Server data from the Official MCP Registry
An AI agent's trading mandate it can't break: checked before every order, reasoning sealed in IRL.
About
An AI agent's trading mandate it can't break: checked before every order, reasoning sealed in IRL.
Security Report
IRL Gateway is a well-structured MCP trading server with strong security controls. Authentication is required via API tokens, input validation is comprehensive, and the architecture fails closed when the policy engine is unreachable. Minor code quality issues exist around broad exception handling and logging, but these do not materially impact security. Permissions (network HTTP, file I/O, environment variables) are appropriate for a trading gateway that must communicate with an external policy service. Supply chain analysis found 5 known vulnerabilities in dependencies (0 critical, 1 high severity). Package verification found 1 issue.
7 files analyzed · 12 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
What You'll Need
Set these up before or after installing:
Environment variable: IRL_BASE_URL
Environment variable: IRL_API_TOKEN
Environment variable: IRL_AGENT_ID
Environment variable: IRL_MODEL_HASH
Environment variable: GATEWAY_BROKER
Environment variable: PAPER_BALANCES
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-macropulse-lab-irl-gateway": {
"env": {
"IRL_AGENT_ID": "your-irl-agent-id-here",
"IRL_BASE_URL": "your-irl-base-url-here",
"IRL_API_TOKEN": "your-irl-api-token-here",
"GATEWAY_BROKER": "your-gateway-broker-here",
"IRL_MODEL_HASH": "your-irl-model-hash-here",
"PAPER_BALANCES": "your-paper-balances-here"
},
"args": [
"irl-gateway"
],
"command": "uvx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
IRL Gateway
Give your AI agent a trading account it can't misuse, and a record of every decision it can't rewrite.
IRL Gateway is an MCP server that sits between an AI agent (Claude, ChatGPT, or your own) and an exchange account. Every order the agent places goes through the IRL Engine:
- Policy before execution. IRL checks the order against the agent's mandate (active status, notional cap, allowed assets and venues) before anything reaches the exchange. Out of mandate means no order.
- The rationale is sealed. The agent must say why it is trading. The gateway hashes that rationale together with the trade inputs and seals the hash into IRL's tamper-evident trace, anchored daily to Bitcoin. The plaintext stays in your local journal.
- Intent is reconciled with the fill. After the exchange fills the order, IRL compares what was authorized with what executed and records
MATCHEDorDIVERGENT.
When something goes wrong, you can prove what the agent was allowed to do, what it said it was doing, and what actually happened.
AI agent ── MCP ──> irl-gateway ──> IRL: authorize (policy + sealed rationale)
│
├──────> exchange: market order (client id = sealed intent)
│
└──────> IRL: bind fill -> MATCHED / DIVERGENT
Tools
| Tool | What it does |
|---|---|
execute_trade(symbol, side, rationale, quantity | notional) | The only tool that moves money. Spot market order through authorize → place → bind. Returns filled, denied, blocked or failed, with the IRL trace_id and verdict. |
get_policy() | The agent's mandate as IRL enforces it, plus the local kill-switch state. |
get_quote(symbol) | Last price on the gateway's venue. |
get_balances() | Free balances (paper or exchange). |
get_trace(trace_id) | IRL's sealed record of one trade. |
list_recent_trades(limit) | Local journal: rationale, context hash, trace id and outcome per trade. |
Behaviour the agent can rely on:
- Fail closed. If IRL is unreachable or denies the intent, no order is sent.
- Kill switch. Create the file
~/.irl-gateway/KILLand every trade is refused before IRL is even called. Delete it to resume. - No silent fills. If the exchange fills but the IRL bind fails, the result still reports the fill and flags it for reconciliation.
Quick start (paper trading)
You need an IRL server and an agent registered on it. Paper trading is the default: fills are simulated at live public Binance prices, and no exchange keys are needed.
pip install irl-gateway # or run it without installing: uvx irl-gateway
Register the agent once, with its mandate:
curl -X POST "$IRL_BASE_URL/irl/agents" -H "Authorization: Bearer $IRL_API_TOKEN" \
-H "Content-Type: application/json" -d '{
"name": "my-claude-trader",
"model_hash_hex": "<sha256 of your agent config>",
"max_notional": 100,
"allowed_assets": ["BTC/USDT", "ETH/USDT"],
"allowed_venues": ["paper-binance"]
}'
Then add the gateway to your MCP client, for example Claude Code or Claude Desktop:
{
"mcpServers": {
"irl-gateway": {
"command": "uvx",
"args": ["irl-gateway"],
"env": {
"IRL_BASE_URL": "https://irl.example.com",
"IRL_API_TOKEN": "…",
"IRL_AGENT_ID": "<agent_id from registration>",
"IRL_MODEL_HASH": "<the same model_hash_hex>",
"AGENT_MODEL_ID": "claude-opus-5-5",
"PAPER_BALANCES": "USDT=1000"
}
}
}
}
Ask the agent to check get_policy, then trade.
Configuration
| Variable | Default | Meaning |
|---|---|---|
IRL_BASE_URL, IRL_API_TOKEN | required | IRL server and bearer token |
IRL_AGENT_ID, IRL_MODEL_HASH | required | The registered agent and its model hash |
AGENT_MODEL_ID | unspecified-model | Model name sealed into each trace (the agent can override it per trade) |
AGENT_CONFIG_CHECKSUM | none | Optional checksum of the agent's configuration, sealed into each trace |
IRL_L2_MODE | off | regime if your IRL server requires Layer 2 regime binding |
GATEWAY_BROKER | paper | paper or exchange |
EXCHANGE_ID | binance | Any ccxt exchange id; also the price source for paper trading |
EXCHANGE_API_KEY, EXCHANGE_API_SECRET | Required for exchange | |
EXCHANGE_TESTNET | true | Use the exchange's testnet |
PAPER_BALANCES | USDT=1000 | Starting paper balances (used only until paper_state.json exists; the paper account then persists across restarts) |
IRL_GATEWAY_HOME | ~/.irl-gateway | Journal (journal.jsonl), kill switch (KILL) and paper account (paper_state.json) location |
The venue IRL sees is the exchange id (binance), or paper-<exchange> for paper trading, so a mandate can allow paper trading while denying the real account.
How the rationale is sealed
For each trade the gateway builds a context of the rationale, symbol, side, quantity, reference price, venue, model id and client order id. It hashes that context as canonical JSON (sorted keys, no whitespace) with SHA-256 and sends the hash to IRL as prompt_version = "ctx-sha256:<hex>", which IRL seals into the trace's reasoning_hash.
The journal stores the full context next to its hash, so anyone holding a journal line can recompute the hash and match it to the sealed trace. IRL itself never sees the rationale's text.
Development
python -m venv .venv && .venv/bin/pip install -e ".[dev]"
pytest --cov=irl_gateway
ruff check src tests && black --check src tests && isort --check-only src tests && mypy src
Status
Early (0.1). Spot market orders only. Paper trading and ccxt exchanges are supported; Alpaca is next. Not investment advice, and no strategy is included: the gateway controls and records what your agent does, it does not decide.
MIT licensed.
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Worldmonitor
Freeby Koala73 · Developer Tools
Live markets, conflicts, country risk, chokepoints, energy, and China decision signals. 89 tools.
Paperclip
Freeby Paperclipai · Developer Tools
Trending hip-hop artist momentum scores across four cultural dimensions.
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
