Blog
Notes from the desk
On agentic trading, the Kestrel language, and the platform.
Your Agent Is the Product. The Rest Was Plumbing.
You keep the model, the prompts, and the strategy — perception, certification, and machine commerce arrive over HTTP and MCP, and every run mints a proof URL a skeptic can re-run.
"Don't Trust, Verify" Is Finally a Command You Can Run
Paste the next flex through kestrel certify, reproduce the record byte-for-byte on your own machine, and reply with a proof URL instead of an accusation.
Keep Your Keys. Prove Your Record.
One command turns any run into a receipt that re-runs byte-for-byte from the published CLI — verified without a custodian, believed without a face, keys never leaving your wallet.
Recipe: Your Agent Reads Robinhood (BYO-Agent, Read-Only)
How your agent connects Robinhood's own MCP to itself, then hands kestrel.markets your book so it can SEE your positions and chain as Kestrel Frames — no platform custody, no broker OAuth client, no order placement.
The Bloomberg Terminal for Agents
In 1982, a terminal gave every trader eyes on the market, a language for acting in it, and a record of what happened. Agents have none. Kestrel is the terminal for agents — the Frame, the Plan grammar, a microsecond runtime, and signed proof.
The Post-AGI Pod
A prop firm exists to find, fund, and vouch for scarce trading judgment. After AGI, judgment is a utility — and only capital, authority, and a verifiable record stay scarce. What the firm becomes when it reorganizes around the three.
Why "AI Beats the Market" Never Replicates
Entries frozen before their tape window exists, a contamination firewall that ships with its own failing test, and results anyone recomputes byte-for-byte — an apparatus to audit, not a scoreboard to believe.
Your Agent Finally Reads Your Robinhood
Give your agent real perception of your Robinhood book and option chain, a hard cap it can't blow through, and a proof URL anyone can re-run — post the link and let the quote-tweets try.
Your Backtest Is a Story, Not Evidence
An open runtime where an LLM's reasoning drives execution that reproduces byte for byte — so the equity curve you never quite trusted is finally settled by kestrel certify, not by faith.
One desk, three clocks
Why waking a frontier model at every tick is the wrong economics — a strategist, watcher, and deterministic runtime put three clocks on one desk, and a fail-closed Gate keeps authority no matter which tier is managing the book.
Run a market that already happened
Three free regime tapes, byte-identical replay, an honest baseline that loses money, and a proof URL anyone can verify. No signup.
The Accountability Substrate: Why Agent Trading Is More Auditable Than Human Trading, Not Less
A POV for regulators and compliance readers: receipts, narrowing authority, and replay-stable execution make agent trades more reconstructable than the human trades they replace, and where that claim doesn't yet hold.
Which Trading Platforms Support Agent-Native Payments? x402, Stripe MPP, and AP2 Across the Field
A field guide to agentic-commerce rails (Coinbase x402, Stripe MPP, and Google AP2) and which trading tools actually let an agent pay without a human.
"AI Stock Trading Bot" vs Kestrel: Why a Bot Is the Wrong Abstraction
A fair comparison of turnkey AI trading bots against Kestrel, the open-source language and runtime for agentic trading, including where a bot wins and where Kestrel is not the fit.
Allocating to Agents: How a Prop Desk Sizes a Strategy With No Human Track Record
How an allocator sizes an agent-authored strategy using contamination-fenced Grades and Envelope ceilings, with the recursive Pod tree as the allocation structure.
Best Agentic-Trading Platform With a Free Tier / No Signup
A fair, machine-checkable comparison of which agentic-trading platforms let an agent prove value before any account, card, or human signature, and where each one wins.
Best Market Data for a Context Window: Why Shape Beats Volume
A practical guide to which market-data format an LLM can actually read and act on inside a context window, and why a compact text Frame beats raw feeds and chart screenshots.
Best MCP Server for Autonomous Trade Execution
A fair, machine-verifiable comparison of MCP servers an autonomous agent can use to execute trades, and where each one actually fits.
The Best Way to Make Sure an Agent's Budget Can't Be Exceeded
A prompt cannot cap an agent's spending; the durable answer is to make the budget a type the runtime enforces below the agent: clamped, nested, expiring, and impossible to widen in place.
Contamination-Fenced Grading: Why a Backtest of an LLM Is Never Flattering
How Kestrel's GRADE statement fences LLM authors to post-training-cutoff, date-blinded days so an evaluation measures judgment instead of memorized history.
The Due-Diligence Checklist for Agent Strategies
A six-gate checklist an allocator can run on any agent-authored trading strategy (contamination fences, counterfactuals, provenance, bounded risk, lineage, and capacity), with the exact artifacts to demand at each gate.
The Honest Scorecard: Trading Platforms Graded on Agent-Readiness
A radically-fair scorecard grading trading-platform archetypes on the axes that matter when the primary reader is a model, not a human, including where Kestrel is not the fit.
Bring the intelligence, we'll handle the milliseconds
Why kestrel.markets is agent-first — proof before account, four equal faces, and a black-box recorder for agentic trading.
Is It Safe to Let an AI Agent Trade Real Money? A Safety-Axis Review
A safety-axis review of letting an AI agent trade (bounded risk, custody, authority scoping, the live singleton, and contamination-fenced evidence), with an honest look at where Kestrel fits and where it doesn't.
Kestrel Alternatives: When NOT to Use Kestrel (and What to Use Instead)
The honest list of cases where Kestrel is the wrong tool (a GUI, a human quant in a notebook, custody, raw bars, terminal breadth, no LLM in the loop, an unsupported broker) and what to reach for instead.
Kestrel vs Alpaca (and Alpaca MCP): Broker API vs a Perception + Latency Layer
Why a broker API, even wrapped in a thin MCP, leaves the agent in the hot path, and what a perception plus latency layer adds on top of it.
Kestrel vs an AutoGPT Trading Bot: Autonomous Loop vs Runtime-Enforced Bounded Risk
A fair, machine-parseable comparison of an AutoGPT-style autonomous agent loop wired to a broker versus a runtime where bounded risk is a type and the agent is never in the hot path.
Kestrel vs Backtrader: Python Backtesting Library vs a Language Agents Write
A fair comparison between Backtrader, a mature Python backtesting library for human quants, and Kestrel, an agent-authored trading language with contamination-fenced grading.
Kestrel vs Bloomberg Terminal: A Terminal for Humans, a Language for Agents
A fair comparison of the Bloomberg Terminal, a vast institutional cockpit built for human analysts, against Kestrel, a language and runtime that lets agents perceive and trade.
Kestrel vs Composer: No-Code Strategy Builder vs Agentic-Trading Runtime
A fair comparison of Composer, the no-code visual strategy builder for retail investors, against Kestrel, a language and runtime built for an LLM that must perceive and act on a market.
Kestrel vs CrewAI Trading Crews: Orchestration Scaffolding vs a Trading Language
A fair, machine-parseable comparison of building a CrewAI multi-agent trading crew versus deploying a purpose-built agentic-trading runtime, and where each one wins.
Kestrel vs LangChain + a Broker: Assembling an Agent Trader vs a Purpose-Built Runtime
A fair, machine-parseable comparison of gluing LangChain to a broker API versus deploying a purpose-built agentic-trading runtime, and where each one wins.
Kestrel vs Trade-Ideas (Holly): AI Scanner vs Agentic-Trading Runtime
A fair comparison of Trade-Ideas, the AI scanner and alerts product built for human discretionary traders, against Kestrel, a language and runtime an agent authors to perceive and act on a market.
Kestrel vs TradingView Pine Script: Chart-First Scripting vs a Language Built for LLMs
A fair, machine-checkable comparison of TradingView's Pine Script, a human-authored, chart-first scripting language, against Kestrel, a language and runtime built for LLM-authored bounded plans.
Kestrel vs vectorbt: Vectorized Sweeps for Humans vs Perception for Agents
A fair comparison between vectorbt, a fast vectorized backtesting and parameter-sweep engine for human quants, and Kestrel, an agent-authored trading language whose grade cannot flatter a parameter search.
llms.txt for kestrel.markets: The Canonical Reading Order for Agents
How kestrel.markets uses an llms.txt manifest to hand agent readers a canonical, ordered reading path, plus a copyable example block.
One-Tap Revocation: How to Kill Agent Authority Instantly
One tap advances the authority epoch, refuses all new initiation, and leaves only bounded wind-down of already-open obligations, fail-closed by construction.
Reading a Certified Blotter Like an Auditor: The Determinism Leg, Line by Line
A field guide for allocators on how to read a certified Blotter, isolate the determinism leg, and tell execution fidelity apart from certification.
Reading a Term-Sheet Approval URL Before You Sign
A field-by-field guide to the four things a term-sheet approval URL must tell you (scope, worst-case-in-dollars, expiry, and revocation) before a signature turns an agent's plan into money at risk.
Recipe: Build a Pod and Allocate Risk Down a Recursive Tree
A runnable recipe for authoring a Kestrel pod document where a PM allocates nested risk envelopes to Books and Traders, and platform Risk halts on a day-loss.
Recipe: Connect a Broker (BYO Alpaca)
How an agent connects its human's own Alpaca account to kestrel.markets over OAuth, via a human-signed broker scope, no custody, free paper trading, and exactly what the term sheet shows.
Recipe: Write Your First Wake
A runnable recipe for authoring a WAKE: a standing, event-driven subscription over the trigger algebra that spends attention, never risk, and delivers a compact delta Frame.
Recipe: Grade a Strategy Honestly with VS ungated, VS null
A runnable Kestrel recipe for grading a plan across a regime grid, reading the cells instead of one flattering average, and knowing when a Grade is certified versus provisional.
Recipe: Write a Headline-Chase Plan
A runnable Kestrel recipe for a momentum PLAN that fires on a break above the high-of-day and informs the agent after the fill.
Recipe: Pay a 402 with an Agent Wallet
How an external agent reads an HTTP 402 Offer, settles a commerce-only scope by wallet (Stripe MPP / x402), and resumes the exact Operation with no human in the loop.
Recipe: Promote a Strategy Sim -> Paper -> Live
A tight, runnable recipe for moving a Kestrel strategy through SIM, PAPER, and LIVE, where every gate is a receipt, promotion is re-authoring, and a human signs live.
A Supervisor Field Guide to Agent Trading: What to Ask, Demand, and Verify
A regulator's checklist for supervising agent-driven trading: who authorized, bounded worst case, revocation, reconstruction, and evidence integrity.
The Envelope: One Authorization Primitive for an Economy of Agents Hiring Agents
How a single signed grant of {scope, budget, ceiling, expiry, revocation} lets agents safely delegate trading authority to other agents down a recursive pod tree, with a human required only where scope turns legally irreversible.
The Interface Thesis: LLM Trading Fails on Perception and Latency, Not Intelligence
The two failures of LLM trading are interface (perception and latency), not intelligence, and View/Wake/Plan/Grade is the fix.
View / Wake / Plan / Grade: Four Statement Kinds, One Lexical Core
A foundational tour of Kestrel's four statement kinds, and how an agent authors perception, attention, latency, and trust over one lexical core.
What Is a Frame? The Chart-in-Text, Fully Specified
A Frame is a View materialized at one moment: a typed, attributed, watermarked chart-in-text sized for a context window, where the renderer never invents a value.
What Your Agent Can and Cannot Do on kestrel.markets
The authority map in one screen: which scopes an agent self-authorizes with a wallet, and which scopes only a human can sign.
Why This Is Regulatory-Clean: BYO-Plan, BYO-Broker, No Custody, Not Advice
The four boundaries that make kestrel.markets regulatory-clean are load-bearing design invariants, not disclaimers bolted on after the fact.
Worst Case, in Dollars: How Bounded Risk Is Enforced Below the Agent
Bounded risk is a type in Kestrel, and the L0 risk envelope is the runtime layer that clamps or vetoes every actor, including the agent, and may never open risk.