IRL Gateway
OfficialEnables AI agents to trade on Binance through the IRL Gateway, executing spot market orders with policy authorization, sealed rationales, and fill reconciliation. Binance public prices are also used for paper trading by default.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@IRL GatewayCheck my mandate, then buy $50 of BTC/USDT and explain why."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
IRL Gateway
Give your AI agent a trading account it can't misuse, and a record of every decision it can't rewrite.
IRL Gateway is an MCP server that sits between an AI agent (Claude, ChatGPT, or your own) and an exchange account. Every order the agent places goes through the IRL Engine:
Policy before execution. IRL checks the order against the agent's mandate (active status, notional cap, allowed assets and venues) before anything reaches the exchange. Out of mandate means no order.
The rationale is sealed. The agent must say why it is trading. The gateway hashes that rationale together with the trade inputs and seals the hash into IRL's tamper-evident trace, anchored daily to Bitcoin. The plaintext stays in your local journal.
Intent is reconciled with the fill. After the exchange fills the order, IRL compares what was authorized with what executed and records
MATCHEDorDIVERGENT.
When something goes wrong, you can prove what the agent was allowed to do, what it said it was doing, and what actually happened.
AI agent ── MCP ──> irl-gateway ──> IRL: authorize (policy + sealed rationale)
│
├──────> exchange: market order (client id = sealed intent)
│
└──────> IRL: bind fill -> MATCHED / DIVERGENTTools
Tool | What it does |
| The only tool that moves money. Spot market order through authorize → place → bind. Returns |
| The agent's mandate as IRL enforces it, plus the local kill-switch state. |
| Last price on the gateway's venue. |
| Free balances (paper or exchange). |
| IRL's sealed record of one trade. |
| Local journal: rationale, context hash, trace id and outcome per trade. |
Behaviour the agent can rely on:
Fail closed. If IRL is unreachable or denies the intent, no order is sent.
Kill switch. Create the file
~/.irl-gateway/KILLand every trade is refused before IRL is even called. Delete it to resume.No silent fills. If the exchange fills but the IRL bind fails, the result still reports the fill and flags it for reconciliation.
Sealed = sent. Order sizes are rounded to the venue's step and checked against its minimums before IRL seals them, so the sealed quantity is exactly what reaches the exchange. An order the venue would reject is blocked with a plain reason instead.
Related MCP server: tradebox-mcp
Quick start (paper trading, about a minute)
uvx irl-gateway initThat one command gets a free paper-tier token from norve.dev, registers your agent with a starter mandate (BTC/USDT and ETH/USDT, at most 1,000 USDT per order, on paper-binance), saves the credentials to ~/.irl-gateway/agent.json, and prints:
a
claude mcp add irl-gateway ...line for Claude Code, andan
mcpServersblock for Claude Desktop, Cursor or any MCP client.
Paste one of them, then ask the agent to call get_policy and make its first paper trade. Paper fills are simulated at live public Binance prices with Binance's real order-size rules, so no exchange keys are needed.
Options: --name, --assets BTC/USDT,SOL/USDT, --max-notional 250, --contact you@example.com (so we can reach you), --server (your own IRL engine).
Free tier limits: paper venues only, up to 3 agents and 500 authorizations a day per token. Want to trade live, or run without limits? Self-host the engine or ask for a full token.
curl -X POST https://norve.dev/irl/signup -H "Content-Type: application/json" -d '{"client_name": "my-claude-trader"}'
# -> {"token": "...", "tier": "paper", ...} (shown once)
curl -X POST https://norve.dev/irl/agents -H "Authorization: Bearer $IRL_API_TOKEN" -H "Content-Type: application/json" -d '{
"name": "my-claude-trader",
"model_hash_hex": "<sha256 of your agent config>",
"max_notional": 100,
"allowed_assets": ["BTC/USDT", "ETH/USDT"],
"allowed_venues": ["paper-binance"]
}'Then add the gateway to your MCP client:
{
"mcpServers": {
"irl-gateway": {
"command": "uvx",
"args": ["irl-gateway"],
"env": {
"IRL_BASE_URL": "https://norve.dev",
"IRL_API_TOKEN": "…",
"IRL_AGENT_ID": "<agent_id from registration>",
"IRL_MODEL_HASH": "<the same model_hash_hex>",
"AGENT_MODEL_ID": "claude-opus-5-5",
"PAPER_BALANCES": "USDT=1000"
}
}
}
}Configuration
Variable | Default | Meaning |
| required | IRL server and bearer token |
| required | The registered agent and its model hash |
|
| Model name sealed into each trace (the agent can override it per trade) |
|
| Optional checksum of the agent's configuration, sealed into each trace |
|
|
|
|
|
|
|
| Any ccxt exchange id; also the price source for paper trading |
| Required for | |
|
| Use the exchange's testnet |
|
| Starting paper balances (used only until |
|
| Journal ( |
The venue IRL sees is the exchange id (binance), or paper-<exchange> for paper trading, so a mandate can allow paper trading while denying the real account.
How the rationale is sealed
For each trade the gateway builds a context of the rationale, symbol, side, quantity, reference price, venue, model id and client order id. It hashes that context as canonical JSON (sorted keys, no whitespace) with SHA-256 and sends the hash to IRL as prompt_version = "ctx-sha256:<hex>", which IRL seals into the trace's reasoning_hash.
The journal stores the full context next to its hash, so anyone holding a journal line can recompute the hash and match it to the sealed trace. IRL itself never sees the rationale's text.
Development
python -m venv .venv && .venv/bin/pip install -e ".[dev]"
pytest --cov=irl_gateway
ruff check src tests && black --check src tests && isort --check-only src tests && mypy srcStatus
Early (0.1). Spot market orders only. Paper trading and ccxt exchanges are supported; Alpaca is next. Not investment advice, and no strategy is included: the gateway controls and records what your agent does, it does not decide.
MIT licensed.
This server cannot be deployed
Maintenance
Related MCP Connectors
Place and inspect orders on your own exchange accounts from an MCP-connected agent.
Scoped agent execution. Server-side credentials, policy, budgets and verifiable receipts.
Supervised API-write gateway for AI agents with policy, human approval and execution receipts.
Agent routing, safety preflight, execution receipts, best execution and verified outcomes.
Related MCP Servers
- AlicenseNot gradedqualityFmaintenanceEnables AI agents to execute prediction-market trades through a risk-control gateway that enforces signed mandates and generates proof trails for accountability.0MIT
- AlicenseNot gradedqualityCmaintenanceEnables AI trading agents to trade safely through any broker MCP server by recording every tool call and reasoning in a local blackbox, while enforing configurable guardrails such as symbol whitelists, order size caps, rate limits, and daily-loss circuit breakers before orders reach the exchange.MIT
- AlicenseNot gradedqualityCmaintenanceEnables AI agents to propose stock, ETF, and crypto trades through Alpaca paper trading while enforcing deterministic policy rules and recording every decision in an audit trail.9 npmMIT
- FlicenseNot gradedqualityCmaintenanceEnables AI agents to trade on Binance through a governed MCP proxy that enforces configurable policies, requires a recorded rationale before orders, detects prompt injection, logs all actions in a tamper-evident audit trail, and blocks execution until a human approves.-