Trading on Torii
Torii is NightWatch's trading terminal for Hyperliquid, a non-custodial exchange. Non-custodial means NightWatch never holds your money: your funds sit in your own Hyperliquid account, and NightWatch asks that account to place orders through a limited key. This chapter covers the markets you can trade, the trading station layout, how that limited key works, how the Telegram trading flow works, and which parts of this are live today versus planned for later.
Three markets on the page, two you can order from today
Hyperliquid runs more than one order book (Hyperliquid calls each one a "dex") under one exchange. Torii's market list (left panel, searchable, with favorites and sector filters) now shows all three at once, sorted by trading volume by default.
| Main perp market | xyz market | Spot | |
|---|---|---|---|
| What trades there | Crypto only (232 listed markets, 0 stocks) | Tokenized equity and commodity perps only (103 listed markets, 0 crypto) | Hyperliquid's own spot pairs (e.g. PURR/USDC) |
| Example tickers | BTC, ETH, and other crypto perps | SKHX, SMSN, and other tokenized-equity perps, plus commodity perps such as GOLD and BRENTOIL | PURR/USDC and other listed spot pairs |
| Order submission from Torii | Live for one account only today, the operator's allowlisted account (every other account is refused); for that account, open only, since 2026-09-28 โ close a main-market position on Hyperliquid itself for now; closing it from Torii is planned for v1.1 | Yes โ open and close | Not yet โ chart and quote only, marked "not tradable yet" in the market list; order submission is planned for v1.1 |
| Collateral | USDC | USDC | USDC (spot balance) |
| Measured trading fee (actual fills, not the rate card) | taker about 3.6bp, maker about 1.2bp | taker about 0.9bp, maker about 0.16bp | not yet measured (order submission not live) |
NightWatch checked this by reading real trade fills rather than trusting Hyperliquid's published rate card, and found xyz is roughly 4 times cheaper to trade than the main market, in practice. That's the opposite of what the published rate card implies on paper, which reads as though xyz should cost roughly 2 times more than the main market. In other words: trust the measured fills over the rate card here. A position in a crypto perp and a position in an AI-stock or commodity perp do not automatically share margin: they sit in separate collateral pools unless your own Hyperliquid account has one of Hyperliquid's pooled account modes turned on, which is a Hyperliquid account setting, not something Torii changes for you.
All the same safety rules apply to a main-market order as already applied to an xyz order, unchanged: the per-order and daily dollar caps (split by whether an individual or NightWatch's own pooled/agent path is trading), the kill switch, the liquidity-safety grade floor, and the Telegram match-code handshake. Opening main-market trading did not touch any of those checks โ it only taught the order route a second market to resolve a coin against.
The liquidity-safety grade floor for new exposure is NW Grade C: an ungraded market or one graded D/F refuses new exposure outright; grade C itself is allowed but held to tighter position-size caps (the same tight-cap tier a provisional grade โ one under 7 days old โ gets regardless of its letter). This is a fixed rule in the code (svc/common/liquidity_safety.py's GRADE_FLOOR_REFUSE/GRADE_FLOOR_TIGHT), not an account-specific setting โ the earlier note about asking the operator is about your own dollar caps, which can vary by account, not this floor, which does not.
A main-market position opened through Torii does not show a Close button in Torii today: the Positions tab and the order ticket's own account panel still read the xyz ledger only. Close it on Hyperliquid's own site or app with the same wallet, or wait for v1.1, when the Positions tab reads both ledgers. A reduce-only order for a main-market position sent through the API is evaluated as ordinary new exposure rather than a close, for the same reason โ it is never misrouted to the wrong market, it simply doesn't get the reduce-only exemption from the caps yet.
The trading station layout
A market list (search, star a favorite, filter by sector, sorted by 24h volume by default) and an in-page candlestick chart sit at the top of the page, side by side, with a row of account tabs directly under the chart. Torii's original market list and order ticket โ unchanged in how they work โ sit further down the same page, below this new row.
- Chart: candlesticks with a volume bar underneath, drawn in the page itself. Timeframes: 1 minute, 5 minutes, 15 minutes, 1 hour, 4 hours, 1 day, 1 week. Your own recent fills on the selected market show as small up/down arrows on the chart, and an open position's average entry price shows as a dashed line. The older chart popup (opened from the small chart icon next to a market row or the order ticket's own symbol) still exists and still works โ the in-page chart above is now the primary way to see a chart, not a replacement that removed the popup.
- Bottom tabs (directly under the new chart, not the same panel as the order ticket further down): Positions, Open orders, Fills, Funding, Order history, Balances, Transfers. Funding and Order history are new: Funding lists each funding payment your account made or received on a market (Hyperliquid perp markets exchange a periodic funding payment between longs and shorts); Order history lists past orders (filled, canceled, or expired), not just the ones currently resting. Both read straight from Hyperliquid's own account history for your address, merged across the main and xyz ledgers, with no key involved (same read-only, no-signing model as the rest of the account panel). The Positions/Open orders/Fills tabs here show the same xyz-dex data as the order ticket's own account panel further down the page โ reorganized into named tabs, not a second, separate data source.
- Spot rows in the market list open the chart like any other market but carry a "not tradable yet" label instead of an order form โ Torii shows you the number without pretending you can act on it yet, same as an unlisted name's muted chip elsewhere on this page.
Order types
Market and limit orders are live. Stop, stop-limit, post-only, TP/SL, scale and TWAP orders are built and roll out one at a time, each after a test fill on Hyperliquid's testnet.
Every type below goes through the same checks as a market order โ the dollar caps, the daily cap, the emergency stop, the re-check at execution, and the Telegram confirm code for an AI agent's order. None of those checks is loosened for any type. The difference is the size each one is checked at: the largest amount it could ever fill at, never less than its size at the current price (see "Spending limits" below).
| Type | What it does | Size checked against your cap |
|---|---|---|
| Stop market | Sends a market order once the price reaches your trigger price. | Size ร the higher of the current price and the trigger, plus at least a 10% market-fill allowance (or your own slippage setting, if that is larger) โ a stop market fills at whatever the book gives once triggered, and this checks it at a wider margin than an ordinary market order until live fills prove that margin can be narrower |
| Stop limit | Places a limit order at your limit price once the trigger is reached. | Size ร the highest of the current price, the trigger and the limit price |
| Post-only (ALO) | A limit order that only adds liquidity. If it would fill right away, Hyperliquid cancels it, and Torii says so in plain words ("it would have filled right away โ move your price away from the market"). | Size ร the higher of the current price and the limit price |
| Entry + TP/SL | Opens a position (market or limit entry) with a take-profit and/or stop-loss attached. The exits are reduce-only: they can only close, never open or grow a position. | Size ร the highest of the entry, take-profit and stop-loss prices; a market entry uses the ordinary slippage allowance, but each take-profit/stop-loss exit uses the same wider 10%-or-more allowance stop market uses, since an exit fills the same way |
| TP/SL on a position | Adds a take-profit and/or stop-loss to a position you already hold. Reduce-only, sized to the whole position, and it follows the position's size. | Position size ร the highest of the current price, take-profit and stop-loss, plus the same wider 10%-or-more allowance (both legs fill the same way a stop market does) |
| Scale | Splits your size into 2 to 20 limit orders spread evenly across a price range. The size per order is either equal or weighted toward one end (the last order up to 5ร the first). | The total at the range's highest price must fit your cap, and every single order must fit too โ otherwise the whole scale order is refused. Each order must also clear Hyperliquid's own minimum order size ($10); if raising your size or lowering the order count would fix it, NightWatch says so |
| TWAP | Hyperliquid's own time-weighted order: it buys or sells gradually over 5 to 1,440 minutes, optionally at random intervals, and can be cancelled while it runs. | Size ร the current price plus slippage; later child orders can fill higher than the price it was checked at, since the average price can drift over a long run. Each estimated child order must also clear Hyperliquid's own $10 minimum. An AI agent's own TWAP is capped at 60 minutes โ a person confirming in Torii sees the live order and can judge the drift directly; an agent cannot, so its runs stay shorter |
Before you sign. The ticket's size slider sets your order as a percentage of the margin available in your trading balance, at the leverage you picked. A preview (behind the โธ toggle) shows the estimated liquidation price, the estimated fee, the margin the order uses, the largest amount it could fill at, which cap applies to you and how much room is left under it. These are estimates from public prices; Hyperliquid's own numbers after the fill are the real ones. Then NightWatch's server checks the order against your caps, your browser checks the same number again, and only then does your own wallet sign โ NightWatch never holds the key.
After you send. The Open orders and Order history tabs show each order's type and trigger price, and a TWAP list under Open orders shows how much of each TWAP has filled and how much of its time has passed, with a Cancel button while it runs.
For an AI agent or API caller. POST /torii/order takes an order_v2 object instead of order_kind: {"type": "stop_market", "trigger_px": โฆ}, "stop_limit" (trigger_px, limit_px), "limit_alo" (limit_px), "tpsl" (entry market or limit, entry_px, tp_px, sl_px), "position_tpsl" (tp_px, sl_px, with reduce_only: true), "scale" (start_px, end_px, count, skew) or "twap" (minutes, randomize). The response carries order_v2.spec (the rounded prices) and order_v2.worst_case (the amount checked against your cap, and a scale order's individual orders).
The trade-only agent key
When you "enable trading" in NightWatch, you are not handing NightWatch your wallet's private key. You are approving a second, separate key called an agent key (Hyperliquid's own name for this is an API wallet) that can only place and cancel orders.
This was verified directly against Hyperliquid's live network, not assumed from documentation: an agent key can sign trading orders, but any attempt to withdraw funds signed by an agent key is rejected by Hyperliquid itself, at the protocol level. Moving collateral between a user's own balances is a separate story. Hyperliquid does have a signature type that lets an agent key move funds between a user's own balances, and NightWatch has not fully tested how far that permission actually reaches - this is a question the team is still working through, not one it has ruled out. What NightWatch can say with confidence is that its own Telegram approval flow does not rely on that agent-side capability: the "send funds from your main balance to the xyz balance" step described below is designed to require your own wallet's signature, not the agent key's. So the worst case if a NightWatch-issued agent key were ever stolen is that someone places bad orders while your money stays inside your own Hyperliquid account and cannot be withdrawn; whether such a key could also shuffle funds between your own balances is a question NightWatch is still testing, not one it has ruled out.
Each agent key issued through the Telegram flow is also short-lived: it is valid for 30 days from approval, tied to one physical device, and expires automatically. A separate, longer-lived agent key exists for NightWatch's own server-run trading paths; the two are not interchangeable.
The Torii fee
The Torii terminal's builder fee is 0.1% per order, the maximum Hyperliquid allows on perps. You agree to it once, with one Hyperliquid signature from your main wallet that is part of the same "enable trading" action as the agent-key approval: a NightWatch Wallet signs it without an extra prompt, and a wallet you hold yourself shows one extra signature request. The enable screen shows a single line with the rate, "Torii fee 0.1% per order", read from the server's configured rate. If you decline the signature, enabling still finishes and the terminal shows one line with a button to sign it later. An order never carries more than 0.1%, and never more than the maximum your own signature approved. The fee can be lowered; it is never raised.
How Telegram trading gets turned on
Enabling trading from the Telegram Mini App is a multi-step handshake designed so that no single compromised system (not the Telegram app, not the phone, not NightWatch's own server) can approve a trading key by itself. It runs like this:
- Tap "Enable trading" in the Mini App. This creates an approval request that expires after 5 minutes if unused.
- NightWatch opens
/torii/approvein your regular browser (not inside Telegram), where you sign in with the same wallet already linked to your NightWatch account. - Compare the match code. The page shows a 6-character code, which is simply the last 6 characters of the new agent's wallet address. The Telegram app shows the same 6 characters on your phone. You are asked to eyeball-compare the two before continuing. This exists specifically so that if NightWatch's server were ever compromised and tried to swap in a different agent address, you would catch it here, because the code shown on your phone would not match the one your browser is about to approve.
- Approve on Hyperliquid. Your connected wallet signs Hyperliquid's own "approve agent" message. This is a real signature from your wallet, and Hyperliquid, not NightWatch, is the one that checks and accepts it.
- Optional: fund the stock desk. You can move a percentage (25%, 50%, all, or skip) of your main-market USDC balance over to the xyz desk so you have something to trade with there. This step can be skipped entirely and crypto trading still works. As noted above, this transfer step requires your own wallet's signature, not the new agent key's.
- Claim. The browser tells NightWatch's server the approval is done, using the same match code, which is what actually links your Telegram account to the new agent key server-side.
If your connected wallet doesn't match the wallet already on file for your account, the flow stops and shows a mismatch screen rather than letting you sign with the wrong wallet.
Spending limits (caps)
Every order placed through Torii is checked against dollar limits before it is allowed to go out. These limits can change over time, so this book describes what each one controls rather than quoting exact figures:
| Limit | What it controls |
|---|---|
| Pooled/agent per-order cap | Maximum size of a single order placed by NightWatch's own pooled/agent trading path (not an individual user's browser session) |
| Pooled/agent daily cap | Maximum total dollars that pooled path can execute in one day |
| Individual per-order cap | Default per-order limit for an individual signed-in user trading through the web page, which that user can request to raise in fixed steps |
| Individual daily cap | Maximum total dollars one individual user can execute in one day |
Each order is checked at the largest amount it could fill at, not only at its size times the current price. A limit order is checked at the higher of the current price and its limit price; the order types in "Order types" above are checked the same way at their own worst case โ a stop at its trigger plus at least a 10% market-fill allowance, a scale order's total at its highest price (with every order in it checked on its own as well, and against Hyperliquid's own $10 minimum), a TWAP at the current price plus slippage. That can only make a check stricter, never looser.
By default, an order that closes an existing position (a "reduce-only" order) is checked against these exact same per-order and daily caps as any other order; closing a position gets no special exemption automatically. NightWatch has also built a separate, higher ceiling meant only for closing orders, so that a cap intended to limit new risk-taking doesn't someday trap someone inside a position they're trying to exit. That higher ceiling is not in this version yet: today, closing a position costs you the same daily and per-order room as opening one.
A resting order (a stop, a limit, a scale order, a TWAP) counts against the day's cap on the day it was placed, not the day it eventually fills or finishes. An order left open overnight does not draw against tomorrow's room when it fills tomorrow.
The region check (geo gate)
NightWatch has built a region check for the Telegram trading path specifically; the web /torii page has no region check at all. When you try to enable or place a trade through Telegram, NightWatch first looks at the residency setting already stored on your account, and only falls back to a geo hint from the network layer - the country code its network provider (Cloudflare) reports for your connection - if that account setting isn't stored. That Cloudflare signal can't be spoofed by anything the visitor's own browser sends, though this protection holds only as long as traffic to NightWatch can't be routed around Cloudflare entirely. This check exists, but it is not in this version: today it does not block anyone by region. NightWatch can turn it on later if a legal review concludes it's needed.
Is trading actually live right now?
Be direct about this: live order placement works today only for one account - NightWatch's operator, trading through their own allowlisted Hyperliquid account on the web terminal. Trading for all other accounts is not in this version; it's planned for v1.1 ("trading for all accounts with your own key").
For everyone else, new orders are not accepted yet, though existing positions can still be closed so nobody gets trapped. That closing carve-out works today; the separate, higher ceiling for closing orders described above is not in this version yet.
A signed-in user who is not the operator's allowlisted account gets a clear "not authorized" response from the web terminal rather than a fake success.
So, honestly: the approval handshake described above, the agent-key security model, and the caps are all real, built and working today. What isn't available yet is pushing a live order to Hyperliquid from any account other than the operator's - that's the v1.1 milestone.
Legal notice
Torii is not investment advice, and availability varies by jurisdiction โ this applies whether or not live order placement is turned on for your account. While order flow is still gated (see "Is trading actually live right now?" above), that gate is pending legal review and builder-wallet setup, not a technical limitation โ prices and the order book you see are real even though the order/close buttons don't execute yet for most accounts. Once trading is live for an account and it signs and sends an order with its own wallet (non-custodial โ NightWatch never holds the key), that order is real and irreversible the moment it's sent. The page's own footer carries a one-line version of this notice at all times, with the fuller wording available behind a "Legal โธ" toggle there.
Funding your account
/torii/fund previews a two-step bridge for getting money into your Hyperliquid balance:
- A third-party widget would bridge a token from almost any chain into native USDC sitting in your own Arbitrum wallet.
- A NightWatch panel would then move that USDC from your Arbitrum wallet into your Hyperliquid balance (Hyperliquid's deposit bridge only accepts USDC arriving on Arbitrum, which is why the first hop exists).
Moving real funds this way is not in this version; it's planned for v1.1 ("live payments on Base and Arbitrum"). Today, /torii/fund shows a preview of this flow: the bridging widget and deposit button don't appear on the page yet, and the underlying bridge hop points at Arbitrum Sepolia, a test network for Arbitrum, not the real Arbitrum network. Treat /torii/fund as a preview today, not a channel for moving real money.
Index perps: trading an index or an ETF, not just a single stock
Alongside single-name tokenized equities (SKHX, SMSN, and the rest of the xyz market described above), the xyz market also lists perps that track an index or an ETF rather than one company - the S&P 500, the Nikkei 225, Korea's KOSPI 200, and a set of sector and country ETFs such as a semiconductor ETF or a 3x-leveraged South Korea ETF. /torii/indices is a dedicated page for this subset: it shows the live level, how much it moved over the last day and the last week, trading volume, open interest, and the maximum leverage Hyperliquid allows for that market.
NightWatch calls this page a relay, and means that literally: the two buttons on each row either open NightWatch's own Torii terminal on that exact market (the same trade-only agent key and builder fee described earlier in this chapter apply there, unchanged) or send you straight to Hyperliquid's own trading page for it. Either way, NightWatch never holds your funds and never places that order for you - the page's whole job is showing you the number and getting out of your way.
One leverage note worth reading before you tap a leveraged name: two of these ETFs (a 3x semiconductor-bull fund and a 3x South-Korea-bull fund) are themselves already 3x-leveraged products before Hyperliquid's own leverage is applied on top. Any leverage you choose on Hyperliquid stacks on the fund's own built-in 3x, not replaces it - the page says so directly on those two rows.
Every row's underlying is checked against trade.xyz's own published market specifications before it's shown as a real name; a row NightWatch could not confirm that way says "reference pending" and carries no description, rather than guessing what it tracks.
Each row on /torii/indices links to its own detail page at /torii/indices/<symbol> - who issues the fund and how it's built, its constituents with weights (fetched daily from the issuer's own holdings file where one is public, or shown as a documented reference list with its source and date otherwise), the same level/24h/7d numbers plus a 30-day change and Hyperliquid's hourly funding rate, and a "Related on Hyperliquid" list of other xyz markets that share the same underlying companies. The relay buttons there carry a leverage selector (1x/2x/5x/max, capped to what Hyperliquid allows for that market) - choosing one only pre-fills that leverage on the Torii ticket you land on; you still confirm the order yourself, and NightWatch still never places it for you.
Index perps: the tradability rating
Next to each index or ETF perp, /torii/indices shows a NightWatch rating of how easy the market is to trade: usable, thin or avoid, with one line naming the single measure that decided it. The rating comes from NightWatch's own measurements of the Hyperliquid book, scanned every 15 minutes and summarised over the last 14 days, and from nothing else: market news is not an input, and the page is not investment advice.
Usable needs all of these at once: NW Grade A or B, a median spread of at most 15 basis points, at least $100,000 of resting orders within 2 % of the price on each side of the book, at least $10 million of 24-hour trading volume, and a funding cost (the trailing 30-day average, scaled to a year) of at most 15 %. Thin means at least one measure falls in the middle band: Grade C, a spread of 15 to 40 basis points, $25,000 to $100,000 of depth, $1 million to $10 million of daily volume, or a funding cost of 15 % to 40 %. Avoid means at least one measure is worse than that: Grade D or F, a spread above 40 basis points, depth under $25,000, daily volume under $1 million, funding above 40 %, less than seven days of scans, or a reference NightWatch has not yet verified ("reference pending"). The rule is deterministic; the same stored numbers always give the same rating, and the card states which number decided it.
Because most liquidity sits in US trading hours, the rating is also given per session, shown as a strip of four cells on each row: US regular (09:30 to 16:00 New York time, the cash-market hours: 13:30 to 20:00 UTC in summer, 14:30 to 21:00 UTC in winter), US extended (04:00 to 09:30 and 16:00 to 20:00 New York time), Asia (the rest of the weekday, 20:00 to 04:00 New York time) and weekend (Saturday and Sunday UTC). A market can be usable in US regular hours and thin elsewhere. For a weekday session, the rule also asks for a median share of the day's notional of at least 10 % (the median over the weekdays of the last 14 days of that session's share of each day's notional; 2 % to 10 % is thin, below 2 % is avoid). The weekend is a whole day rather than a slice of one, so it is rated without the share test (grade, spread, depth, funding, reference and history still apply), and the card shows the weekend notional against the weekday median as information. NYSE hours follow US daylight time automatically. A bucket with fewer than 20 samples shows "insufficient" and its sample count instead of a guess. Each row also carries the two relay buttons, Trade in Torii and Open on Hyperliquid. The detail page adds a 24-bar hour-of-day profile of spread, depth and volume share over 14 days, the funding cost over 7 and 30 days, and two numbers that are shown but not rated: the tracking gap and the gap risk. The tracking gap compares the perp's mark at the reference's official close time with that official close (perp mark minus reference close, divided by the reference close, in bps), for every trading day that has a stored close; the card shows the 14-day median and the worst day, with the number of days and the data source, and says "insufficient" below 5 days. It is computed 30 minutes after each reference's own session close (New York, Seoul or Tokyo time, so it follows daylight time), exchange holidays have no close and are skipped, and a stored close is never rewritten. Closes come from Yahoo's public chart data, with Finnhub as a fallback for US ETFs when a key is configured and Yahoo has no close for the day (only a price stamped at the session close is accepted); a reference with no published close level shows "reference close unavailable" instead of a number. The gap risk is the typical move of the perp while the reference market is closed.
Every rating carries the label "judged by the house AI, calibration pending". NightWatch also asks its AI model the same usable / thin / avoid question with the same numbers and records whether it agrees with the rule; when it disagrees the row shows "under review". The AI never overrides the rule. The label stays until a month of agreement records has been published (charter decision 7). The page lists, searches (market, reference name, reference ticker), sorts on every number and filters by reference type, rating, session, verified reference and thin liquidity; the filters live in the page address so a view can be shared. The same data is served read-only by GET /guardrail/ratings (latest rating per market; filters session, rating, reference_type) and GET /guardrail/ratings/{market} (history, daily session statistics, hour-of-day profile), both cached for 60 seconds.
Exchange grades
Daily grading is paused: no letter grades are published yet, and until grading starts the page and the API show each venue code as "not enough data"; the method described below is what will apply when it starts.
/exchanges grades every centralised exchange NightWatch scans, from A to E, once a day when grading runs, using only NightWatch's own measurements: no market news, no reviews, no third-party volume rankings. Each exchange is shown by its two-letter venue code, never its name. The codes exist so that a grade is read for what was measured and not for a brand; the mapping from code to exchange stays on NightWatch's servers, and a code keeps its exchange for good.
Five components are scored from 0 to 100 and weighted: liquidity quality 40 % (the share of the exchange's markets at NW Grade A, B, C and D-F, plus the median spread and the median resting depth within 2 % of the price across its top 200 markets by notional), reliability 20 % (outages recorded in the last 30 days: 100 minus 5 points per distinct outage hour), coverage 15 % (the share of listed markets scanned in the last 24 hours, and how fresh the newest scan is; "listed" means the markets NightWatch tracks as not delisted, not the exchange's own list), warning lead time 15 % (for each delisting, special-treatment tag or suspension the exchange announced in the last 90 days, whether NightWatch's own warning came at least 24 hours earlier, using the same event records as the "We Called It" headline; hit rate and median lead in days) and fee level 10 % (scored by band from the exchange's spot taker fee in the static fee table the arbitrage cost model uses: up to 0.10 % scores 100, 0.10 to 0.20 % scores 60, above 0.20 % scores 20; only the band is published, never the exact fee, and every band covers at least two exchanges; maker fees show "no record" until that table carries them). Withdrawal reliability is shown as "no record" in v1 and is scored in v1.1 only where NightWatch has a measured withdrawal record.
The score is the weighted average, and the letter is A at 80 and above, B at 65, C at 50, D at 35 and E below that. A component with fewer than 7 days of data (or fewer than 7 announced delistings for the warning lead) is "insufficient", and one with nothing measured is "no record": both are left out of the score, the remaining weights are renormalised to add up to 100 %, and the row says so. When liquidity cannot be scored, or less than half of the weight has data, the exchange shows "not enough data" instead of a letter. Every component is shown with its number, window and formula; each row has a 30-day score history. To keep a grade from identifying an exchange by its size, NightWatch publishes shares, a coarse market-count range (under 100, 100 to 300, 300 to 1000, over 1000), hours and bands, never raw market, scan or event counts. Depth is published as a ratio to notional only, until USD conversion exists (v1.1).
Every grade carries the label "judged by the house AI, calibration pending". When grading runs, NightWatch also asks its AI model once a day the same question, which letter the measurements deserve, and stores its answer; when the AI disagrees the row shows "under review". The AI never overrides the rule, and the label stays until a month of agreement records has been published. The page searches by code and filters by grade; the filters live in the page address so a view can be shared. The same data is served read-only by GET /guardrail/exchanges (latest grade per code; filters grade, q) and GET /guardrail/exchanges/{code} (every component and 30 days of grades), both cached for 60 seconds. Agents can find it through the Agent Router entry read_exchange_grades. A grade is not a recommendation to use or avoid an exchange.
NightWatch sub-indices
A sub-index is a basket inside a parent index whose members are named by a written rule, not by an opinion. /torii/indices lists them in a section at the top, and each has its own page at /torii/indices/sub/{slug}. The first is the US Strategic Crypto Reserve basket, inside the parent index CMC20 (the CoinMarketCap 20 Index: the top 20 by market cap, rebalanced monthly at 00:00 UTC on the 1st, with stablecoins and pegged assets left out; NightWatch does not recompute it, it reads the monthly constituent list and uses it as the pool of eligible assets).
The rule, version 1: a member is an asset that is (a) a constituent of CMC20 at the monthly rebalance and (b) named as a reserve or stockpile asset in an official United States government document, or in an official statement by the President or a federal agency (Treasury, SEC). The current sources are the President's public announcement of 2025-03-02, which named BTC, ETH, XRP, SOL and ADA, and Executive Order 14233 of 2025-03-06, which establishes the Strategic Bitcoin Reserve (bitcoin) and the United States Digital Asset Stockpile (digital assets other than bitcoin); press reports never count. From those sources the list is BTC, ETH, XRP, SOL and ADA. A change in either source changes membership at the next monthly rebalance only, and a document dated after a rebalance is never used for it (no look-ahead). The rule text is frozen per version and every version is kept; a new version is a new series shown beside the old one. NightWatch also applies two filters at each rebalance: the asset needs NW Grade A or B on at least one tracked venue, and it must have no active delisting warning. A filtered-out member's weight is spread over the rest, and the event is logged and shown on the page.
Weights are equal (20 % each at five members), rebalanced monthly, with no leverage. The level starts at 1000 on 2025-03-07, the first trading day after the Executive Order, and is the daily close level computed from the spot reference closes of the five assets (UTC day close, the same Yahoo adapter the tracking gap uses). Between rebalances the holdings drift with price; a rebalance executes at the close of the previous UTC day. A live figure next to it multiplies the units held by Hyperliquid mid prices and is for display only. The backtest runs from 2025-03-07 to today with the same rule and is published once and never restated. Its honesty box states the data source and window, that membership is fixed by the official documents as of each rebalance (no look-ahead), that costs are assumed at 0 bp (no trading cost, spread or slippage), that NightWatch filters are applied at the latest rebalance only because grade history for earlier months is not available, that tracking against CMC20 is not available until a CMC20 level series is stored, and that a month without a stored CMC20 constituent list shows "parent list pending" (membership then follows the official documents alone or keeps the previous month's list). The constituent list is entered by the NightWatch operator from the public CMC20 page with its source link and capture date; until a month is entered the page says so.
The parent list is entered by the house, not scraped. Each month an operator records the CMC20 constituents for that month in the admin deck together with the source link and the capture time. Until a month is recorded the sub-index shows "parent list pending": membership then follows the official documents alone, or the previous month's list once one exists, and every level stored under that fallback is flagged in the honesty box. Entering a month later never changes levels already stored.
The page shows the versioned rule text, the members with weights and filter status, the level chart (backtest and live), and an event timeline of official events only: each entry has a date, a title, the official source link and the affected members, and the house AI classifies it as affecting membership, affecting weights or informational, with its probability and an "under review" mark when it is unsure. Market news and price commentary are not entries. Each sub-index has one Hive room ("Discuss in Hive"), and each member has "Trade in Torii" and Hyperliquid relay links to its perpetual market; NightWatch relays only, it never holds funds or places the order. The list searches by name, parent and member, sorts by change since base, level, update time and name, and keeps the view in the page address. The same data is served read-only by GET /guardrail/subindices (filter q) and GET /guardrail/subindices/{slug} (rules, members, daily levels, events, honesty box, parent months), both cached for 60 seconds, and agents can find it through the Agent Router entry read_subindices. Running a basket of these assets as a vault is a later step (v1.2). Not investment advice. Not news.
What you can do now
- Open
/toriito see live Hyperliquid market data for both the crypto market and the xyz market (tokenized equities and commodities), even before enabling trading. - Open
/torii/indicesto see index and ETF perps specifically - the S&P 500, Nikkei 225, KOSPI 200, and sector/country ETFs - each with a usable / thin / avoid tradability rating, a four-cell session strip, 24-hour change, 24-hour volume, funding cost and max leverage, searchable and sortable. - Try the Telegram "Enable trading" flow to see and understand the agent-key approval handshake, including the match-code check, without assuming it will place a live order today.
- If you are NightWatch's own operator,
/toriiorder placement works for your own Hyperliquid account; for anyone else, it currently will not - general access is planned for v1.1. - Do not send real funds through
/torii/fundyet - treat it as a preview until NightWatch confirms live funding has been enabled and tested with a small real deposit. - If you have questions about a specific dollar cap or which controls are currently turned on for your account, ask the NightWatch operator directly - these are values that can change over time.