IRL NorveImmutable Reasoning Log · free to use
GitHub →

MCP gateway|For AI agents that trade

Give your agent
a mandate.

Plug IRL into Claude, ChatGPT or your own agent. Every order is checked against the agent's mandate before it reaches the exchange, its reasoning is sealed, the fill is bound to it, and the record is anchored on Bitcoin. Free to use.

Connect your agent →

The trade on the right is real, made by our reference agent in paper trading. Your browser can recompute every layer of it.

MCP
    Engine
    IRL · Rust · source-available
    Anchoring
    Bitcoin · OpenTimestamps
    Latest public anchor
    loading…
    This record
    Not yet verified by you
    Proof artifactDecision
    Agent metadataRecorded
    Agent ID
    Model
    Recorded (UTC)
    01 / What the agent said, turned into a fingerprintRecorded
      Context hash
      Intent: Mandate cap
      Proof state: recorded, not yet verified by youSwitch tabs to inspect each layer

      The ownership gap

      Your agent just made a trade
      you can't explain.

      Brokers now let AI agents trade on your behalf, and say plainly that they don't supervise or audit them. Logs show what an agent did. They can't prove why, what it knew, or that nobody edited them afterwards.

      QuestionLogs todayWith IRL
      Was the agent allowed to do this?Checked by hopeMandate enforced before the order
      Why did it trade?Inferred after the factRationale sealed before execution
      Which model decided?Not verifiableModel hash registered before the trade
      When, exactly?One editable timestampDecision time and record time, both kept
      Did execution match the intent?Not trackedEvery fill bound: MATCHED or DIVERGENT
      Could anyone have edited the record?Yes, whoever runs the serverNo: roots on Bitcoin, checkable offline
      Running in publicfrom the open anchor feed
      —decisions sealed in the published anchors
      —Merkle roots published
      —carry a Bitcoin timestamp receipt
      —latest anchor (UTC)

      Before anything else / Mandate

      Give it a mandate.
      Watch it say no.

      Every order is checked against the agent's mandate before it can reach the exchange. Out of mandate means no order, no matter how good the agent's reasons sound. Try to get an order past this real agent's mandate.

      Mandate · agent
      Assets
      Venues
      Cap per order
      The agent wants to placeSame rules as the engine
      1. Agent is active
      2. Venue is allowed
      3. Asset is allowed
      4. Within the cap
      ALLOWED The order may go to the exchange. Next: its reasoning is sealed.
      Try

      Try to break it

      Change one character.
      Watch exactly what breaks.

      This is the real record, and it's editable. Your browser recomputes every layer as you type and compares it with what was recorded. Swap the order id and only the binding breaks. Touch the agent's words and everything built on them does.

      Five layers, recomputed by your browserNot yet verified
      1. Claimthe agent's words + the order—Recorded
      2. Identitywhich model, with that context—Recorded
      3. Sealthe snapshot, before the order—Recorded
      4. Matchbound to the exchange fill—Recorded
      5. Anchorin a root on Bitcoin—Recorded

      SHA-256(reasoning hash ‖ order id)

      This decision in its period's Merkle tree · tap a node
      Select a node in the tree.

      Trust model

      What a closed chain proves,
      and what it doesn't.

      IRL is a commitment scheme with independent timestamping. It doesn't make dishonesty impossible; it makes it expensive, contemporaneous and permanent. Here is the exact guarantee, the way an auditor will ask for it.

      A MATCHED chain proves
      • Existence. This exact snapshot existed when it was sealed.
      • Integrity. No field changed after the seal.
      • Order. The seal came before execution; back-dating is rejected.
      • Binding. This reasoning is tied to that exchange transaction.
      • Identity. The model hash was registered before the trade.
      • Independence. Checkable against Bitcoin with zero trust in us.
      It does not prove

      That the agent told the truth.

      The agent reports its own reasoning. A dishonest operator could seal a made-up one. Lying still doesn't pay:

      • The story must be committed before the outcome is known.
      • It must reference a model registered beforehand.
      • Any gap between sealed intent and fill is recorded as DIVERGENT, permanently.

      On the roadmap: capturing the snapshot inside hardware-attested enclaves.

      You don't have to trust us. Export a proof bundle and hand it to an auditor, a regulator or an investor. They check it offline, against Bitcoin, with no account and no access to our servers.

      Zero-risk first step

      Nobody puts an untested gate
      in front of live orders.

      You don't have to. Start where nothing can go wrong, then turn enforcement on.

      01Shadow mode

      Audit everything, block nothing.

      With SHADOW_MODE=true every request is checked and sealed but never denied. Compare IRL's verdicts with your live behaviour first.

      02Self-host

      Your strategy never leaves.

      One container plus PostgreSQL in your own infrastructure. The Bitcoin anchor publishes only a 32-byte root.

      03Paper first

      Earn trust on simulated fills.

      The gateway paper-trades at live prices by default, so an agent can build a record before it touches real money.

      Fails closed. IRL unreachable or saying no means no order.
      Kill switch. One file stops every trade before IRL is even asked.
      No silent fills. A fill whose binding fails is reported, never hidden.

      Built for what's coming

      Auditability is becoming
      expected.

      Supervisors are already asking how firms oversee autonomous agents. IRL produces the specific evidence each framework talks about.

      FrameworkWhat it asks forWhat IRL gives you
      MiFID II · RTS 6ESMA briefing, Feb 2026Pre-trade controls and records for algorithmic trading, explicitly including AIMandate checks before every order; sealed, timestamped records
      FINRA 2026 reportRules 3110 / 3120Supervision of AI agents acting beyond the user's intent; tracking agent actionsPer-agent mandates, suspension, and a record of every action and its reasoning
      SEC 15c3-5Market access rulePre-trade risk controls on market accessOut-of-mandate orders are refused before the exchange
      EU AI Act · Art. 12Record-keepingAutomatic event logging for high-risk AI systemsTamper-evident event logs, exportable as proof bundles

      IRL produces evidence; it doesn't make you compliant on its own. Your obligations depend on who you are and where you operate.

      Developers

      One MCP server between your agent and the exchange.

      irl-gateway is an MCP server. Your agent calls execute_trade with its reasoning; the gateway checks the mandate, seals the reasoning, places the order and binds the fill. Paper trading by default, at live Binance prices.

      pip install irl-gateway
      uvx irl-gateway

      The six tools your agent sees

      • execute_trademoves money

        The only tool that places an order: mandate check, seal, order, bind. Returns MATCHED or DIVERGENT.

      • get_policyread

        The mandate as IRL enforces it: status, notional cap, allowed assets and venues, kill switch.

      • get_quoteread

        Last traded price for a pair on the gateway's venue.

      • get_balancesread

        Free balances on the account, paper or exchange.

      • get_traceread

        IRL's sealed record of one trade: intent, verdict and proofs.

      • list_recent_tradesread

        Recent trades from the local journal, each rationale next to its trace.

      Pricing

      Free. No access form.

      We'd rather have agents using it and telling us what breaks than a sales funnel.

      Gateway $0/ forever

      The MCP server your agent talks to.

      • MIT licensed
      • On PyPI and in the official MCP Registry
      • Six tools, from execute_trade to get_trace
      • Paper trading by default, at live Binance prices
      pip install irl-gateway →
      Engine $0/ self-hosted

      The engine that authorizes, seals, binds and anchors.

      • Source-available (FSL-1.1), Apache 2.0 after two years
      • Mandate checked before every order
      • Intent bound to the fill: MATCHED or not
      • Merkle roots anchored on Bitcoin
      Read the source →

      Accountability infrastructure

      Autonomy needs accountability.

      Build agents that can prove what they intended, why they decided it, and where they executed.

      Start on GitHub →

      Public verifier

      Verify a record or a proof bundle

      Paste this page's record, or a proof bundle exported from any IRL engine (GET /irl/attestation). Your browser recomputes every check; no server is involved, so it can't tell you what you want to hear.

      Examples, both real: (download) · (download)