MMashDiv

The Convert settings page

Every tab of Admin → Convert → Settings, who may change what - the nine Super Admin keys, the three switches that live on the core Instant Convert house page, the one kill switch System Settings also carries - and why the page refuses a value rather than quietly correcting it.

3 min readUpdated 1 October 2026admin, settings, super-admin, kill-switch, validation

Admin → Convert → Settings (/admin/convert/settings). Reaching the page needs access.convert.settings, reading it view.convert.settings, saving edit.convert.settings. Every key, its default and its range is in the settings reference; this page is about how the screen behaves.

The tabs

Tab Holds
General Pause quoting, Mode (live or drain), and whether a balance convert needs two-factor.
Pricing The fee, the spread, the minimum spread without an exchange provider, and how long a quote holds.
Price guards The execution drift limit (last look), the quote impact limit, the reference venue and its deviation limit, and the two venues used without an exchange provider. See Pricing.
Limits Minimum and maximum per convert, per user per UTC day, all users per rolling hour, and the unhedged exposure cap.
Convert & Send The Send switch, and how long a payout that failed before broadcast keeps being retried. See Sends.
Hedging Mode and pause (read-only here), the hedge cycle, the hedge threshold, the order and hourly caps, the slippage limit and the failures before a pause. See Hedging.
Treasury House movements (read-only here) and the automatic profit sweep. The switch governs the hourly automatic sweep only; Sweep now on the P&L page works either way. See Movements and Profit & loss.

Who may change what

Nine keys need the Super Admin role, because one flip of any of them changes what happens to somebody else's money or widens what one bad hour can cost the house: convertQuotingPaused, convertMode, convertMaxUnhedgedUsd, convertHedgeMode, convertHedgePause, convertMaxHedgeUsdPerOrder, convertMaxHedgeUsdPerHour, convertRebalanceEnabled and convertPnlSweepEnabled. The six of them edited on this page carry a Super Admin only chip and an explanation; an admin without the role sees them read-only, with a lock and the current value, and the server re-checks the role on every save rather than trusting the page. Any key the platform itself marks protected is treated the same way.

Three of those have one editor, and it is not this page. Hedging mode, the hedging pause and house movements are changed only on the core Instant Convert house page (Finance → Transaction Management → Pool Backing, then the House inventory button), with the Super Admin role and a fresh two-factor code. That page works while Instant Convert is disabled, unlicensed or uninstalled, which is exactly when you need these switches. This page shows them read-only, even to a Super Admin, with a House page badge and an Open the house page link; a save that includes one is refused with the path of its editor.

One kill switch has two. convertQuotingPaused is on this page and also on System → Settings (Features, Instant Convert), so quoting can be stopped while the Convert console itself is unreachable. Every other convert* key is refused by System → Settings by name: the three house switches above are changed on the house page, and the rest here, where they are validated.

Refused, never corrected

A save sends only the keys you changed, as one all-or-nothing patch. A value the server would not accept is refused with a sentence naming the number it disagreed with; nothing is clamped. Somebody who types 60 into a 40 bps field and sees 60 afterwards believes the guard is at 60, so the page tells you instead.

Beyond each field's own range, four rules compare fields, judged on what the settings will be once the patch lands:

  • the execution drift limit must be below the spread;
  • the reference deviation limit must be below the spread;
  • the minimum convert may not exceed a non-zero maximum;
  • the reference venue cannot be your trading provider.

A rule only fires when the patch touches one of its fields, so an inconsistency already stored never blocks an unrelated save.

What the server reads

Settings are stored as text, and nothing seeds the table: a key you have never saved reads as its default, and the page shows that default. A value edited by hand in the database that the page would refuse is read as the default, not clamped: a spread of −40 clamped to 0 would price every convert at the raw book.

Every guard threshold, the hedge switches and the caps are server-only: the unauthenticated platform settings endpoint never serves them, so nobody can read when a quote is worth taking against the house. The eleven keys a browser can see are the quoting pause, the fee, the spread, the quote lifetime, the no-provider minimum spread, the per-convert minimum and maximum, the per-user daily limit, the two-factor requirement, the Send switch and the profit-sweep switch. Each is either shown to users anyway or says nothing about your position.