> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cinder.exchange/llms.txt
> Use this file to discover all available pages before exploring further.

# Operations

> Retained original commands and current durable receipts.

**Carrier:** `POST /v1/exchange` (encrypted binary).

**Read family:** `operations` · **Permission:** owner or current READ agent.

Retained original commands and current durable receipts. Results are private to the bound account. The same query is
available over HTTP and [WebSocket](/api/websocket), including subscriptions.

<Note>
  These are signed SDK fields and decoded results, not a plaintext JSON HTTP body.
  The shared carrier accepts encrypted `application/octet-stream`.
</Note>

<RequestExample>
  ```ts SDK request theme={null}
  const response = await client.request({
    id: ctx.id,
    epoch: ctx.epoch,
    expiresAt: ctx.expiresAt,
    command: {
      kind: 'read',
      query: { family: 'operations', limit: 32 },
    },
  });
  ```
</RequestExample>

<ResponseExample>
  ```ts Decoded page theme={null}
  ({
    kind: 'page',
    family: 'operations',
    revision: snapshotRevision,
    next: new Uint8Array(40),
    evaluatedAt: observedAt,
    rows: [
      {
        kind: 'operation',
        committedAt: observedAt,
        command: {
          kind: 'order', market: ctx.market, lots: 2n,
          minimum: 90n, maximum: 110n, fee: 1n,
          tif: 'IOC', reduceOnly: false, goodUntil: ctx.goodUntil,
        },
        receipt: {
          kind: 'receipt',
          id: ctx.originalOrderId,
          digest: recordedIntentDigest,
          policy: approvedPolicyVersion,
          outcome: 'partial',
          filled: 1n,
          paid: 0n,
          railFees: 0n,
          feeCap: 2n,
          possiblyExposed: true,
          allowPartial: false,
        },
      },
    ],
  })
  ```

  ```ts Stale cursor error theme={null}
  ({ kind: 'error', code: 'conflict' })
  ```
</ResponseExample>

## Request fields

Use the configured [client and envelope](/api/authentication). Each request supplies
`id`, current `epoch` and authentication `expiresAt`, as shown in the example.

<ParamField body="command.kind" type="&#x22;read&#x22;" required>
  Read-command discriminator.
</ParamField>

<ParamField body="command.query.family" type="&#x22;operations&#x22;" required>
  Selects this exact private projection.
</ParamField>

<ParamField body="command.query.limit" type="number" required>
  Integer from 1 to 64 rows. The example requests 32.
</ParamField>

<ParamField body="command.query.cursor" type="Uint8Array (40 bytes)">
  Omit or use all-zero bytes to start. For another page, use the prior page’s `next` under the same snapshot revision.
</ParamField>

## Response fields

Illustrative decoded SDK values are shown at the right; absent optional fields
mean unavailable, not zero. Empty `rows` is valid.

<ResponseField name="kind" type="&#x22;page&#x22;" required>
  Paged-response discriminator.
</ResponseField>

<ResponseField name="family" type="&#x22;operations&#x22;" required>
  The requested family.
</ResponseField>

<ResponseField name="revision" type="Uint8Array (32 bytes)" required>
  Commitment to the permitted snapshot and query identity, not a global activity counter.
</ResponseField>

<ResponseField name="next" type="Uint8Array (40 bytes)" required>
  Next cursor; all-zero means no more retained rows.
</ResponseField>

<ResponseField name="evaluatedAt" type="bigint (u64)" required>
  Qualified Cinder evaluation time, in milliseconds.
</ResponseField>

<ResponseField name="rows" type="ReadRow[]" required>
  At most the requested limit.

  <Expandable title="Operations row fields">
    <ResponseField name="kind" type="&#x22;operation&#x22;" required>
      Operation-row discriminator.
    </ResponseField>

    <ResponseField name="committedAt" type="bigint (u64)" required>
      Qualified Cinder transaction-observation time, in milliseconds.
    </ResponseField>

    <ResponseField name="command" type="Command" required>
      Original operation economics; contains one of the eight original command types, not another read.
    </ResponseField>

    <ResponseField name="receipt" type="Receipt" required>
      Current durable [receipt](/api/lifecycle) for that operation.
    </ResponseField>
  </Expandable>
</ResponseField>

## Behavior

Retained Cinder history, not native venue history. READ-agent projections omit owner grant commands that contain other agent keys. An operation may be durable while its external outcome remains unknown.

## Paging and errors

Read queries do not change financial state or consume order budgets.
Permissions filter rows **before** paging. Changed permitted rows return encrypted
`conflict`; restart at zero instead of combining revisions. End-of-pages covers
retained rows, not complete external venue history.

See [paging](/api/reads/paging), [errors](/api/errors), [limits](/api/limits)
and [availability](/status). A disconnected subscription needs fresh attestation,
current authority and a replacement snapshot.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.