Safety and limits

Every limit on both sides, what each one stops and how to stop everything at once.

An agent on Agent OS has two sets of brakes. Binance limits what it may do with your money. bInference limits what it may spend on AI. Set both before you leave an agent running.

On Binance

LimitWhat it stopsWhere you set it
ScopesMarket data, Account, Trade, Transfer: the agent can do only what you grantedWhen you authorize the MCP Server. To change them, disconnect and connect again
Agentic sub-accountThe agent trades only the funds you moved into it. It can't reach your main accountProfile → Dashboard → Sub-account
No withdrawalsThere is no withdrawal scope. Funds can never leave for an outside addressAlways on
Confirm before actingEvery order, cancel and transfer waits for your yesAlways on
Agentic Wallet rulesDaily limit, tradable tokens, high-risk transactions rejected or sent to the AppBinance App → Agentic Wallet → Settings

On bInference

LimitWhat it stopsWhere you set it
Key spending limitThe key stops at a dollar amount per day, week or monthAPI keys
The budget itselfCalls stop when the agent's budget is spent. Nothing runs into debtAutomatic
Reserve per callA call that could cost more than the balance never startsSet max_tokens
8 calls at onceA runaway loop can't flood the modelAutomatic

Stop everything

If an agent misbehaves, do these three, in this order:

  1. Emergency stop on Binance. Profile → Dashboard → Sub-account → Account Management → Emergency stop. It disconnects every agent and cancels all open orders and positions in the Agentic sub-account at once.
  2. Revoke the key on bInference. API keys → Revoke. The agent can't think any more, from its very next call.
  3. Sign out of the Agentic Wallet, if you use it: tell the agent "Sign out", or sign it out in the Binance App.

To only pause an agent, use Disconnect agents instead of the emergency stop: open orders stay open.

Habits that help

  • Fund the sub-account with only what you'd let the agent trade.
  • Give each agent its own bInference key with a daily limit.
  • Read every order the agent restates before you say yes. AI can misread a price or a size.
  • Never paste keys or the MCP address into a chat.

Binance's own terms apply to trading through Agent OS, and you're responsible for the trades your agent places. See Binance's MCP Server guide and its disclosures.

On this page