Halt trading under a policy
Halts trading under this policy at once — any active member of the organisation may, with no capability and no approval; orders it governs are refused TRADING_HALTED until a resumption is approved. A pending proposal on the policy survives.
Authentication
Bearer authentication of the form Bearer <token>, where token is your auth token.
Path parameters
The record's id — a positive 32-bit integer the platform minted.
Headers
Required on every write: a URL-safe string of 1 to 64 characters from [A-Za-z0-9._~-] (a UUID fits), scoped to you. It names one operation on one record, ever: a retry replays the stored outcome (Idempotent-Replay: true) or attaches to the live one, and reuse on another record refuses 409 IDEMPOTENCY_KEY_REUSED. Missing or malformed, 400.
The ETag the read minted, quoted or bare; absent or * is unconditional; a weak validator refuses 400 INVALID_IF_MATCH. A stale value answers 412 VERSION_CONFLICT with currentVersion and a fresh ETag: re-read, reapply, retry. Send it — every write restates the whole record, so an unconditional write overwrites every field from your copy, and an amend against a pending proposal replaces that proposal.
Request
0 = unconditional — a halt must never lose a version race. int64 as a decimal JSON string
Response
The trading policy as the platform now holds it after the write — the same row the read serves, with the answering change's position, the row's ETag and, on a replayed key, Idempotent-Replay.
The position as a decimal string — the last change this member had applied, orders and balance readings included.
Owner-stamped.
ACTIVATE, AMEND, RETIRE or RESUME_TRADING; NONE otherwise. NONE is the unset sentinel: outputs only — as input, omit the field instead; explicit NONE refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as NONE, never as an error; as input an unknown name refuses 400 — the parse is strict
UNKNOWN is the unset sentinel: outputs only — as input, omit the field instead; explicit UNKNOWN refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as UNKNOWN, never as an error; as input an unknown name refuses 400 — the parse is strict
The row's version — monotonic per record, bumped on every change; orders record which version governed them. int64 as a decimal JSON string
The admission tolerance for a degraded connection: an order-entry credential whose connection has been DEGRADED for no longer than this still admits; DOWN always refuses, and a cancel never gates. 0 = any DEGRADED refuses (the strict reading). Measured from the health fact's envelope time, so every member agrees. int64 as a decimal JSON string
How stale an accepted but never instructed order may be when it reaches the venue: past it the connector never places it and the order disposes toward INSTRUCTION_EXPIRED. 0 = the connector's configured default window, never a lockout. int64 as a decimal JSON string
The refdata instrument — carried, not resolved here; 0 = the organisation-wide default row. int64 as a decimal JSON string
The halt: true on the organisation-wide default row halts the organisation; true on a per-instrument row halts that instrument. False is the decode default — but no order is admitted without an ACTIVE policy row at all: the real gate is the row's existence. a boolean; absent reads false
Open-order ceiling; 0 = none. Counted over the organisation's open orders as a whole: the tighter of the governing row's and the organisation-wide default row's stated ceilings binds. A per-instrument row's ceiling is not yet scoped to its instrument.
Per-order notional cap; 0 = no cap; refused non-zero on org-default rows as maxOrderQty. money (a Decimal on the wire: a scaled integer with its own scale), served as an exact decimal string at the value's own scale — every fractional digit that scale states, trailing zeros included; never raw; null when the 0 sentinel means unset
Per-order quantity cap; 0 = no cap. The organisation-wide default row has no scale context — a non-zero value on it is refused INVALID_FIELD. money (a Decimal on the wire: a scaled integer with its own scale), served as an exact decimal string at the value's own scale — every fractional digit that scale states, trailing zeros included; never raw; null when the 0 sentinel means unset
Entry-rate ceiling per tumbling minute of stream time, enforced at the orders owner; 0 = no ceiling. Counted over the organisation's accepted orders in the minute: the tighter of the governing row's and the organisation-wide default row's stated ceilings binds, as maxOpenOrders does.
The user whose proposal is pending, so an approver is checked to be someone else; 0 when nothing is pending.
The limit-price collar against the market-data top-of-book reference; 0 = no collar — the reference-freshness gate still applies unconditionally, since the reference is mandatory.
How fresh the top-of-book reference must be at admission (the NO_REFERENCE_PRICE gate); 0 disables the age comparison alone — the reference itself stays mandatory for every order type, so an absent reference refuses either way. int64 as a decimal JSON string
Never present since 0.3.3: every money value on this API states its own scale on the wire — a policy amount or cap since 0.3.3, an order's and an execution's since 0.3.2, a balance's since 0.3.1 — so a row is never served raw, whether or not this member holds the asset or instrument it references. Kept, deprecated, so a client generated from 0.3.2 still compiles; it goes at the next major.