This record as markdown: /tools/io-github-1lystore-mcp-server/1ly-trade-token.md
What 1ly_trade_token does on 1ly
AI agents use 1ly_trade_token to commit financial operations through 1ly, usually the final step of a payment, billing, or trading workflow. A call moves real money.
Why 1ly_trade_token is rated Critical
Trading tokens is a financial operation that moves or commits monetary value. The server description explicitly mentions 'buy/sell APIs' and 'USDC & $1LY' as currencies, confirming that token trades involve real financial assets. Misuse could result in unauthorized financial transactions, making this critical severity.
From the tool's definition 'Trade tokens on Bags (Bags only)' — trading tokens constitutes financial transactions involving buying/selling assets
Attacks that exploit this kind of access
The rule that runs 1ly_trade_token safely
PolicyLayer is an MCP gateway: it sits between your AI agents and 1ly, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For 1ly_trade_token, this is the rule to start with:
Any call to 1ly_trade_token is blocked until a human approves it. The rest of the server keeps working.
The button opens the PolicyLayer dashboard: create your workspace, connect 1ly, apply this rule, and every 1ly_trade_token call is checked against it from then on.
Questions about 1ly_trade_token
Trade tokens on Bags (Bags only). It is categorised as a Financial tool in the 1ly MCP Server, which means it involves financial transactions. Block by default and require explicit approval.
Register the 1ly MCP server in PolicyLayer and add a rule for 1ly_trade_token: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches 1ly. Nothing to install.
1ly_trade_token is a Financial tool with critical risk. Critical-risk tools should be blocked by default and only enabled with explicit human approval.
Yes. Add a rate_limit block to the 1ly_trade_token rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for 1ly_trade_token. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
1ly_trade_token is provided by the 1ly MCP server (@1ly/mcp-server). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on 1ly, and thousands of servers like it.
Across the catalogue