Skip to main content
Carrier: POST /v1/exchange (encrypted binary). Permission: Owner or scoped TRADE agent. Admit one bounded order; acceptance is not execution. The same command is available over WebSocket.
Fields below describe the SDK request before encryption and the decoded reply. The HTTP body is encrypted binary application/octet-stream, not JSON. Use a verified SDK client; the interactive playground is disabled.

Request fields

The client supplies the configured domain, account, policy, signer and verified session binding, and signs the canonical envelope.
Uint8Array (32 bytes)
required
Nonzero private request ID. Retain it for an exact retry; use a distinct ID for a different intent.
bigint (u64)
required
Current account authority epoch.
bigint (u64)
required
Authentication expiry in milliseconds, within the verified session and deployment limits.
"order"
required
Command discriminator.
Uint8Array (32 bytes)
required
Governed market and precision.
bigint (i64)
required
Nonzero: positive buy, negative sell.
bigint (u64)
required
Positive inclusive lower execution-price bound, in ticks.
bigint (u64)
required
Positive inclusive upper execution-price bound, in ticks; must be at least minimum.
bigint (i128)
required
Nonnegative maximum quote-atom fee per lot, not percentage or total fee. abs(lots) × fee must fit i128.
"GTC" | "ALO" | "IOC"
required
Good-til-cancelled, add-liquidity-only or bounded immediate-or-cancel.
boolean
required
Must not open/reverse the private customer’s position.
bigint (u64)
required
Financial dispatch expiry in milliseconds, immutable on economic retry.

Response fields

The example uses illustrative quote atoms and configured IDs, not live venue data. A receipt records operation progress; acceptance is not execution or payment.
"receipt"
required
Response discriminator.
Uint8Array (32 bytes)
required
Durable operation ID. For an operation lookup, this is the target ID, not the query ID.
Uint8Array (32 bytes)
required
Commitment to the immutable economic intent.
number (u32)
required
Governed policy version.
Outcome
required
rejected, accepted, dispatched, acknowledged, partial, complete or unknown. See lifecycle.
bigint (i64)
required
Actual attributed signed lots, not requested quantity.
bigint (i128)
required
Qualified net payment to the beneficiary, in quote atoms.
bigint (i128)
required
Actual customer-paid payout rail fees; not ordinary trading fees.
bigint (i128)
required
Declared fee cap: absolute requested lots × fee-per-lot for orders, or extra rail-fee cap for payouts. Not the amount charged.
boolean
required
Whether the operation may have escaped for external execution. False alone is not a final settlement guarantee.
boolean
required
The recorded payout partial-dispatch consent. False for unrelated commands.

Behavior

Receipt with declared total feeCap = abs(lots) × fee and actual signed filled lots. feeCap is not charged fees; actual ordinary-fill costs appear in fills. Admission requires joined risk and reservations. Agent limits/budget apply. IOC may partially fill or not fill. Native capability must also be qualified; no unbounded market-order path.

Errors and reconciliation

Typed errors are returned inside the encrypted reply, not as field-specific HTTP status codes. Invalid fields, expired or out-of-scope authority, conflicting intent IDs and unavailable required evidence fail closed. A delivery error or timeout is not a rejection. Reconnect with fresh attestation and reconcile the original operation ID before any economic retry. See lifecycle, limits and availability.