Skip to content

Pre-launch · product preview

Your AI can already trade your money.
Now you can tell it no.

Breaker is the safety layer that sits between your AI trading agent and your Robinhood account. Point your agent at Breaker instead of the broker, and every order it proposes has to get past the limits you set — allowed, held for your approval, or blocked outright.

  • Never takes custody of funds
  • Never picks trades
  • Limits you set yourself
BreakerGate activeagent: claude-desktop
Account value
$17,420.18
Today
−$41.20
Crypto
31.4%

Sealed record · today

  • 16:41:07 BUY 12.0000 SOL-USD

    Hold · over 15% concentration cap

    $2,209.20
  • 16:12:55 BUY 0.0042 BTC-USD

    Allow · all checks passed

    $395.30
  • 15:58:31 SELL 0.3100 ETH-USD

    Allow · reduces risk

    $986.54
  • 15:47:02 BUY 3,000.0000 DOGE-USD

    Block · past daily loss limit

    $642.00

Kill switch

One tap cuts the agent off from Robinhood entirely.

Illustrative interface. Breaker is pre-launch.

The problem

One URL, and an AI is trading your real account.

Robinhood shipped Agentic Trading in 2026: a first-party Model Context Protocol server that any MCP-compatible client — Claude, ChatGPT, Cursor, Codex, Grok — can connect to and place real orders through, inside a dedicated Agentic account you fund deliberately. Crypto support landed on July 20, 2026. The plumbing is solved. Nothing about it was ever the hard part.

The hard part is that once you paste that URL, there is no step between your agent deciding something and your money moving. No second look. No ceiling. No way to say not that one while it is still a proposal instead of a fill.

70%

would hand an AI their portfolio

Either fully autonomously, or within limits they set themselves. The appetite is not hypothetical.

79%

would switch platforms entirely

For better AI trading tools. This is a market moving quickly, not a niche experiment.

2:1

margin for one safeguard above all others

Real-time notifications plus the ability to instantly revoke the agent's permissions — more than twice as requested as anything else.

Source: OKX survey of 1,400 US crypto traders, published July 21, 2026.

People already know what they want. Nobody has built it into the path.

Told about their agent in real time, and able to pull its permissions instantly — that was the single most-requested safeguard in the OKX survey, by more than two to one over anything else. It was also the only question with no generational split: Boomers and Gen Z answered it identically. That is not a preference. That is a missing component.

Breaker is that component.

How it works

You change one URL. Everything else stays the same.

Today your agent talks straight to Robinhood. With Breaker, it talks to Breaker instead. Breaker speaks the exact same protocol and exposes the exact same tools, so your agent cannot tell the difference — it asks for a quote, it gets a quote; it checks your balance, it gets your balance. Reads go straight through, untouched.

Writes are different. Every actual order stops at the gate and gets one of three answers.

Your AI agent

Claude, ChatGPT, Cursor, Codex, Grok — anything that speaks MCP.

https://mcp.breaker.trade/v1

tool call

Breaker

Reads pass through untouched. Every write is evaluated against your rules.

deterministic rule engine · < 1 ms

forwarded

Robinhood

Your ring-fenced Agentic account, funded deliberately.

https://agent.robinhood.com/mcp/trading

  • Allow

    Inside your rules. Relayed to the broker immediately.

  • Hold

    Notification to your phone. Nothing executes until you approve. Unreviewed holds expire as rejections.

  • Block

    Crosses a hard limit. Refused, and the agent is in timeout until you release it.

Try a scenario

What you asked your agent

Rotate 2% of the cash balance into BTC.
Proposed orderBUY
symbol
BTC-USD
side
BUY
quantity
0.0042
type
MARKET
price
$94,120.00
notional
$395.30

Breaker reads the structured order above — not a sentence the agent wrote about itself.

AllowForwarded in full

evaluated in 0.4 ms
  • Position size cappasses$395.30 of $2,500
  • ConcentrationpassesBTC 8.9% → 10.6% of 15%
  • Daily loss limitpasses-$41.20 of -$500
  • Trade ratepasses2nd of 6 this hour
  • AllowlistpassesBTC-USD permitted

Every configured rule passes. The order is relayed untouched and the fill comes back to the agent exactly as it would have without a gate in the way.

The held case

A hold is a question, not a delay you will miss.

When an order needs you, the order stops moving and you get a notification with the actual numbers — symbol, size, price, and the specific rule it ran into. Approving takes one tap. So does rejecting.

If you never look at it, it does not quietly go through. An unreviewed hold expires into a rejection. Silence is a no.

And the kill switch

One tap cuts the agent off from your account entirely. In-flight holds are dropped, new orders are refused, and Breaker's access is revoked. The agent cannot undo it, and it cannot release its own timeout.

TUE 4:41 PM
4:41
BreakerHold

Approval needed

BUY 12.0000 SOL-USD
market · $2,209.20

Would push SOL to 18.6% of the account, over your 15% cap.

RejectApprove

EXPIRES IN 4:52 · UNREVIEWED = REJECTED

Earlier today

Allowed · BUY 0.0042 BTC-USD

Blocked · BUY 3,000 DOGE-USD

Held orders reach you where you already are. Nothing executes until you tap approve.

Why it can't be bypassed

Four differences, and the first one is the whole argument.

Plenty of tools will help an AI agent behave. Almost all of them depend on the agent choosing to ask. Breaker does not require the agent's cooperation, because the agent has nowhere else to go.
01

It's in the path, not beside it.

Competing tools are SDKs. The agent is supposed to call them before it acts. When it works, it works — but it is a courtesy, and courtesy is exactly what fails first. An agent that is confused, prompt-injected, or running down an error path simply proceeds unchecked, and you find out afterwards.

Breaker is the only road. Your agent's credential points at Breaker, and there is no route to Robinhood that skips the check — not because the agent agreed to behave, but because that route does not exist.

Beside the path

agentbroker
risk sdk (optional call)

In the path

agentbreakerbroker

no second road exists

02

The rules are arithmetic, not vibes.

"Is this position more than 15% of my portfolio" and "have I already lost 5% today" are subtraction. They are not opinions, and they do not need a language model.

Breaker runs a deterministic rule engine. It answers in under a millisecond and it gives the identical answer every time. Same input, same verdict, always. There is no temperature setting on a comparison operator, and there are no hallucinated approvals.

Other tools
Send a text description of the action to an LLM and wait roughly two seconds for a judgment that may differ on the next identical call.
Breaker
Evaluate the numbers. Sub-millisecond, reproducible, auditable.
03

It reads your real account, not the agent's description of it.

An agent that describes its own action vaguely gets a vague verdict. That is a structural problem with grading the essay instead of the trade.

Breaker inspects the actual structured order — symbol, side, quantity, price — and checks it against account state fetched independently from Robinhood. It never takes the agent's word for anything, which means an agent that has been confused or prompt-injected cannot talk its way through.

Other tools
Grade a sentence the agent wrote about what it is about to do.
Breaker
Grade the order itself, against balances and positions fetched from the broker directly.
04

It understands portfolios, not just single transactions.

Risk does not arrive in one big trade. It arrives as twelve reasonable-looking ones in an hour, or as the fourth attempt to win back the first three.

Breaker tracks concentration, total exposure, drawdown from your high-water mark, realized loss so far today, trade pace, and revenge-trading after consecutive losses. A stateless per-action checker structurally cannot see any of this — each order looks fine on its own, and that is exactly the problem.

Other tools
Evaluate each action in isolation, with no memory of the previous eleven.
Breaker
Carry state across the whole session, the whole day, and the whole account.

Your rules

Limits you can state in one sentence and check with a calculator.

Nothing here is a judgment call. Each rule is a number you choose and a comparison Breaker performs, which is why the answer arrives in under a millisecond and never changes its mind.

Rule set

12 / 13 active

Size & exposure

How big any one bet can get.

Loss & drawdown

When the day is over.

Pace & behaviour

How fast and how often.

Sanity checks

Catching the obviously wrong.

Interactive mock with illustrative values. Toggle a rule or select one to see how Breaker would answer a matching order.

Worked example

Position size cap per trade

set to $2,500

Order from your agentBUY
symbol
ETH-USD
side
BUY
quantity
1.4000
type
MARKET
price
$3,182.40
notional
$4,455.36

Block

$4,455.36 is 78% over your $2,500 per-order cap. Refused, and the agent is in timeout until you release it.

Stopping risk is not the same as trapping you

Breaker knows the difference between an order that increases your risk and one that reduces it. Hitting your daily loss limit stops new buys. It never stops you closing a position you are trying to get out of.

The same logic runs through every rule. A cooldown after three losses pauses new entries, not exits. A concentration cap refuses the order that pushes you over it, not the one that brings you back under. The gate exists to keep a bad day from becoming a worse one — locking you inside a losing position would do the opposite.

Provable track record

A performance history that is provable rather than asserted.

Because Breaker sits in the path, it sees every proposed order before it becomes a result. Each one is written to an append-only record with its verdict and a timestamp, and then the outcome happens — never the other way around.

Sealed record

root 04e1…b9f7

  • 14:02:11.482BUY 0.0042 BTC-USD @ marketAllow
    digest 8f3c9a…d417outcome 15:40 · +$18.20
  • 14:18:53.117BUY 12.0000 SOL-USD @ marketHold
    digest 2b70e4…9ca1outcome 16:05 · approved, −$62.40
  • 15:47:02.905BUY 3,000 DOGE-USD @ marketBlock
    digest c50a1f…3e88outcome never placed

Illustrative entries. The middle row is a losing trade you approved — it stays in the record exactly like the others.

  • Written before anyone knows

    The entry is sealed at the moment the order is proposed. At that instant the outcome is genuinely unknown — which is the only thing that makes the record worth anything.

  • Append-only, fingerprinted

    Entries are chained and a cryptographic fingerprint is published. Editing yesterday means every fingerprint after it stops matching, in public.

  • Losses cannot be deleted

    The unflattering trades are already in the record before they turn unflattering. Nobody gets to quietly curate the good ones.

  • Calls cannot be invented

    You cannot claim a trade you did not make, because there is no sealed entry for it and there never will be one dated in the past.

Setup

Under a minute, and one of those steps is a copy-paste.

There is nothing to install, no code to write, and no change to how you talk to your agent. You are moving one endpoint.
  1. Open a Agentic account and fund it deliberately

    ~20s

    Robinhood keeps agent trading in a separate, ring-fenced account. You move money into it on purpose. This is your first and strongest limit: an agent cannot lose money that is not in the account.

  2. Connect Breaker

    ~15s

    Authorize scoped access so Breaker can read your positions and relay approved orders. You can revoke it from either side at any time.

  3. Set your limits

    ~20s

    Start from a conservative default set and adjust the numbers. Position cap, concentration, daily loss, trade pace, allowlist. It is a form, not a config language.

  4. Point your agent at the new URL

    ~5s

    Replace the broker's MCP endpoint with Breaker's in whatever client you use. Nothing else in your setup changes, and your agent never learns it happened.

Terminalone line changes
Before: claude mcp add --transport http trading \https://agent.robinhood.com/mcp/trading
After: claude mcp add --transport http trading \https://mcp.breaker.trade/v1

Same command, same tools, same agent. Different destination.

What your agent sees afterwards

  • The same tool names, the same arguments, the same response shapes. Quotes, balances, positions and order history are relayed untouched.
  • A held order returns a pending status with the rule it hit, so a well-behaved agent simply waits instead of retrying.
  • A blocked order returns a refusal. Retrying does not help, and there is no alternate endpoint to try.

What sitting in the path actually requires

To check orders before they reach the market, Breaker has to hold a scoped Robinhood access token for your account. We would rather say that plainly than bury it.

  • The token is encrypted at rest and decrypted only inside the request path when an order is being evaluated or forwarded.
  • Write access is confined to the ring-fenced Agentic account you fund deliberately — not your main brokerage balance.
  • Breaker never takes custody of your funds. It can only relay, hold, or refuse the orders your own agent proposes.
  • The kill switch revokes the token immediately, and you can revoke it from Robinhood independently at any time.

$BREAK · not live yet

An access token for the service. Nothing more than that.

$BREAK is a utility token that unlocks higher tiers, higher limits, and advanced rules. Subscription revenue from the service backs its utility. It is not live, and it is not required to use Breaker.

What it is for

  • Access to higher service tiers
  • Higher limits and rate ceilings
  • Advanced rule types
  • Paying service fees

It will launch on Robinhood Chain, Robinhood's permissionless Ethereum L2 (chain ID 4663, launched July 1, 2026) — a fitting home for a tool that guards Robinhood accounts.

Read the $BREAK details

Coming soon · nothing to buy

$BREAK is not live. There is no presale, no allocation, no public sale, and no launch date. Nothing on this site is an offer to sell or a solicitation to buy any token or security.

$BREAK does not represent a share of trading profits, revenue, dividends, income, or yield, and carries no expectation of financial return. It is access and fee utility for a paid service, and the service works fully without it.

Product preview

The dashboard you'll live in

Limits, pending approvals, kill switch, and a decision log — every order your agent proposes, sealed before it reaches the market.

BreakerPaper

Account

Equity
$17,420.18
Buying power
$4,812.00
Realised today
−$41.20
Drawdown
2.1%

Waiting on you

Hold

BUY 12.0000 SOL-USD

$2,209.20

Would push SOL above 15% concentration cap

Agent: scale into SOL on pullback

ApproveDeny

Recent decisions

  • #48BUY 0.0042 BTC-USD$395.30Allow28m ago
  • #47SELL 0.3100 ETH-USD$986.54Allow41m ago
  • #46BUY 3,000 DOGE-USD$642.00Block1h ago

Illustrative preview. Breaker is pre-launch — no live accounts yet.