Reins
In development — not open yet

A human in the loop, for agents that trade while you sleep

Reins Cloud is the same risk engine as Reins, hosted: an agent connects to one URL with an API key, limits it cannot change hold every order, anything over a size you choose waits for your approval, and a kill switch stops it dead. It is being built in the open and is not open for sign-ups yet; what has and has not run is set out below.

What it enforces

Limits outside the model

Position cap per asset, leverage, a daily loss limit that halts trading, an asset allowlist, a rate limit, and a stop-loss required on anything that opens a position. No tool changes them, so no prompt gets past them.

Your approval on the big ones

Set a size above which an order waits for a person. The agent is told it is held, not refused, and can poll or withdraw. Requests lapse after ten minutes, and again if the price moves more than 1% while waiting, so nobody ever approves one trade and gets another.

A kill switch that stays pulled

Any key can stop the agent, including the agent itself. Turning it back on needs your login and a fresh second factor. Cancels and closes keep working while it is on, so stopping never traps a position.

Keys you can prove nobody holds

Each agent gets a Hyperliquid API wallet. In production its key is created inside a KMS and never exported, so the service can ask for a signature but cannot read the key — that path is written and tested against a stand-in, not yet against a live KMS. Testnet today uses a weaker vault: the key encrypted in the database, which live mode refuses to start on. Either way an API wallet cannot withdraw, and you can revoke one on Hyperliquid without asking us.

Told before you notice

Alerts by email, Telegram and SMS for the things that matter: an order held for approval, a limit hit, a stop fired, an agent gone quiet, a fill you did not place, the exchange unreachable.

Every attempt on the record

An append-only decision log: what the agent tried, the reason it gave in its own words, what the risk engine said, what the exchange did. Refusals and orders held for you are kept as carefully as fills.

One URL and a key

Point any MCP runtime — Claude Desktop, Claude Code, Cursor, or your own loop — at the endpoint. There is nothing to install, and the same capabilities are on a plain REST API for anything that does not speak MCP.

{
  "mcpServers": {
    "reins-cloud": {
      "url": "https://cloud.r2rlabs.com/mcp",
      "headers": { "Authorization": "Bearer rc_live_agent_…" }
    }
  }
}

The agent gets market data, orders, positions, stops and its own decision log. It also gets the tools a hosted service needs that a local one does not: check whether an order would be allowed before placing it, follow an order held for your approval, and pull its own kill switch when something looks wrong.

What it costs

Paper

Free. Simulated fills on live prices, the same limits, no key and no money.

Testnet

Free. Real Hyperliquid testnet orders with test funds.

Live

2 basis points of the volume it protects, charged as a Hyperliquid builder fee on each fill. No subscription, and nothing to pay while an agent is idle.

$10,000 of volume costs $2. We are paid when your agent trades, not for watching it sit still.

Where it is, plainly

In development. It runs on one machine, has no users, and is not open for sign-ups. The engine, the dashboard, human approval, the alerts, the audit log and the MCP endpoint are built and covered by around 430 tests.

What has actually happened on an exchange: one end-to-end run on Hyperliquid testnet. A wallet signed the agent approval, Hyperliquid accepted it, an order filled with a stop resting on the exchange, and the fills reconciled against Hyperliquid's own record.

What has not: a live KMS, real email, SMS and Telegram delivery, any deployment beyond a laptop, a second user, a security audit, and mainnet. Those come before anyone is asked for money or keys.

Say if you want to hear when it opens, or run Reins yourself today — free, open source, the same risk engine, and it needs nobody's permission.