Safety and limits
Every limit on both sides, what each one stops and how to stop everything at once.
An agent on Agent OS has two sets of brakes. Binance limits what it may do with your money. bInference limits what it may spend on AI. Set both before you leave an agent running.
On Binance
| Limit | What it stops | Where you set it |
|---|---|---|
| Scopes | Market data, Account, Trade, Transfer: the agent can do only what you granted | When you authorize the MCP Server. To change them, disconnect and connect again |
| Agentic sub-account | The agent trades only the funds you moved into it. It can't reach your main account | Profile → Dashboard → Sub-account |
| No withdrawals | There is no withdrawal scope. Funds can never leave for an outside address | Always on |
| Confirm before acting | Every order, cancel and transfer waits for your yes | Always on |
| Agentic Wallet rules | Daily limit, tradable tokens, high-risk transactions rejected or sent to the App | Binance App → Agentic Wallet → Settings |
On bInference
| Limit | What it stops | Where you set it |
|---|---|---|
| Key spending limit | The key stops at a dollar amount per day, week or month | API keys |
| The budget itself | Calls stop when the agent's budget is spent. Nothing runs into debt | Automatic |
| Reserve per call | A call that could cost more than the balance never starts | Set max_tokens |
| 8 calls at once | A runaway loop can't flood the model | Automatic |
Stop everything
If an agent misbehaves, do these three, in this order:
- Emergency stop on Binance. Profile → Dashboard → Sub-account → Account Management → Emergency stop. It disconnects every agent and cancels all open orders and positions in the Agentic sub-account at once.
- Revoke the key on bInference. API keys → Revoke. The agent can't think any more, from its very next call.
- Sign out of the Agentic Wallet, if you use it: tell the agent "Sign out", or sign it out in the Binance App.
To only pause an agent, use Disconnect agents instead of the emergency stop: open orders stay open.
Habits that help
- Fund the sub-account with only what you'd let the agent trade.
- Give each agent its own bInference key with a daily limit.
- Read every order the agent restates before you say yes. AI can misread a price or a size.
- Never paste keys or the MCP address into a chat.
Binance's own terms apply to trading through Agent OS, and you're responsible for the trades your agent places. See Binance's MCP Server guide and its disclosures.