Price sources and signed prints
Boundary evidence, quorum checks, one resolution and the reasons a Window voids.
A Window settles from opening and closing boundary prints. A latest-price tile does not decide its result. The resolver uses the price policy frozen into that Window's MarketTerms.
Loading diagram…
Read diagram source
flowchart TD
sources[Named price sources] --> oracles[Three oracle parties]
oracles --> quotes[Signed PriceQuotes and payload hashes]
quotes --> check[Resolver checks each boundary]
check -->|Admitted quorum agrees| outcome[OpenPrint then Up or Down Resolution]
check -->|No admitted quotes| missing[MissingPrint]
check -->|Fewer than quorum| quorum[QuorumNotMet]
check -->|Quorum arrived but slot was not recorded in time| absent[ResolverAbsent]
check -->|Spread exceeds policy| disagreement[SourceDisagreement]
missing --> void[Void Resolution]
quorum --> void
absent --> void
disagreement --> void
void --> refund[Stake and fee returned on settlement]
The usual policy needs 2 of 3 distinct oracle parties, with a spread within 1% of the median. The contracts enforce the values copied into each Window's terms. A tie pays Up when tieUp is set, as in the listed price-call policy.
What a void reason means
| Reason | Meaning in Market.daml |
|---|---|
MissingPrint | No valid evidence was supplied for that boundary after its deadline. |
QuorumNotMet | Some valid evidence exists, but fewer distinct oracles than the required quorum. |
ResolverAbsent | Enough valid evidence exists, but the slot was not recorded before its deadline. |
SourceDisagreement | The valid quotes exceed the terms' maximum deviation. This can void during the opening or closing check. |
A missed deadline does not create a refund automatically. The resolver must record a void, then settlement returns stake and fee. If ops stays down, the owner can take a stale refund from refundAfter without an ops actor. Halts and voids explains the user path.
The named source
Each Series' policy names its source. Oracle parties sign what they read; an external provider is not itself a Canton party.
| Lane | Implemented source path | Dependency |
|---|---|---|
| BTC and ETH | Coinbase, Kraken and Bitstamp 1-minute candle closes, one exchange per oracle party | Exchange access and final candle data |
| Stocks | RedStone; QQQ and VOO use Alpaca's last IEX trade | Source access and stock session calendar |
| xStocks | Jupiter Price v3, median of three samples; a Switchboard adapter also exists | Read the Window's frozen policy for its actual source |
| Pre-IPO names | PreStocks catalogue | Catalogue access and rate limits |
| Baskets | Index in points derived from the PreStocks members | A valid read of every member |
| Valuation indices | Pyth index adapter | Entitled provider key; implementation alone does not make a lane live |
| Events | Committee attestations from oracle parties | Event terms and committee quorum |
Current listings and source health are shown in Markets and Status. This table describes source routing, not acceptance of every lane on hosted DevNet.
Timing and evidence
The crypto feeder starts Kraken and Bitstamp at T + 5 seconds, Coinbase at T + 10 seconds. These are fetch schedules, not a guaranteed result latency. Ledger confirmation, resolver work and projection add time. Admission limits and close deadlines come from the Window's policy.
Each quote carries the SHA-256 of its source payload. Ops attempts to archive the exact response. A quote on the ledger does not prove its archived payload is available: Proof reports missing evidence and re-verifies what it can read.
Three oracle parties read the named source; the resolver needs two that agree.
Choose a stage to read its responsibility and authority.01 · Crypto lanes
02 · Attested lanes
03 · Resolution
Three exchanges
Each oracle party reads its own exchange's 1-minute candle; the close of the candle ending at the boundary is its price.
One exchange per oracle party; a candle that is not final in time is not posted.
Each Window freezes its source policy. Crypto uses three exchanges; attested lanes use their named provider. These source paths do not establish present provider availability or acceptance of every lane on hosted DevNet.
Download diagram Full size