quick start (paper trading, about a minute)
That one command gets a free paper-tier token from norve.dev, registers your agent with a starter mandate (BTC/USDT and ETH/USDT, at most 1,000 USDT per order, on paper-binance), saves the credentials to ~/.irl-gateway/agent.json, and prints:
- a
claude mcp add irl-gateway ...line for Claude Code, and - an
mcpServersblock for Claude Desktop, Cursor or any MCP client.
Paste one of them, then ask the agent to call get_policy and make its first paper trade. Paper fills are simulated at live public Binance prices with Binance's real order-size rules, so no exchange keys are needed.
Options: --name, --assets BTC/USDT,SOL/USDT, --max-notional 250, --contact [email protected] (so we can reach you), --server (your own IRL engine).
Free tier limits: paper venues only, up to 3 agents and 500 authorizations a day per token. Want to trade live, or run without limits? Self-host the engine or ask for a full token.
Doing it by hand instead
Then add the gateway to your MCP client:
Configuration
The venue IRL sees is the exchange id (binance), or paper-<exchange> for paper trading, so a mandate can allow paper trading while denying the real account.
How the rationale is sealed
For each trade the gateway builds a context of the rationale, symbol, side, quantity, reference price, venue, model id and client order id. It hashes that context as canonical JSON (sorted keys, no whitespace) with SHA-256 and sends the hash to IRL as prompt_version = "ctx-sha256:<hex>", which IRL seals into the trace's reasoning_hash.
The journal stores the full context next to its hash, so anyone holding a journal line can recompute the hash and match it to the sealed trace. IRL itself never sees the rationale's text.
Development
Status
Early (0.1). Spot market orders only. Paper trading and ccxt exchanges are supported; Alpaca is next. Not investment advice, and no strategy is included: the gateway controls and records what your agent does, it does not decide.
MIT licensed.
來源:README.md,提交 2e6fd99
工具
0版本歷史
1- v0.3.0最新Oct 7, 2026


