xXTrade

The bot panel goes live — and it is read-only by construction

Published · by , solo founder, Switzerland

Shipped · Editorial policy

What shipped

A panel inside the xXTrade app that shows the state of a real trading bot, and a page at /openclaw for pointing your own agent at xXTrade's read-only endpoints. It landed on 14 August 2026 in commit 98fa7cd — 22 files, about 3,100 lines, roughly 95 named tests across the two new API files.

The public view is a nine-field literal

api/bot-status.ts answers GET and nothing else. What an anonymous visitor can read is not a filtered version of the bot's snapshot; it is a separate object built by a pure function, toPublicStatus, that returns exactly nine fields:

FieldWhat it is
botId, kind, modeWhich bot, what type, and whether it is live or paper.
equity, todayPnlAccount value and the day's profit or loss.
openPositionsCount, restingOrdersCount, armedMarketsCountThree counts. Not the positions, not the orders, not the markets — the counts.
lastTickAtFreshness, so a stalled bot looks stalled.

The bot's briefing note, its guard details, its refusal reasons, its dormant-pair reasoning and its model spend are not omitted by a filter that could be edited back in later. They are absent from the return type. "The public view leaks nothing" is a property of the types and is tested without a server.

The full snapshot exists, and it opens for the owner's wallets behind an EIP-191 signature verified server-side — the same gate the visitor endpoint already used.

The chat cannot be talked into acting

api/bot-chat.ts is the one POST in the pair, and its only writes are rate-limit counters and the model call. Anything that asks the bot to do something is refused before any model call happens — the refusal is a branch in front of the provider, not an instruction inside a prompt. "Pause the bot right now" never reaches a model at all.

Bring your own agent

/openclaw ships a one-click-copy connect prompt and five versioned skill documents that teach an external agent xXTrade's real read-only endpoints, its market universe, how self-custody works here, and how wallet linking works. The page has no input element on it — not a disabled one, not a hidden one. There is nowhere to paste a key, by construction.

Nothing here takes custody of anything, and none of it places orders for you. Trading perpetual futures can lose you more than you put in; see the risk disclosure.