OwarineDocs
Open app
How it works

Price sources and signed prints

Boundary evidence, quorum checks, one resolution and the reasons a Window voids.

Reviewed 2026-10-06

A Window settles from opening and closing boundary prints. A latest-price tile does not decide its result. The resolver uses the price policy frozen into that Window's MarketTerms.

Prints, resolution and refunds

Loading diagram…

Read diagram source

flowchart TD
sources[Named price sources] --> oracles[Three oracle parties]
oracles --> quotes[Signed PriceQuotes and payload hashes]
quotes --> check[Resolver checks each boundary]
check -->|Admitted quorum agrees| outcome[OpenPrint then Up or Down Resolution]
check -->|No admitted quotes| missing[MissingPrint]
check -->|Fewer than quorum| quorum[QuorumNotMet]
check -->|Quorum arrived but slot was not recorded in time| absent[ResolverAbsent]
check -->|Spread exceeds policy| disagreement[SourceDisagreement]
missing --> void[Void Resolution]
quorum --> void
absent --> void
disagreement --> void
void --> refund[Stake and fee returned on settlement]

The usual policy needs 2 of 3 distinct oracle parties, with a spread within 1% of the median. The contracts enforce the values copied into each Window's terms. A tie pays Up when tieUp is set, as in the listed price-call policy.

What a void reason means

ReasonMeaning in Market.daml
MissingPrintNo valid evidence was supplied for that boundary after its deadline.
QuorumNotMetSome valid evidence exists, but fewer distinct oracles than the required quorum.
ResolverAbsentEnough valid evidence exists, but the slot was not recorded before its deadline.
SourceDisagreementThe valid quotes exceed the terms' maximum deviation. This can void during the opening or closing check.

A missed deadline does not create a refund automatically. The resolver must record a void, then settlement returns stake and fee. If ops stays down, the owner can take a stale refund from refundAfter without an ops actor. Halts and voids explains the user path.

The named source

Each Series' policy names its source. Oracle parties sign what they read; an external provider is not itself a Canton party.

LaneImplemented source pathDependency
BTC and ETHCoinbase, Kraken and Bitstamp 1-minute candle closes, one exchange per oracle partyExchange access and final candle data
StocksRedStone; QQQ and VOO use Alpaca's last IEX tradeSource access and stock session calendar
xStocksJupiter Price v3, median of three samples; a Switchboard adapter also existsRead the Window's frozen policy for its actual source
Pre-IPO namesPreStocks catalogueCatalogue access and rate limits
BasketsIndex in points derived from the PreStocks membersA valid read of every member
Valuation indicesPyth index adapterEntitled provider key; implementation alone does not make a lane live
EventsCommittee attestations from oracle partiesEvent terms and committee quorum

Current listings and source health are shown in Markets and Status. This table describes source routing, not acceptance of every lane on hosted DevNet.

Timing and evidence

The crypto feeder starts Kraken and Bitstamp at T + 5 seconds, Coinbase at T + 10 seconds. These are fetch schedules, not a guaranteed result latency. Ledger confirmation, resolver work and projection add time. Admission limits and close deadlines come from the Window's policy.

Each quote carries the SHA-256 of its source payload. Ops attempts to archive the exact response. A quote on the ledger does not prove its archived payload is available: Proof reports missing evidence and re-verifies what it can read.

Where a Canton print comes fromOwarine

Three oracle parties read the named source; the resolver needs two that agree.

Choose a stage to read its responsibility and authority.

01 · Crypto lanes

candle close
signed quote
evidence

02 · Attested lanes

read at T
signed quote
named source

03 · Resolution

open recorded
close admitted
public read
STAGE 1.1

Three exchanges

Each oracle party reads its own exchange's 1-minute candle; the close of the candle ending at the boundary is its price.

AUTHORITY BOUNDARY

One exchange per oracle party; a candle that is not final in time is not posted.

Each Window freezes its source policy. Crypto uses three exchanges; attested lanes use their named provider. These source paths do not establish present provider availability or acceptance of every lane on hosted DevNet.

Download diagram Full size

On this page