You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Where the key is, in every agent wallet we could check
Every line below is one claim about one product, with the URL it comes from, the words as they are written there, and the date we last read them. Nothing here is our reading of what a product does: it is what its own documentation, its published code or a public registry says.
How this page is kept
Every line is read again before each release of our packages. The date in the last column is the day it was last read, not the day it was written.
A line that no longer checks out is removed, not softened. If a product changes, the line changes with it or it goes.
We quote, we do not characterise. Where a product does something a bare private key does not, it is in the section that says so.
A name appears only with a source anyone can open. A claim we could not verify is not on this page.
Our own claims are at the bottom. They point at our documentation, not at an outside source, because they are ours to prove: the measurements behind them were run on Hyperliquid mainnet and are named there.
The key is with a company, and the agent holds a credential that makes it sign
Product
What the source says
Source
Last read
MetaMask Agent Wallet, server-wallet mode
"Keys are managed and secured server-side in a trusted execution environment (TEE), so agents can't access your main wallet. You retain self-custody."
"Google, email passwordless, and MetaMask Mobile QR are three separate methods." and "Each one loads a different wallet address, even if you use the same email across them."
The published bundle carries the host "agentic-proxy.workers.cx.metamask.io" (in dist/chunks/result-D_1AaN84.js) and the host "api.segment.io" (in dist/chunks/analytics-Dn0Jy_K1-Bqqb5NVS.js).
The provider is configured from the environment: "CDP_API_KEY_ID=your_api_key_id", "CDP_API_KEY_SECRET=your_api_key_secret", "CDP_WALLET_SECRET=your_wallet_secret".
The Hyperliquid MCP servers of the official registry
Read on 2026-09-29 with the registry's own search: ten distinct servers answer the query hyperliquid.
Server
What the source says
Source
Last read
io.github.R2Rlabs/hyperliquid-reins, the only one of the ten that places orders
Its REINS_PRIVATE_KEY variable, marked secret, is described as "Live mode: an API wallet's key, which can trade but not withdraw. Never the account's own key."
Its PAY_WALLET_KEY variable, marked secret, is described as "Optional. Private key of a funded Circle Gateway wallet, for the paid tools. Free tools need nothing."
None of dev.tesseralytics/hyperliquid-data, io.github.Br0ski777/hyperliquid-data, io.github.Br0ski777/hyperliquid-whales, io.github.Glebenjoy/hyperliquid-info-mcp, io.github.alekskram/hyperliquid-agent-gateway, io.github.junct-bot/hyperliquid-mcp, io.github.kitsune-de/hyperliquid-mcp, io.github.retampweb/pa1m-hyperliquid declares an "environmentVariables" entry holding a key: five are remote servers, three declare no variable at all.
"Our transaction simulation engine analyzes token outflow from your account and estimates the volume in USD." and "This includes token transfers, swaps, and deposits (for example, to Uniswap, Polymarket, or Hyperliquid)."
Copying a trader with MetaMask Agent Wallet, and what a plugin may do
perps-copytrade is a plugin for MetaMask Agent Wallet that copies a Hyperliquid trader. Its repository was read at commit 4307b980 (2026-09-30).
Claim
What the source says
Source
Last read
What the plugin is, and who signs it
Its README: "Copy a Hyperliquid trader's perps opens and closes onto your MetaMask agent wallet, mirrored in real time." Its skill file declares "author: metamask" in its metadata.
"Server-wallet mode is recommended for unattended daemons", then "it signs without a password prompt. In BYOK or guard mode, each mirrored order may pause for MFA/password approval, which stalls a daemon." Server-wallet mode is the one whose keys are "managed and secured server-side", in the first table of this page.
In the plugin's package.json, the command copytrade:start declares "capabilities": ["wallet-read"], and no command of the package declares "wallet-submit".
src/copytrade/executor.ts runs spawn(cmd, fullArgs, { env: process.env, stdio: ["ignore", "pipe", "pipe"] }) with the arguments "perps", "open" and, at the end, "--yes", "--json"; src/copytrade/mmBin.ts sets cmd by "re-running the same entrypoint that loaded this plugin".
The repository.url of @metamask/agent-wallet 7.0.0, published 2026-09-16, is "https://github.com/MetaMask/agentic.git"; that address and the declared homepage github.com/MetaMask/agentic-cli both answer HTTP 404.
The LICENSE file inside the published tarball: "You are granted a limited non-exclusive license to inspect and study the code in this repository. There is no associated right to reproduction granted under this license except where reproduction is necessary for inspection and study of the code."
Versions 6.0.0 to 6.2.1 of the same package remain published under MIT or Apache 2.0. Nothing of theirs is copied into ours: what we took is the shape of the command line, so that a recipe written for one reads in the other. The commands stand side by side in docs/parity-metamask.md.
What we say about ourselves
These are ours to prove, so they point at our own pages rather than at anyone else's.
The account's private key stays in Locker Vault, offline, and the computer holds only a sealed agent key that expires on its own. README.md, first three lines.
The agent key is refused by Hyperliquid for withdraw3, usdSend, spotSend, sendAsset, usdClassTransfer, approveAgent and approveBuilderFee, and accepted for vaultTransfer. Measured on Hyperliquid mainnet on 2026-09-28, one signed attempt per action. README.md, the table, and docs/security-model.md.
A stolen agent key still loses money: it can trade against an accomplice on a thin market, and it can deposit the account into someone else's vault. We say it in the same table rather than write "sign-only". docs/security-model.md.
No account, no server of ours, no telemetry: the hosts lpa reaches, and when, are listed one by one. docs/network.md.
A paper account that fills on Hyperliquid's real book with the real fees, before any key and any vault exists. README.md, "Start on paper".
Every movement of funds is a QR code signed on the phone, which is why an agent cannot make one on its own. docs/security-model.md.
A copy that runs with nobody watching signs with the agent key, which expires and cannot withdraw, under a mandate the person signed on the phone that names the trader and caps the budget; never with the account's key, and never on a server of ours. docs/security-model.md, "Live copies".
The agent's limits can be signed on the phone, bound by bound, and the guardian checks that signature before every order it opens; nothing on the computer widens them. docs/security-model.md, "The mandate".
A plugin runs in a separate process that reads its own folder only (it still knows the user name, the computer's name and its network addresses, and the install screen says so), and the guardian answers only requests carrying a token that process cannot read: starting another program is refused to it, not merely undeclared. Measured on Node 24.21.0 on 2026-09-30. docs/security-model.md, "Plugins".