What it runs
What it signs
The order is recorded before its NAV is known, and the price source prices it once its dealing point has closed (forward pricing). The fund’s consent takes a price only from the price source it names, so the price source signs nothing in the settlement itself. Who signs each transaction is on Price the asset.
The Oracle interface
Every NAV that moves value is read through one Daml interface,Oracle, in the package nodeasset-oracle-api. Its view is the asset (instrumentId), the NAV (nav), the withholding rate (withholdingRate) and the time it is as of (asOf). Reading a point checks that the asset’s own price source signed it, for that asset, with a NAV above zero and a rate from 0 up to, but not including, 1.
PublishedNav, innodeasset-oracle, is the smallest template that implements it, and the default.- A template of its own implements
Oracle, is signed by the price source alone, and names the venue’s party as an observer, since the venue reads what its party can see. The venue setsvenue.parties.oracle-templateto its name. - CAPS, if it publishes that way: the price source derives a capsule from its own CAPS feed, and an adapter template it signs presents the capsule as a NAV point behind
Oracle, adding the asset and the withholding rate. A capsule anyone else derived prices nothing. The same capsules can share the fund’s NAV with lenders and distributors, one capsule each.
PublishedNav; no NodeAsset package depends on CAPS.
Its NAV feed
Off the ledger, the price source sends its official NAV to the venue’s engine with what a signature cannot carry: an expiry and a kill switch. The engine checks the feed against the ledger’s NAV and holds the asset when they disagree, when the NAV expires, or when the kill switch is pulled (what the venue does with it). The venue gives the feed a client of its own at its identity provider, in thefeed role, which posts statements and reads nothing, and names the source it posts to.
By API
Post each NAV as canonical JSON to the source. The examples use$ENGINE for the venue’s engine and $FEED for the feed client’s bearer. The same bytes again answer 200 with the statement already stored, so a retry is safe; a new statement answers 201 with the reconciliation run its arrival started.
curl
Retry a 5xx or a lost answer. Set a 4xx aside with its problem: the same bytes get the same refusal. Decimals go as strings or plain JSON numbers.

