Skip to main content
venue: derive. Over HTTP, lyra, lyrafinance, lyrav2 and derivexyz also resolve to it. Derive is a self-custodial options, perps and spot exchange. Every action is authorized by an EIP-712 signature over its exact terms, so verify the unsigned params and sign only on ALLOW. A signed action is already authorized, whatever the verdict.

What to send

The params of the private API call, either bare or in the JSON-RPC envelope {method: "private/order", params: {...}}. Instrument names are parsed from Derive’s format: ETH-PERP, ETH-20260828-2600-P (put, strike $2,600, expiring 2026-08-28) and ETH-USDC. Bare params are typed by shape. Withdraw and deposit bodies are identical without the method, so a bare one is read as a withdrawal with a note; include the method. Detection without venue:
  • Orders with a perp or option instrument are detected. Spot pairs such as ETH-USDC also need two or more signing fields (subaccount_id, max_fee, signature_expiry_sec, signer, nonce).
  • Envelopes with a method from the table are detected. private/cancel, cancel_all, cancel_by_label, withdraw and deposit share names with Deribit’s API and also need subaccount_id. An unknown private/* method is classified only when venue is set.
  • Other bare shapes (withdrawals, transfers, session keys, cancels, RFQs) need Derive-specific fields. Set venue to be sure.

Live lookup

For order and replace on perp and option instruments, the adapter posts to https://api.lyra.finance/public/get_ticker. It adds whether the instrument exists and is active, and its mark price. It flags a limit price more than 20% from the mark, a price off the tick size, and an amount off the amount step or below the minimum. The timeout is 3.5 seconds and results are cached for 5 minutes. An unresolved instrument gets a note to treat the market and the order’s size as unverified and lean ESCALATE.

Notes the classifier adds

  • Selling an option without reduce_only writes short-option exposure.
  • limit_price is required even for market orders, where it is the worst fill the order accepts.
  • max_fee is signed into the order. When max_fee × amount exceeds 5% of notional, the note states the worst-case fee.
  • A signature_expiry_sec of 2,000,000,000 or more is flagged as a signature that never expires.
  • A payload that arrives already signed is flagged: the verdict can gate submission but no longer gates signing.
  • Session keys: admin scope can sign orders, withdrawals and transfers. account scope cannot sign orders or withdrawals. Granular scopes cannot be verified from this snapshot and lean ESCALATE. A raw on-chain registration (signed_raw_tx) defaults to admin whatever scope it states.
  • private/order_debug places nothing, but the same params are usually sent next. A replace is judged on the new order’s terms.
  • Trigger and TWAP orders, transfers of an asset named only by address, and an order that also carries session-key fields.

Example

From an MCP client

Instruct the agent to call verify_intent before signing any Derive action (orders, withdrawals, transfers, session keys), with your rules as intent, the exact params as action and venue: "derive", and to act only on ALLOW.
Derive’s Terms of Use restrict United States persons and other listed jurisdictions. A verdict checks an order against your rules. It does not make you eligible to trade on Derive.