The asset’s price source signs every NAV an order settles at, on its own node. Its feed, checked against the ledger’s NAV, adds an expiry and a kill switch, which a signature cannot provide. An outside provider plugs in as a nav source the engine compares, and never replaces that signature. This page connects both; what the administrator sends, by API or by file, is on Price source. Examples use $ENGINE for the engine’s URL and $TOKEN for a reader’s bearer.

The administrator’s feed

Set it up

  1. Add a nav source to the engine’s configuration (venue.recon.external.sources): an id, kind: nav, the instruments it states, and the tolerance its NAV may differ from the ledger’s by.
  2. Give the administrator’s connector its own identity, with a bearer in the feed role: it posts statements to its source and reads nothing else.
The administrator then posts each NAV to POST /v1/external-statements?externalSourceId=<the source's id>, and each statement starts a reconciliation run.

Expiry and kill switch

Each run checks the feed and holds the asset:
  • when the ripcord is pulled, at once, on receipt;
  • when the NAV has expired, at the first run after expiresAt;
  • on a mismatch, where the feed’s official NAV differs from the ledger’s NAV of the same business date by more than the source’s tolerance.
While held, the asset’s distributions and redemptions are refused instrument-held. A fresh NAV or a lowered ripcord clears the finding but not the hold; risk releases the hold, under two approvers (release a hold).
curl

The ledger’s NAV

The feed checks the NAV and never sets it. Only the price source signs the ledger’s NAV: the day’s NAV point, which valuations and distributions read and the feed is compared with, and each order’s own price (Subscribe and redeem). GET /v1/instruments/FUND/price answers the price now and the contract it comes from.

Oracles

Every NAV that moves value is read through one Daml interface, Oracle, which the price source publishes behind: The Oracle interface describes it, with PublishedNav and CAPS capsules. The engine reads the template its configuration names (venue.parties.oracle-template). Outside providers compares the options.
  • A provider’s NAV, such as Chainlink’s SmartData NAV, reaches the engine as a nav source: a connector of the deployment’s own fetches each report and posts it as a statement, in the same canonical JSON as the administrator’s, with its own expiresAt and ripcord. The engine compares its official NAV with the price source’s point. Set the source’s blocking: false to make its findings reports only.
  • It feeds checks and never prices an order. NodeAsset ships the nav source and its checks, and no provider connector. No NodeAsset transaction reads a provider’s contract, so a provider learns of no order, only of what it serves the connector.
Related: Price source and oracles · Price the asset · Pricing