nav source the engine compares, and never replaces that signature. This page connects both; what the administrator sends, by API or by file, is on Price source.
Examples use $ENGINE for the engine’s URL and $TOKEN for a reader’s bearer.
The administrator’s feed
Set it up
- Add a
navsource to the engine’s configuration (venue.recon.external.sources): anid,kind: nav, the instruments it states, and the tolerance its NAV may differ from the ledger’s by. - Give the administrator’s connector its own identity, with a bearer in the
feedrole: it posts statements to its source and reads nothing else.
POST /v1/external-statements?externalSourceId=<the source's id>, and each statement starts a reconciliation run.
Expiry and kill switch
Each run checks the feed and holds the asset:- when the ripcord is pulled, at once, on receipt;
- when the NAV has expired, at the first run after
expiresAt; - on a mismatch, where the feed’s official NAV differs from the ledger’s NAV of the same business date by more than the source’s tolerance.
instrument-held. A fresh NAV or a lowered ripcord clears the finding but not the hold; risk releases the hold, under two approvers (release a hold).
curl
The ledger’s NAV
The feed checks the NAV and never sets it. Only the price source signs the ledger’s NAV: the day’s NAV point, which valuations and distributions read and the feed is compared with, and each order’s own price (Subscribe and redeem).GET /v1/instruments/FUND/price answers the price now and the contract it comes from.
Oracles
Every NAV that moves value is read through one Daml interface,Oracle, which the price source publishes behind: The Oracle interface describes it, with PublishedNav and CAPS capsules. The engine reads the template its configuration names (venue.parties.oracle-template). Outside providers compares the options.
Chainlink, RedStone and Kaiko
- A provider’s NAV, such as Chainlink’s SmartData NAV, reaches the engine as a
navsource: a connector of the deployment’s own fetches each report and posts it as a statement, in the same canonical JSON as the administrator’s, with its ownexpiresAtandripcord. The engine compares its official NAV with the price source’s point. Set the source’sblocking: falseto make its findings reports only. - It feeds checks and never prices an order. NodeAsset ships the
navsource and its checks, and no provider connector. No NodeAsset transaction reads a provider’s contract, so a provider learns of no order, only of what it serves the connector.

