MMashDiv

Pricing - where a rate comes from and the guards that refuse it

How every convert is priced as two trades through USDT on your exchange provider's order books, the book cache that never serves a stale price, the reference venue, the impact cap, the last look and the loss bound it gives you, and the two-venue mode for installs without an exchange provider.

6 min readUpdated 1 October 2026admin, pricing, spread, fee, reference, last-look, order-book, no-provider

A convert's rate is the price at which the house could replace, on your exchange provider, the inventory it just paid out, plus the fee and the spread. Everything on this page exists to make sure that price is real at the moment it is promised, and still real a moment later when it is kept.

The route: always through USDT, one taker fee per trade

A convert from C1 to C2 is priced as the market trades the house would make through USDT, walking the books for the size:

  1. Sell C1 into the C1/USDT bids, walking down the book;
  2. Buy C2 from the C2/USDT asks with what step 1 raised.

Each trade pays a taker fee, read from the market's metadata on your provider. When the metadata has none, 20 bps is assumed, above the standard taker tier of every curated venue, so an unknown fee is over-charged to the user and never under-charged to the house. When C1 or C2 is USDT the route is a single trade.

A direct C1/C2 market is never used to improve the rate. It carries one fee where the hedge pays two, so pricing from it would promise a rate the hedge cannot achieve. It is read only as a one-sided sanity bound: when a tight direct book says the route is too generous to the user by more than the reference deviation, one of the three books is wrong in the user's favour, and the quote is refused.

Then, on the result:

Amount Is
amountIn what the user gives, fee included, in C1
feeAmount amountIn × convertFeeBps / 10,000, in C1, rounded half-up
net amountIn − feeAmount: what the house receives, and what is walked
amountOut the walked route, less each trade's taker fee, less the spread, rounded down
rate amountOut / amountIn
usdValue the trade's USDT value on the route, used for every USD limit

Every amount is rounded to the precision the wallet ledger itself uses for that currency, so each ledger entry written later is exactly the figure the quote stored. A user sizing the convert by what they want to receive is solved backwards through the same books and then checked forwards, so they are never charged a unit more than the forward arithmetic needs.

The book cache

  • Every book comes through one cache, one snapshot per venue and symbol, shared across every backend process. A quote is served a snapshot up to 1.5 seconds old; the last look uses one at most 2 seconds old; a book older than 3 seconds is stale and refused, and its cached copy has already expired.
  • One process refreshes a symbol at a time, under a Redis lease. Another that needs it waits briefly for that copy and refuses if it does not arrive. There is no fallback to an older or cheaper price. In particular, the platform's ticker hash, which has no expiry and no timestamp, is never read.
  • A venue that answers "rate limited" opens Convert's own circuit breaker for that venue: 30 seconds, doubling on repeats within ten minutes, up to five minutes, shared by every process. While it is open, quotes are refused.
  • The platform's own exchange ban flag is honoured: while it is set, no provider book is read. And a failed quote read never restarts the shared trading connection, which could itself trigger the platform-wide ban and stop Spot trading for everybody.

The four guards

Every guard refuses; none widens the price to make a quote fit. Their limits are server-only settings: the public settings endpoint never serves them, and a refusal never names the venue, the guard or the number. A user who could read the drift limit would know exactly when a quote is worth taking against you.

Reference venue (convertReferenceProvider, default auto, shown as Automatic (another venue)). Each market's mid on your provider is compared with the same symbol's mid on a second, keyless public venue, before the spread and fee. The quote is refused when they differ by more than convertMaxRefDeviationBps (default 40 bps), and also when the reference cannot be read. Automatic picks a curated venue that is not your trading provider, and when that venue does not list the symbol at all it moves on to the next, up to three. A venue you name is used and nothing else. The reference cannot be your trading provider: on the same venue it would compare the cache with itself and pass everything, and the settings page refuses that choice. Curated venues: Binance, OKX, Bybit, KuCoin, Bitget, Gate, MEXC, Kraken, Coinbase, XT.

Impact (convertMaxQuoteImpactBps, default 100 bps). A quote whose walk moves the price by more than this, or runs off the end of the book, is refused: This amount is too large to convert at a fair price right now. Try a smaller amount. This is what stops one large convert eating through a thin book.

Last look (convertMaxExecDriftBps, default 15 bps). At execution the books are read again and the same convert priced now. If the held quote has become better for the user than that by more than the limit, the convert is refused: The price moved. Get a new quote. A move in the user's favour executes as quoted.

Staleness and availability. No book, a stale book, a ban, an open breaker, a venue that lists no USDT market for the coin: Prices are temporarily unavailable for ETH or There is no market to price ETH right now.

Every quote records what it was built from in its priceInputs: each book read and when, the reference mids, the impact, the spread actually applied. Open any order under Admin → Convert → Orders to see them under How this rate was built; the record exactly as stored is folded under Technical data (for support).

The bound this gives you

Both guard limits must stay below the spread, and the settings page refuses a save that breaks that. On a convert that executes, the house loses at most the execution drift plus whatever the market does over the book's age (two seconds) and the time the hedge takes to follow. With hedging keeping up, that is less than the spread plus the fee, so every convert is priced to earn something. Turn hedging off and the "time the hedge takes" is however long you leave the position open.

Pricing without an exchange provider

With no exchange provider configured, Spot converts are refused (there is nothing to price Spot inventory on and nothing to hedge it with), and so are Sends paid from a Spot balance; nothing is hedged either. Ecosystem converts, and Sends paid from an Ecosystem balance, still run, priced from the keyless books of two public venues:

  • convertNoProviderVenues: auto (Binance and OKX), or two different venues you name, comma-separated (on the settings page, Venues without an exchange provider reads Automatic (Binance and OKX), or Two venues I choose with the two picked by name);
  • the route is walked on both, and the quote takes the rate worse for the house;
  • the two venues are each other's reference: they must agree within convertMaxRefDeviationBps, and either one down refuses the quote;
  • the spread is never below convertNoProviderMinSpreadBps (default 100 bps), because nothing can be hedged;
  • every such convert counts against the unhedged exposure cap.

The settings

Setting Default Range
convertFeeBps 20 0 to 5000 bps
convertSpreadBps 50 0 to 5000 bps; must stay above the two guards below
convertMaxExecDriftBps 15 0 to 5000 bps, below the spread
convertMaxRefDeviationBps 40 0 to 5000 bps, below the spread
convertMaxQuoteImpactBps 100 0 to 5000 bps
convertReferenceProvider auto auto, or a curated venue that is not your trading provider
convertNoProviderVenues auto auto, or two different curated venues
convertNoProviderMinSpreadBps 100 0 to 5000 bps
convertQuoteTtlSeconds 10 3 to 60 seconds

A longer quote lifetime gives users more time to read and gives anyone watching the market a longer free option on the price. The last look bounds what that option can cost, but only to the drift limit.