Repository navigation
FAQ
How do I enable signing?
Fresh installs are read-only by default. Run xrpl-trade live and type go live at the prompt (no flag skips this). Mainnet signing requires a named signing profile; xrpl-sign --approve refuses while read-only. See Security.
Where's my mainnet seed stored? In your secure credential vault, never in this skill's local files. Muse must release it only after genuine approval. Mainnet local seed creation and backup are refused. Testnet local credentials are stored separately in a typed file bound to their network and account. Never paste a seed into chat.
Do I need the Changelly buy skill? No — it's an optional companion. If your wallet already has XRP, skip it. If not, it generates a card-buy link so you can fund the wallet first. (See Prompt Library → Power combos.)
I ran buy — did it trade?
No. xrpl-trade only proposes. Check xrpl-sign --list — your proposal
sits there, unapproved, doing nothing, until a human runs
xrpl-sign --hash <hash> --approve. It expires after 24h.
Why was my proposal rejected at signing?
Common reasons: price too far from the book (max_deviation_bps), book
too thin/one-sided/wide, asset has no spend_limits entry, pair not in
approved.json, payment to a non-allowlisted destination, or the proposal
is older than 24h. The signer prints the specific reason — see
Command Reference for the full reject list.
Can I approve by hash prefix? No. Review commands may accept prefixes, but signing requires the full 64-character proposal digest. The CLI flag alone does not establish human approval; Muse must bind the reviewed operation to the vault call.
Why did my proposal stop working after a policy edit?
The envelope binds the policy digest and complete named profile. After
deliberately editing and reviewing policy, run
xrpl-sign sync-profile --profile <name> and create a new proposal. Never
re-use an approval tied to the old policy/profile.
Why can't I trade RLUSD?
Fail-closed design: assets without a spend_limits entry are blocked,
not defaulted. Add explicit per-tx/per-day caps for RLUSD (with its full
issuer) in your policy when you're ready.
How do the daily limits work? True rolling 24h windows per asset, enforced with file-locked reservations. A reservation stays reserved until the validated ledger result proves what happened — a crash can't silently free spent budget.
What if accounting state is corrupt or a transaction outcome is unknown?
Do not delete the state file. Corrupt state blocks signing. recover-state
preserves the source and requires full digests for the source and reviewed
reconstruction; migrate-state retains old state and moves validated
liabilities to the profile's account/network namespace. Timeouts and
incomplete history keep reservations pending.
What's the max fee?
max_fee_drops (default 1000 drops = 0.001 XRP). Anything pricier is
rejected.
My limit order didn't fill. Why?
A limit order only fills if the market reaches your price. "Buy 5 XRP two
cents under market" rests on the book by design — that's the point. All
offers carry an expiry (default 1h, max 24h); check xrpl-sign --list and
re-propose if it lapsed.
It said tesSUCCESS — am I done?
tesSUCCESS at submission is provisional. The signer waits for the
validated ledger result and reports that. Use reconcile --hash any time
to fetch the final outcome.
How do I see my open offers?
xrpl-sign --list shows pending (unapproved) proposals. For live offers
resting on the book, cancel with cancel --seq <offer-sequence>.
Why did my payment get blocked?
Payments only go to (address, destination_tag) pairs in your
destination_allowlist — empty by default. Add the destination
deliberately, with its tag.
Do I really need the destination tag?
If the destination is an exchange (or any account with RequireDestTag),
yes — without it your funds can be lost in their omnibus wallet. The
signer refuses untagged payments to such destinations, even failing closed
when the tag lookup itself errors.
Can the agent trade on its own? No. There is no autonomy, no scheduling, no market-watching, no auto-approve. Every transaction needs a human approving its exact hash. That's the entire point of the skill — see Security.
Which networks are supported?
mainnet, testnet, and devnet are supported. Mainnet signing requires
the reviewed profile and verified Muse runtime boundary. The faucet is only
for testnet/devnet.
What does xrpl-trade doctor verify?
It checks local profile files, signer/helper hashes, protected-file
permissions, and readable accounting state without network or credentials.
It always reports the Muse approval/vault and protected execution boundary
as unverified.
Something's wrong — where do I look?
- The signer's rejection message (it's specific).
-
xrpl-trade reconcile --hash <hash>for the validated outcome. -
~/.xrpl/audit.logfor what was actually signed. - Technical Reference for how the piece in question works.
Propose → approve → sign. Nothing moves without your hash.