MCP gateway for AI agents that trade

Give your agent
a mandate.

Plug IRL into Claude, ChatGPT or your own agent. Every order is checked against the agent's mandate before it reaches the exchange, its reasoning is sealed, the fill is reconciled, and the record is anchored to Bitcoin. Free to use.

◆ Works with any MCP client ◆ Bitcoin anchored ◆ Verify offline
agent ⇄ irl-gateway (MCP)
“Check my mandate, then buy $50 of BTC and explain why.”
tool execute_trade
{
  "symbol": "BTC/USDT",
  "side": "buy",
  "notional": 50,
  "rationale": "Above its 200-day average,
     volatility near target."
}
✓ mandate checked
✓ rationale sealed
✓ order placed
✓ fill reconciled
MATCHEDtrace 038acf72… · anchored daily
DENIED DOGE/USDT is outside this agent's mandate. No order sent.
Running in public

Don't take our word for it. Watch it run.

This instance publishes its Merkle anchors in the open. Each root commits to every decision sealed in its period and is timestamped on Bitcoin. These numbers come straight from /irl/anchors.

—
decisions sealed in the published anchors
—
Merkle anchors published
—
latest anchor
The ownership gap

Your agent just made a trade you can't explain.

Brokers now let AI agents trade on your behalf, and say plainly that they don't supervise or audit them. Logs show what an agent did. They can't prove why, what it knew, or that nobody edited them afterwards.

QuestionLogs todayWith IRL
Was the agent allowed to do this?Checked by hopeMandate enforced before the order: caps, assets, venues, status
Why did it trade?Inferred after the factRationale hash sealed before execution
Which model decided?Not verifiableModel hash registered before the trade
When, exactly?One editable timestampBitemporal: decision time and record time
Did execution match the intent?Not trackedEvery fill reconciled: MATCHED or DIVERGENT
Could anyone have edited the record?Yes, whoever runs the serverNo: daily roots on Bitcoin, verifiable offline
How it works

Check. Seal. Bind. Anchor.

IRL sits between the decision and the exchange. It is not in the execution path: the agent still places its own order, but only with the id IRL sealed.

01 — CHECK & SEAL

Before the order

The agent submits its intent. IRL checks it against the mandate, then seals the snapshot: reasoning_hash = SHA-256(canonical JSON). Nothing trades until it passes.

→
02 — BIND

After the fill

The exchange returns its transaction id. IRL computes final_proof from the seal and the fill and records whether execution MATCHED the intent.

→
03 — ANCHOR

Every day

All seals roll into a Merkle root, timestamped on Bitcoin with OpenTimestamps. From then on the record is tamper-evident against everyone, including us.

trace #1042 · sealed
quantity 0.5 5.0 ← edited later
hash a3f2d9… e08b17…
→
daily Merkle root
recomputed ≠ anchored 7d04c2…
already in a Bitcoin block
TAMPER EVIDENT

Edit one byte of a sealed trace and every hash above it stops matching, while the original root is already on Bitcoin. That is the whole trust model in one loop.

Connect an agent

Three steps to an agent you can account for.

1

Give it a mandate

Register the agent once: its model hash, a notional cap, the assets and venues it may touch. Suspend it anytime.

2

Add the gateway

pip install irl-gateway (it's also in the official MCP Registry) and add it to your MCP client. Paper trading at live prices is the default.

3

Let it trade

The agent calls execute_trade with a rationale. Out of mandate means no order; in mandate means a sealed, reconciled trade.

# pip install irl-gateway   (or let uvx fetch it, as below)
# MCP client config (Claude Code, Claude Desktop, …)
{
  "mcpServers": {
    "irl-gateway": {
      "command": "uvx",
      "args": ["irl-gateway"],
      "env": {
        "IRL_BASE_URL": "https://irl.example.com",
        "IRL_AGENT_ID": "<registered agent>",
        "PAPER_BALANCES": "USDT=1000"
      }
    }
  }
}
execute_tradeThe only tool that moves money. Authorize → place → bind.
get_policyThe mandate as IRL enforces it, plus the kill switch.
get_quote · get_balancesPrice and account, paper or exchange.
get_traceIRL's sealed record of any trade.
list_recent_tradesEach rationale next to its sealed hash.
  • Fail closed. IRL unreachable or saying no means no order.
  • Kill switch. One file stops every trade before IRL is even asked.
  • No silent fills. A fill whose bind fails is reported, never hidden.
Not using MCP? Call IRL from code with the SDK →
# pip install irl-sdk   (TypeScript: npm install irl-sdk)
from irl_sdk import IRLClient, AuthorizeRequest, TradeAction, OrderType

async with IRLClient(IRL_URL, API_TOKEN, MTA_URL) as client:
    result = await client.authorize(AuthorizeRequest(
        agent_id=AGENT_ID, model_id="my-model-v1", model_hash_hex=MODEL_HASH,
        action=TradeAction.LONG, asset="BTC-USD", order_type=OrderType.MARKET,
        venue_id="coinbase", quantity=0.1, notional=6500.0, notional_currency="USD",
    ))
    if result.authorized:
        place_order(client_order_id=..., ...)  # then bind the fill
Trust model

What a closed chain proves, and what it doesn't.

IRL is a commitment scheme with independent timestamping. It doesn't make dishonesty impossible; it makes it expensive, contemporaneous and permanent. Here is the exact guarantee, stated the way an auditor will ask for it.

A MATCHED chain proves

  • Existence: this exact snapshot existed when it was sealed.
  • Integrity: no field changed after the seal.
  • Order: the seal came before execution; retro-dating is rejected.
  • Binding: this reasoning is tied to that exchange transaction.
  • Identity: the model hash was registered before the trade.
  • Independence: verifiable against Bitcoin with zero trust in us.

It does not prove

That the agent told the truth. The agent reports its own reasoning; a dishonest operator could seal a fabricated one.

Why lying still doesn't pay

  • The story must be committed before the outcome is known.
  • It must reference a model registered beforehand.
  • Any gap between sealed intent and the fill is recorded as DIVERGENT, permanently.
  • On the roadmap: capturing the snapshot inside hardware-attested enclaves (TEE).
Trust without trust

You don't have to trust us.

Export a proof bundle and hand it to an auditor, a regulator or an investor. They verify it offline, against Bitcoin, with no account and no access to our servers.

Open-source verifier. Frozen spec. Reimplement it in any language.
Zero-risk first step

Nobody puts an untested gate in front of live orders. You don't have to.

01 · SHADOW MODE

Audit everything, block nothing

With SHADOW_MODE=true every request is checked and sealed but never denied. Compare IRL's verdicts with your live behaviour, then turn enforcement on.

02 · SELF-HOST

Your alpha never leaves

One container plus PostgreSQL in your own infrastructure. Snapshots can be encrypted at rest per trace. The Bitcoin anchor publishes only a 32-byte root.

03 · PAPER FIRST

Start on simulated fills

The gateway paper-trades at live prices by default, with a persistent account, so an agent can earn trust before it touches real money.

For developers

Try it now. No signup.

Three demo agents are pre-seeded. Run a full authorize → bind flow in the interactive API, then verify the proof bundle yourself.

# POST /irl/authorize — check and seal before the order
{
  "agent_id": "00000000-0000-4000-a000-000000000001",
  "model_hash_hex": "sha256-hex-of-model",
  "action": { "Long": 1.5 },
  "asset": "BTC/USD",
  "notional": 64875.00
}
# → { "trace_id": "…", "reasoning_hash": "sha256…", "authorized": true }
Bring your own signal

Works on its own. Plugs into yours.

Optionally, IRL binds every decision to a signed view of the market, so "the model didn't know the market had turned" stops being an excuse.

MTA_MODE=none · DEFAULT

Mandates only

No external signal. Agent mandates are enforced, every decision is sealed and anchored. Nothing else to run.

MTA_MODE=external

A signed regime feed

Point IRL at any Ed25519-signed regime source, such as MacroPulse's daily feed. Each authorization is bound to the regime it saw, and replays are rejected.

RUST TRAIT · MtaClient

Your own model

Implement one trait and pass it at startup. Your model stays private; the audit chain is the same.

Built for what's coming

Auditability is becoming expected.

Supervisors are already asking how firms oversee autonomous agents. IRL produces the specific evidence each framework talks about.

FrameworkWhat it asks forWhat IRL gives you
MiFID II · RTS 6
ESMA briefing, Feb 2026
Pre-trade controls and records for algorithmic trading, explicitly including AIMandate checks before every order; sealed, timestamped records
FINRA 2026 report
Rules 3110 / 3120
Supervision of AI agents acting beyond the user's intent; tracking agent actionsPer-agent mandates, suspension, and a record of every action and its reasoning
SEC 15c3-5Pre-trade risk controls on market accessOut-of-mandate intents are refused before the exchange
EU AI Act · Art. 12Automatic event logging for high-risk AI systemsTamper-evident event logs, exportable as proof bundles

IRL produces evidence; it doesn't make you compliant on its own. Your obligations depend on who you are and where you operate.

Free & open

Free. Seriously.

An audit trail is only worth something if others trust it, and trust comes from use. So IRL is free to use, its source is open to read, and it is built in public. Verification will always be free for everyone.

Free
Public sandbox
Try the full flow in minutes. No signup.
$0
Demo agents pre-seeded
  • Authorize → bind against this instance
  • Interactive API explorer
  • Public anchor feed you can verify
Open the sandbox →
Later
Hosted for teams
When you'd rather not run it yourself.
Tell us
Shaped by early users
  • Managed IRL with retention guarantees
  • Compliance reports for auditors
  • Whatever you tell us you need
Tell us what you need →

The engine is free for any use except reselling it as a competing service, and every release becomes Apache 2.0 after two years. Want to host or embed IRL for others? Talk to us.
We'd rather have a hundred people using IRL and telling us what's broken than one invoice.

Every agent decision, provable.

Connect an agent, run it on paper, and hand anyone evidence they can verify without trusting you. Then tell us what's missing.