venue: derive. Over HTTP, lyra, lyrafinance, lyrav2 and derivexyz also resolve to it.
Derive is a self-custodial options, perps and spot exchange. Every action is authorized by an EIP-712 signature over its exact terms, so verify the unsigned params and sign only on ALLOW. A signed action is already authorized, whatever the verdict.
What to send
The params of the private API call, either bare or in the JSON-RPC envelope{method: "private/order", params: {...}}. Instrument names are parsed from Derive’s format: ETH-PERP, ETH-20260828-2600-P (put, strike $2,600, expiring 2026-08-28) and ETH-USDC.
Bare params are typed by shape. Withdraw and deposit bodies are identical without the method, so a bare one is read as a withdrawal with a note; include the method.
Detection without
venue:
- Orders with a perp or option instrument are detected. Spot pairs such as
ETH-USDCalso need two or more signing fields (subaccount_id,max_fee,signature_expiry_sec,signer,nonce). - Envelopes with a method from the table are detected.
private/cancel,cancel_all,cancel_by_label,withdrawanddepositshare names with Deribit’s API and also needsubaccount_id. An unknownprivate/*method is classified only whenvenueis set. - Other bare shapes (withdrawals, transfers, session keys, cancels, RFQs) need Derive-specific fields. Set
venueto be sure.
Live lookup
Fororder and replace on perp and option instruments, the adapter posts to https://api.lyra.finance/public/get_ticker. It adds whether the instrument exists and is active, and its mark price. It flags a limit price more than 20% from the mark, a price off the tick size, and an amount off the amount step or below the minimum. The timeout is 3.5 seconds and results are cached for 5 minutes. An unresolved instrument gets a note to treat the market and the order’s size as unverified and lean ESCALATE.
Notes the classifier adds
- Selling an option without
reduce_onlywrites short-option exposure. limit_priceis required even for market orders, where it is the worst fill the order accepts.max_feeis signed into the order. Whenmax_fee × amountexceeds 5% of notional, the note states the worst-case fee.- A
signature_expiry_secof 2,000,000,000 or more is flagged as a signature that never expires. - A payload that arrives already signed is flagged: the verdict can gate submission but no longer gates signing.
- Session keys:
adminscope can sign orders, withdrawals and transfers.accountscope cannot sign orders or withdrawals. Granular scopes cannot be verified from this snapshot and lean ESCALATE. A raw on-chain registration (signed_raw_tx) defaults to admin whatever scope it states. private/order_debugplaces nothing, but the same params are usually sent next. A replace is judged on the new order’s terms.- Trigger and TWAP orders, transfers of an asset named only by address, and an order that also carries session-key fields.
Example
From an MCP client
Instruct the agent to callverify_intent before signing any Derive action (orders, withdrawals, transfers, session keys), with your rules as intent, the exact params as action and venue: "derive", and to act only on ALLOW.
Derive’s Terms of Use restrict United States persons and other listed jurisdictions. A verdict checks an order against your rules. It does not make you eligible to trade on Derive.
