What the user connects
The trader generates a Bybit API key with:- ✅ Trade permissions (read + place/cancel orders)
- ❌ No withdraw permissions
- ❌ No transfer permissions
What the agent can do
- Read market data and your account state.
- Place, modify, and cancel orders on the market committed on-chain.
- Respect the risk caps committed on-chain (max drawdown, max leverage, max position).
What the agent cannot do
- Move funds off Bybit.
- Trade markets that weren’t committed.
- Exceed the committed risk caps.
- Change a strategy mid-run without writing a new commit.