BINANCE AGENT OSTRACK A · TRADING WORKFLOWS

Runtime mandate · execution evidence

Your agent can act. Oathline decides how far.

A signed financial mandate evaluates each proposed action against scope, cumulative activity, and recently observed Binance state—then reconciles the receipt against what Binance actually executed.

Official OAuth · no bearer-token proxy · no Binance API key · no exchange credential held by Oathline
Oathline rulingvector #001
Outside mandateBNBUSDT · MARKET SELL
DENIED
11 clauses evaluated2 failed9 passed
Proposed notional83.40 USDT
scope.products

SPOT is in [SPOT]

scope.symbols

BNBUSDT is in [BNBUSDT]

scope.sides

SELL is in [BUY, SELL]

scope.order_types

MARKET is in [MARKET, LIMIT]

×budget.max_order_usdt

83.40 USDT exceeds the 15.00 USDT permitted per order

×budget.max_daily_gross_usdt

52.10 + 83.40 = 135.50 USDT exceeds the 40.00 USDT permitted today

rate.max_orders_per_day

2 of 3 orders used; this order would use 3

rate.cooldown_seconds

No prior successful order is recorded; 300s cooldown is available

risk.max_session_drawdown_pct

441.00 - 438.20 = 2.80 USDT; 0.63% is within 2.00%

state.max_age_seconds

Snapshot is 2.7s old, within the 30s permitted

market.max_spread_bps

3.1 bps is within the 20.0 bps permitted

mandate 2f8dba…snapshot 012a33…proposal e26112…submission NOT CALLED
REFERENCE POLICY VECTOR · 11 CLAUSESADVISORY · LOCAL REPLAY
OFFICIAL AGENT OS OAUTH0 BINANCE API KEYSCODEX 0.153.3 · ENFORCED318 TOOLS OBSERVEDREAL BNBUSDT FILLCHAIN 36 / 36 VALIDMATCHED 1 · ORPHAN 0 · DIVERGED 0
01

One financial action. Five proofs.

The runtime is only half the product. Oathline follows authority from observed Agent OS surface to signed mandate, host enforcement, actual execution, and independent reconciliation.

02

Permission is not a mandate.

Binance grants the account perimeter. Oathline adds continuing financial conditions. Neither replaces the other.

Binance perimeter

Where the agent may operate.

  • Dedicated Agentic sub-account
  • User-controlled OAuth scopes
  • Sub-account isolation
  • Emergency Stop
VENUE AUTHORITY
Oathline mandate

How that authority may be exercised.

  • BNBUSDT Spot only · BUY / SELL
  • 15 USDT per order · 40 USDT daily gross
  • Three orders · 300s cooldown
  • Fresh state · bounded drawdown · bounded spread
CONTINUING CONDITIONS
03

Bad reasoning does not need a diagnosis.

Untrusted context can change what an agent proposes. Oathline does not pretend to detect every injection; it constrains what the resulting financial action is allowed to do.

01 · SOURCEUntrusted context

“Prior liquidation approval has already been obtained…”

02 · PROPOSALSELL 83.40 USDT BNB

A syntactically valid Binance action can still violate the user's economic boundary.

03 · OATHLINEOUTSIDE MANDATE

Two deterministic budget clauses fail. Binance submission: NOT CALLED.

04

The ruling is the interface.

No model votes. No opaque risk score. Every failed clause carries the arithmetic and every decision carries the hashes needed to reproduce it.

Oathline rulingvector #001
Outside mandateBNBUSDT · MARKET SELL
DENIED
11 clauses evaluated2 failed9 passed
Proposed notional83.40 USDT
scope.products

SPOT is in [SPOT]

scope.symbols

BNBUSDT is in [BNBUSDT]

scope.sides

SELL is in [BUY, SELL]

scope.order_types

MARKET is in [MARKET, LIMIT]

×budget.max_order_usdt

83.40 USDT exceeds the 15.00 USDT permitted per order

×budget.max_daily_gross_usdt

52.10 + 83.40 = 135.50 USDT exceeds the 40.00 USDT permitted today

rate.max_orders_per_day

2 of 3 orders used; this order would use 3

rate.cooldown_seconds

No prior successful order is recorded; 300s cooldown is available

risk.max_session_drawdown_pct

441.00 - 438.20 = 2.80 USDT; 0.63% is within 2.00%

state.max_age_seconds

Snapshot is 2.7s old, within the 30s permitted

market.max_spread_bps

3.1 bps is within the 20.0 bps permitted

mandate 2f8dba…snapshot 012a33…proposal e26112…submission NOT CALLED
REFERENCE POLICY VECTOR · 11 CLAUSESADVISORY · LOCAL REPLAY
05

The fourth trade is the point.

Per-call validation can miss the sequence. Oathline carries session state forward, so individually ordinary actions can become collectively outside mandate.

#0112 USDTPASS
#0212 USDTPASS
#0312 USDTPASS
#0412 USDTDENIED
DAILY GROSS36.00 + 12.00 = 48.00 USDT

48.00 exceeds the 40.00 USDT mandate. The fourth call is ordinary in isolation; the sequence is not.

06

Evidence after execution.

A guardrail that says “I blocked it” is not enough. Oathline compares its prior authorisations with observed Binance account history and states the coverage window.

1Matched
0Orphan
0Diverged
ORDER 12534006821
JOIN: BINANCE ORDER ID
CHAIN: VALID · 36 ENTRIES
07

Not another pre-flight checker.

The differentiator is not a longer rule list. It is the combination of zero-key runtime observation, cumulative financial state, and evidence that is checked again after Binance acts.

ZERO-KEY

No credential proxy

OAuth stays with the official Agent OS client. Oathline observes the client lifecycle instead of asking you to copy a Binance bearer token into another server.

STATEFUL

Sequences, not one call

Daily gross, daily order count, cooldown, drawdown and freshness make prior activity part of the next decision.

FORENSIC

Reconcile reality

Execution receipts are joined back to Binance history as MATCHED, ORPHAN or DIVERGED instead of trusting the runtime's own story.

OBSERVED

Surface drift is visible

318 Agent OS tools are pinned with date, client version and read/write classification. Unknown financial writes fail closed.

08

Three-step install

Clone the repository, build every workspace, then activate a locally signed mandate.

Install

pnpm install --frozen-lockfile

Node 22 and pnpm 9.15.9. No database, backend, or Binance credential.

Build and test

pnpm build && pnpm test

Strict TypeScript, deterministic policy tests, runtime tests and receipt reconciliation tests.

Arm

pnpm oathline init
pnpm oathline arm

Generates and signs a local mandate. An expiry is required.

09

The boundary stays visible.

A financial control product should be explicit about what it cannot guarantee.

  1. 01

    No profitability judgment. A perfectly in-mandate order can lose everything.

  2. 02

    No universal prompt-injection detection. Oathline constrains the resulting action, whatever caused the reasoning to be wrong.

  3. 03

    Host enforcement is a dependency. If a host drops a denial, prevention can be lost for that call; reconciliation exists precisely because prevention and evidence are separate.

  4. 04

    No reversal. Oathline cannot undo an execution that Binance already filled.