> ## Documentation Index
> Fetch the complete documentation index at: https://docs.trdrs.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Store a risk policy version

> Stores one version of a risk policy: the margin, stop-out, valuation, settlement and posting terms your accounts are held to. A stored version applies to no account until you publish it, and it can never change, so a changed term is always a new version. The response names the version, and the same content sent again returns it with `created: false` and status `200`. Required scope: `venue:configure`. Preview: served on the sandbox to every venue, and production availability is arranged when a venue qualifies. Trading API keys and Partner keys do not authorize these routes.



## OpenAPI

````yaml /api/openapi.json post /api/partner/venues/{venueId}/risk-policies
openapi: 3.1.0
info:
  title: trdrs Engine API
  version: 1.1.0
  description: >-
    ## API Reference


    Every route the trdrs engine serves, with what to send and what comes back.
    It covers market

    data and news, trading and account state for a trader's own software,
    Connect pre-registration,

    the venue routes a prop firm or brokerage runs its accounts through, and the
    Legacy Partner API.


    Start with the Quickstart for your first call. The API standards hold the
    rules every route

    shares: keys, errors, rate limits, idempotency, paging and streaming.
servers:
  - url: https://app.trdrs.co
    description: Production
  - url: /
    description: This engine
security: []
tags:
  - name: Venue platform preview
    description: >-
      Run your venue: its providers, instruments, conditions, groups, routes,
      stages, venue rules, keys, accounts, usage, balance receipts and webhooks.
      These routes are in preview. They are served on the sandbox to every
      venue, and production access is arranged when a venue qualifies. Every
      route here under `/api/partner/` takes a Venue key. The back office
      reaches the same routes under `/api/operator/` with a verified owner’s
      session, because a browser never holds a Venue key, and both run the same
      checks. Changes to these routes are additive only from here on, and the
      Legacy Partner API routes stay as they are.
  - name: Market data
    description: >-
      Search and look up symbols, read price history and quotes, check the
      server clock, and stream live bars. Crypto prices come from each
      provider’s public feed. Futures prices are licensed to each user and
      stream from your own login at a provider that carries them, so without one
      connected, a futures request answers 503 `feed_requires_connection`.
  - name: News
    description: >-
      Market news and the economic calendar, from licensed and open sources,
      tagged with futures roots as they arrive. The content is the same for
      everyone, and these routes admit the same callers as market data: a
      licensed origin, a session or a Trading API key. Page headlines by publish
      time, filter them by instrument root, and stream them live over
      server-sent events. Thumbnails come through the image route.
  - name: Trading
    description: >-
      Place, change and cancel orders, set a position’s exits, and close or
      flatten positions. Every call that places an order takes a `clientOrderId`
      as its idempotency key.
  - name: Account
    description: >-
      Read an account a trader can trade: its balance, positions, working
      orders, fills, profit and loss history, and the live account stream. You
      don’t create accounts here. A trader connects their own account at a
      provider, or opens their own Demo on the paper book, in the trdrs app. A
      venue issues accounts on the paper book with Issue an account into a
      group, and a firm pre-registers accounts at a provider through Connect
      with Pre-register a trader’s account.
  - name: Connect
    description: >-
      Connect is the account picker a trader opens, in the trdrs app or embedded
      on a firm’s site. It lists the built-in providers and every listed venue.
      The pre-registration routes let a firm fill it in ahead of time. You tell
      trdrs that a trader has an account at a built-in provider: their sign-in
      email, and optionally the account number and login name. When that trader
      signs in, Connect shows the account ready to link, and they sign in to the
      provider themselves, once. Nothing here sends a password or grants access
      before the trader’s own login succeeds. You can list who you
      pre-registered and who has linked, and cancel a pre-registration that
      hasn’t been used. A pre-registration expires after 30 days, and sending it
      again refreshes it. These routes take the Partner key. They belong to
      Connect, not to the Legacy Partner API. The whole flow is in the **[Quick
      Start](/docs/guides/quick-start)**.
  - name: Firm accounts (legacy)
    description: >-
      Legacy Partner API. Each route here has a venue twin under
      `/api/partner/venues/{venueId}/accounts…`, which takes a Venue key and a
      named scope, and new integrations use those. This group stays for firms
      that predate venues, and both run the same operation. These routes issue
      and manage evaluation accounts on the paper book with your Partner key:
      the trader trades them on trdrs, and your firm owns their lifecycle. Every
      route sees only the accounts your firm created through this API, so an
      account the same trader opened themselves is invisible here. Creation is
      batched with a result per item, and every write carries your own
      `referenceId`, so a pipeline that crashes can retry safely. These routes
      are served where the engine runs prop evaluations. Elsewhere, every route
      in this group answers `404`.
  - name: Billing
    description: >-
      Legacy Partner API, per firm. What your firm is billed for in a month,
      counted from its fills, and the accounts behind the number. The venue
      routes Read the venue’s metered usage for a month and Read the accounts
      behind the venue’s usage replace these, which still take the Partner key.
  - name: Webhooks
    description: >-
      Legacy Partner API. The venue routes Register a webhook, List the venue’s
      webhooks and Read a webhook’s delivery log replace these, with a Venue
      key, and an endpoint registered either way receives the same events.
      Register an https endpoint, and trdrs pushes events to it, so your back
      office doesn’t have to poll. Every delivery is signed (`trdrs-signature:
      t=<unix>,v1=<hmac-sha256>` over `${t}.${rawBody}`), so you can prove it
      came from trdrs and is fresh. Every delivery is also durable: a failed
      attempt is retried with backoff for about nine hours, and the whole log is
      readable, so an endpoint that was down gets its events late rather than
      never. The pre-registration events (`registration.*`) fire wherever
      Connect runs, and the account events fire where the engine runs prop
      evaluations.
  - name: Challenges
    description: >-
      Legacy Partner API. Stage policies on a venue replace the firm’s half of
      this, and the trader’s enrollment flow has not moved yet. These routes
      list evaluation programs and a trader’s own enrollments. **Preview: the
      one group in this reference outside the additive-only guarantee.** Their
      shapes will change when challenges are rebuilt; see Stability. **They take
      a signed-in session, not a key**, and are served only where the engine
      runs with `CHALLENGES_ENABLED`. Without it, the routes don’t exist and
      every one answers `404`. The administration half isn’t documented here,
      because it is trdrs’s own tooling, not part of the API.
paths:
  /api/partner/venues/{venueId}/risk-policies:
    post:
      tags:
        - Venue platform preview
      summary: Store a risk policy version
      description: >-
        Stores one version of a risk policy: the margin, stop-out, valuation,
        settlement and posting terms your accounts are held to. A stored version
        applies to no account until you publish it, and it can never change, so
        a changed term is always a new version. The response names the version,
        and the same content sent again returns it with `created: false` and
        status `200`. Required scope: `venue:configure`. Preview: served on the
        sandbox to every venue, and production availability is arranged when a
        venue qualifies. Trading API keys and Partner keys do not authorize
        these routes.
      parameters:
        - name: venueId
          in: path
          required: true
          schema:
            type: string
            format: uuid
        - name: Idempotency-Key
          in: header
          required: true
          schema:
            type: string
            minLength: 1
            maxLength: 128
          description: >-
            A key you choose, 1 to 128 characters, that identifies this write.
            Send the same key when you retry it, so the write is never applied
            twice.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/VenueRiskPolicyStoreRequest'
      responses:
        '201':
          description: >-
            Success. The response is sent with `Cache-Control: no-store`, so
            don't cache it.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/VenueRiskPolicyStoreResponse'
        '400':
          description: >-
            The policy breaks a rule of the risk policy contract, and `field`
            names the value refused. A figure marked unsourced can be stored,
            but never published.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: >-
            The Venue key or the session is missing, malformed, revoked or
            expired.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: >-
            The credential is valid but can't do this: the key lacks the scope
            or its creator is no longer an owner, the email isn't verified, a
            reader tried to write, or the request came from an origin that isn't
            trusted.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '404':
          description: >-
            The venue, account or resource doesn't exist in this environment, or
            isn't yours to see.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '409':
          description: >-
            `risk_policy_version_conflict`: the version is stored with other
            content. `risk_policy_owner_conflict`: the policy id belongs to
            another venue or to trdrs, since a policy's first version fixes its
            owner. `risk_policy_id_reserved`: the id starts with `trdrs-`.
            `risk_policy_posting_mismatch`: the posting term doesn't state each
            currency at the precision trdrs posts it in, two decimals for USD
            and six for USDC and USDT.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '413':
          description: The body is larger than this route accepts.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '415':
          description: 'Send the body as JSON, with `Content-Type: application/json`.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '503':
          description: >-
            trdrs can't complete the request right now, because a part of the
            venue platform or its credential store is unavailable. Don't assume
            a write happened: retry it with the same `Idempotency-Key`.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - venueOperatorKey: []
      x-codeSamples:
        - lang: javascript
          label: TypeScript
          source: >-
            const res = await
            fetch('https://app.trdrs.co/api/partner/venues/{venueId}/risk-policies',
            {
              method: 'POST',
              headers: {
                'content-type': 'application/json',
                Authorization: `Bearer ${process.env.TRDRS_VENUE_KEY}`,
                "Idempotency-Key": "example-request-1",
              },
              body: JSON.stringify({
                "policy": {
                  "policyId": "meridian-futures",
                  "version": "2026-10-01",
                  "authority": {
                    "kind": "firm",
                    "venueId": "00000000-0000-0000-0000-000000000001",
                    "name": "Meridian Futures"
                  },
                  "currency": "USD",
                  "pools": {
                    "futures": {
                      "margin": {
                        "version": "margin-2026-10-01",
                        "authority": "firm",
                        "source": "the venue's own terms",
                        "effectiveFrom": "2026-10-01T00:00:00.000Z",
                        "effectiveUntil": null,
                        "asset": "USD",
                        "basis": "per_contract",
                        "window": {
                          "timeZone": "America/Chicago",
                          "startMinute": 510,
                          "exposureCutoffMinute": 900,
                          "endMinute": 915,
                          "weekdays": [
                            1,
                            2,
                            3,
                            4,
                            5
                          ],
                          "closedDates": []
                        },
                        "closeOnly": "at_roll",
                        "contracts": [
                          {
                            "contract": "CME:NQZ2026",
                            "root": "NQ",
                            "day": {
                              "initial": "1000",
                              "maintenance": "500",
                              "sources": {
                                "initial": {
                                  "authority": "firm",
                                  "source": "the venue's own terms",
                                  "sourced": true
                                },
                                "maintenance": {
                                  "authority": "firm",
                                  "source": "the venue's own terms",
                                  "sourced": true
                                }
                              }
                            },
                            "overnight": {
                              "initial": "43207",
                              "maintenance": "43207",
                              "sources": {
                                "initial": {
                                  "authority": "firm",
                                  "source": "the venue's own terms",
                                  "sourced": true
                                },
                                "maintenance": {
                                  "authority": "firm",
                                  "source": "the venue's own terms",
                                  "sourced": true
                                }
                              }
                            }
                          }
                        ]
                      },
                      "thresholds": {
                        "version": "thresholds-2026-10-01",
                        "authority": "firm",
                        "source": "the venue's own terms",
                        "effectiveFrom": "2026-10-01T00:00:00.000Z",
                        "effectiveUntil": null,
                        "marginCall": null,
                        "stopOut": "1",
                        "recoveryLevel": "1.1",
                        "sources": {
                          "marginCall": {
                            "authority": "firm",
                            "source": "the venue's own terms",
                            "sourced": true
                          },
                          "stopOut": {
                            "authority": "firm",
                            "source": "the venue's own terms",
                            "sourced": true
                          },
                          "recoveryLevel": {
                            "authority": "firm",
                            "source": "the venue's own terms",
                            "sourced": true
                          }
                        }
                      },
                      "valuation": {
                        "version": "valuation-2026-10-01",
                        "authority": "firm",
                        "source": "the venue's own terms",
                        "effectiveFrom": "2026-10-01T00:00:00.000Z",
                        "effectiveUntil": null,
                        "maxAgeMs": 5000
                      },
                      "ticketHedging": null
                    },
                    "crypto_derivative": null
                  },
                  "settlement": {
                    "version": "settlement-2026-10-01",
                    "authority": "firm",
                    "source": "the venue's own terms",
                    "effectiveFrom": "2026-10-01T00:00:00.000Z",
                    "effectiveUntil": null,
                    "kind": "settlement_asset"
                  },
                  "posting": {
                    "version": "posting-2026-10-01",
                    "authority": "firm",
                    "source": "the venue's own terms",
                    "effectiveFrom": "2026-10-01T00:00:00.000Z",
                    "effectiveUntil": null,
                    "currencies": [
                      {
                        "currency": "USD",
                        "decimals": 2,
                        "rounding": "half_even",
                        "source": {
                          "authority": "publisher",
                          "source": "ISO 4217: USD minor unit 2",
                          "sourced": true,
                          "document": null
                        }
                      }
                    ]
                  }
                }
              }),
            })

            const data = await res.json()
        - lang: shell
          label: cURL
          source: >-
            curl -X POST
            'https://app.trdrs.co/api/partner/venues/{venueId}/risk-policies' \
              -H "Authorization: Bearer $TRDRS_VENUE_KEY" \
              -H 'Idempotency-Key: example-request-1' \
              -H 'content-type: application/json' \
              -d '{"policy":{"policyId":"meridian-futures","version":"2026-10-01","authority":{"kind":"firm","venueId":"00000000-0000-0000-0000-000000000001","name":"Meridian Futures"},"currency":"USD","pools":{"futures":{"margin":{"version":"margin-2026-10-01","authority":"firm","source":"the venue's own terms","effectiveFrom":"2026-10-01T00:00:00.000Z","effectiveUntil":null,"asset":"USD","basis":"per_contract","window":{"timeZone":"America/Chicago","startMinute":510,"exposureCutoffMinute":900,"endMinute":915,"weekdays":[1,2,3,4,5],"closedDates":[]},"closeOnly":"at_roll","contracts":[{"contract":"CME:NQZ2026","root":"NQ","day":{"initial":"1000","maintenance":"500","sources":{"initial":{"authority":"firm","source":"the venue's own terms","sourced":true},"maintenance":{"authority":"firm","source":"the venue's own terms","sourced":true}}},"overnight":{"initial":"43207","maintenance":"43207","sources":{"initial":{"authority":"firm","source":"the venue's own terms","sourced":true},"maintenance":{"authority":"firm","source":"the venue's own terms","sourced":true}}}}]},"thresholds":{"version":"thresholds-2026-10-01","authority":"firm","source":"the venue's own terms","effectiveFrom":"2026-10-01T00:00:00.000Z","effectiveUntil":null,"marginCall":null,"stopOut":"1","recoveryLevel":"1.1","sources":{"marginCall":{"authority":"firm","source":"the venue's own terms","sourced":true},"stopOut":{"authority":"firm","source":"the venue's own terms","sourced":true},"recoveryLevel":{"authority":"firm","source":"the venue's own terms","sourced":true}}},"valuation":{"version":"valuation-2026-10-01","authority":"firm","source":"the venue's own terms","effectiveFrom":"2026-10-01T00:00:00.000Z","effectiveUntil":null,"maxAgeMs":5000},"ticketHedging":null},"crypto_derivative":null},"settlement":{"version":"settlement-2026-10-01","authority":"firm","source":"the venue's own terms","effectiveFrom":"2026-10-01T00:00:00.000Z","effectiveUntil":null,"kind":"settlement_asset"},"posting":{"version":"posting-2026-10-01","authority":"firm","source":"the venue's own terms","effectiveFrom":"2026-10-01T00:00:00.000Z","effectiveUntil":null,"currencies":[{"currency":"USD","decimals":2,"rounding":"half_even","source":{"authority":"publisher","source":"ISO 4217: USD minor unit 2","sourced":true,"document":null}}]}}}'
components:
  schemas:
    VenueRiskPolicyStoreRequest:
      type: object
      additionalProperties: false
      properties:
        policy:
          type: object
          description: >-
            One version of an account risk policy, as the risk policy contract
            states it: the policy id and version, the authority (a firm, naming
            this venue), the account currency, the terms of each product class
            it offers, the settlement term and the posting term. A product class
            carries its futures margin by dated contract or its crypto
            derivative collateral, its thresholds and its valuation age, each
            term with its own version, authority, source and effective dates.
            Anything else is refused, with `field` naming what.
      required:
        - policy
      example:
        policy:
          policyId: meridian-futures
          version: '2026-10-01'
          authority:
            kind: firm
            venueId: 00000000-0000-0000-0000-000000000001
            name: Meridian Futures
          currency: USD
          pools:
            futures:
              margin:
                version: margin-2026-10-01
                authority: firm
                source: the venue's own terms
                effectiveFrom: '2026-10-01T00:00:00.000Z'
                effectiveUntil: null
                asset: USD
                basis: per_contract
                window:
                  timeZone: America/Chicago
                  startMinute: 510
                  exposureCutoffMinute: 900
                  endMinute: 915
                  weekdays:
                    - 1
                    - 2
                    - 3
                    - 4
                    - 5
                  closedDates: []
                closeOnly: at_roll
                contracts:
                  - contract: CME:NQZ2026
                    root: NQ
                    day:
                      initial: '1000'
                      maintenance: '500'
                      sources:
                        initial:
                          authority: firm
                          source: the venue's own terms
                          sourced: true
                        maintenance:
                          authority: firm
                          source: the venue's own terms
                          sourced: true
                    overnight:
                      initial: '43207'
                      maintenance: '43207'
                      sources:
                        initial:
                          authority: firm
                          source: the venue's own terms
                          sourced: true
                        maintenance:
                          authority: firm
                          source: the venue's own terms
                          sourced: true
              thresholds:
                version: thresholds-2026-10-01
                authority: firm
                source: the venue's own terms
                effectiveFrom: '2026-10-01T00:00:00.000Z'
                effectiveUntil: null
                marginCall: null
                stopOut: '1'
                recoveryLevel: '1.1'
                sources:
                  marginCall:
                    authority: firm
                    source: the venue's own terms
                    sourced: true
                  stopOut:
                    authority: firm
                    source: the venue's own terms
                    sourced: true
                  recoveryLevel:
                    authority: firm
                    source: the venue's own terms
                    sourced: true
              valuation:
                version: valuation-2026-10-01
                authority: firm
                source: the venue's own terms
                effectiveFrom: '2026-10-01T00:00:00.000Z'
                effectiveUntil: null
                maxAgeMs: 5000
              ticketHedging: null
            crypto_derivative: null
          settlement:
            version: settlement-2026-10-01
            authority: firm
            source: the venue's own terms
            effectiveFrom: '2026-10-01T00:00:00.000Z'
            effectiveUntil: null
            kind: settlement_asset
          posting:
            version: posting-2026-10-01
            authority: firm
            source: the venue's own terms
            effectiveFrom: '2026-10-01T00:00:00.000Z'
            effectiveUntil: null
            currencies:
              - currency: USD
                decimals: 2
                rounding: half_even
                source:
                  authority: publisher
                  source: 'ISO 4217: USD minor unit 2'
                  sourced: true
                  document: null
    VenueRiskPolicyStoreResponse:
      type: object
      additionalProperties: false
      properties:
        version:
          type: object
          additionalProperties: false
          properties:
            policyId:
              type: string
            version:
              type: string
            contentDigest:
              type: string
            created:
              type: boolean
          required:
            - policyId
            - version
            - contentDigest
            - created
      required:
        - version
      example:
        version:
          policyId: meridian-futures
          version: '2026-10-01'
          contentDigest: eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
          created: true
    ErrorResponse:
      type: object
      description: >-
        The body of every error response. It always carries `error`, an English
        sentence you can show. A refused trading request also carries `code`,
        one of the refusal codes, and `params`, the details of that refusal.
        Translate by `code` and `params`, and show a generic message for a code
        you don't recognize. Other errors may carry a `code` of their own.
      properties:
        error:
          type: string
          description: What went wrong, as an English sentence.
        code:
          type: string
          description: >-
            A stable machine code. On a refused trading request, it is one of
            the refusal codes.
        params:
          type: object
          description: >-
            The details of the refusal named by `code`, on a refused trading
            request.
      required:
        - error
      example:
        error: invalid_instrument
  securitySchemes:
    venueOperatorKey:
      type: http
      scheme: bearer
      description: >-
        The Venue key (`trdrs_vk_sandbox_…` or `trdrs_vk_production_…`), in
        preview. It belongs to one venue in one environment and carries the
        scopes it was created with. The venue's verified owner creates it while
        signed in, and it works only on the `/api/partner/venues/{venueId}`
        routes. A `trdrs_sk_…` key can't be used in its place. It never lets you
        act as a trader, sign in or manage keys. Keep it on your server.

````