Documentation
How ConaPerps works
ConaPerps is an interface for perpetual futures on Robinhood Chain; orders are executed by the Lighter · Robinhood Chain domain. This page states what the product does, how the venue's risk mechanics work, what is working today, and how to check any record yourself.
Every statement here is grounded in the integration facts verified on 2026-10-08 UTC and names its source. Figures that move (prices, funding, fees, open interest) are not written here; they are read live on Markets and Trade.
01
Product
ConaPerps is an interface. It prepares orders, has you sign them in your browser, submits them to the venue, and then checks what the venue actually did.
What ConaPerps is
A trading interface for the Lighter · Robinhood Chain domain: a dedicated Lighter instance on Robinhood Chain with its own contracts, sequencer, blockspace and liquidity. It is not Lighter Core. Matching, margin, funding and settlement happen on the venue; ConaPerps reads the venue's public market data, builds and signs transactions in your browser, submits them, and reconciles the result.
The venue listed 58 perpetual markets when the integration was verified on 2026-10-08. ConaPerps starts from BTC (market 1) and ETH (market 0) and opens any other market from the same registry; no market comes from a local list.
Source: docs.robinhood.com/chain/lighter-domains (opens in a new tab) · GET /api/v1/orderBookDetails
What it is not
- Not a derivatives engine. ConaPerps does not match orders, set margin requirements, compute funding or liquidate positions. The venue's risk engine decides every fill, margin requirement and liquidation; ConaPerps calculators are labelled as estimates.
- Not a custodian. Collateral moves from your wallet into the venue contract through a deposit you sign, and is held under your own venue account. Orders are signed in your browser with a trading key generated there and registered to that account, and go from your browser straight to the venue.
- Not private. Orders, trades and positions on this venue are public. See Privacy limitations.
Order lifecycle
Every order passes through the same states. ConaPerps shows each one as it happens and keeps a receipt.
Step 1
Signature requested
ConaPerps has built the transaction and is waiting for your signature. Nothing has been sent.
Step 2
Submitted
The signed transaction was posted to the venue, which answered with a venue transaction hash.
Step 3
Pending
The venue holds the transaction (status 1, pending) and has not executed it yet.
Then one of these outcomes
Executed / filled
- Meaning
- The venue executed the transaction (status 2 executed, then 3 packed, 4 committed, 5 verified) and the order filled in full.
Partially filled
- Meaning
- Part of the size filled. The remainder rests in the book or is cancelled, depending on the time in force.
Resting
- Meaning
- A limit order sits in the book without a fill. It stays until it fills, you cancel it, or it expires.
Cancelled
- Meaning
- The order left the book unfilled or partly filled: cancelled by you, expired, or cancelled by the venue (for example a post-only order that would have crossed, or a reduce-only order that would have grown the position).
Rejected
- Meaning
- The venue refused the transaction and returned an error message, which the receipt shows.
Failed
- Meaning
- The transaction failed at the venue (status 0), or it could not be submitted at all.
A transaction hash alone does not mean the order filled: ConaPerps reconciles the venue order state.
After submitting, ConaPerps reads the venue's status for the transaction and its matching-engine event (fill price and size), then the order itself, before it marks a receipt filled, partially filled, resting or cancelled.
Source: apidocs.rh.lighter.xyz (opens in a new tab) (POST /api/v1/sendTx, GET /api/v1/tx) · lighter-ts transaction status codes
02
Risk mechanics
These are the venue’s rules. ConaPerps uses them for its estimates, but the venue’s risk engine decides every real fill, margin requirement and liquidation.
Margin fractions
Each requirement is position size × mark price × a fraction, summed over the account's positions. You set the initial fraction per market with a leverage update, down to the market minimum. The core markets use these fractions:
Initial, minimum
- BTC · market 1
- 2 % (50x)
- ETH · market 0
- 2 % (50x)
Maintenance
- BTC · market 1
- 1.2 %
- ETH · market 0
- 1.2 %
Close-out
- BTC · market 1
- 0.8 %
- ETH · market 0
- 0.8 %
Every other market has its own fractions, read live on Markets.
Source: GET /api/v1/orderBookDetails (2026-10-08) · docs.lighter.xyz · Liquidations & LLP (opens in a new tab)
Account value
- account value =
- collateral + unrealized PnL (every position marked at its mark price)
Account value is compared with the three requirements above. Which one it falls below decides what the venue does next.
Source: docs.lighter.xyz · Liquidations & LLP (opens in a new tab)
Liquidation waterfall
Stage 1
Healthy
account value ≥ initial requirement
Any operation is accepted as long as the account stays healthy afterwards.
Stage 2
Pre-liquidation
initial > account value ≥ maintenance
Only operations that do not increase any position and do not lower the account’s health are accepted.
Stage 3
Partial liquidation
maintenance > account value > close-out
The venue cancels the account’s open orders, then closes positions with immediate-or-cancel orders at the zero price, a price at which the ratio of account value to maintenance requirement stays the same. A fill better than the zero price pays a liquidation fee of up to 1 % to the LLP.
Stage 4
Full liquidation
close-out > account value
The LLP, the venue’s insurance fund, takes the positions over in ascending order of unrealized PnL, as long as it stays above its own initial margin requirement.
Stage 5
Auto-deleveraging
bankrupt account the LLP cannot absorb
Positions the LLP cannot take over are matched against opposite positions, ranked by leverage and unrealized PnL, at prices no worse than those positions’ zero price.
A position in isolated margin mode goes through the same stages on its own, backed by the margin allocated to it.
Source: docs.lighter.xyz · Liquidations & LLP (opens in a new tab)
Funding
Funding is exchanged between traders at every hour mark; the venue takes no fee on it. When the rate is positive, longs pay shorts; when it is negative, shorts pay longs.
- premium =
- time-weighted average of the minute premiums over the hour × FundingPremiumMultiplier
- adjusted =
- premium + clamp(InterestRate − premium, ±SmallClamp × FundingPremiumMultiplier)
- hourly rate =
- clamp(adjusted, ±BigClamp) ÷ 8
- payment =
- −position × index price × hourly rate
The parameters the venue documents for most markets are SmallClamp 0.05 %, BigClamp 4 % and InterestRate 0.01 %. A premium within the small clamp of the interest rate therefore gives 0.01 % ÷ 8 = 0.00125 % per hour, and no hour can exceed ±0.5 %. Position is positive for longs and negative for shorts; a positive payment is received.
The venue's funding-rates endpoint quotes an 8-hour equivalent. ConaPerps divides it by 8 and shows the hourly rate that is actually charged, which matches the venue's hourly funding history.
Source: docs.lighter.xyz · Funding (opens in a new tab) · funding-rates and fundings?resolution=1h compared on api.rh.lighter.xyz
Mark price and index price
The mark price drives unrealized PnL, margin requirements, liquidations and stop-loss / take-profit triggers. It is the median of three values:
- the impact price: the average of the prices to buy and to sell an impact notional against the book;
- the index price plus an exponential moving average of the book's premium, capped at 0.5 % of the index;
- the median of mark prices from external exchanges.
The index price comes from a combination of oracles: Chainlink, Stork and Pyth.
Source: docs.lighter.xyz · Fair price marking (opens in a new tab)
Order types
Market
- How the venue runs it
- CreateOrder type 1, immediate-or-cancel, with a worst-price bound it cannot fill beyond.
- In ConaPerps
- Available
Limit
- How the venue runs it
- Type 0: good-till-time with an expiry from 5 minutes to 30 days, immediate-or-cancel, or post-only.
- In ConaPerps
- Available
Post-only
- How the venue runs it
- Limit option: if the order would cross the book, the venue cancels it instead of letting it take liquidity.
- In ConaPerps
- Available
Reduce-only
- How the venue runs it
- Option on any order: it may only move the position toward zero.
- In ConaPerps
- Available
Stop-loss (market or limit)
- How the venue runs it
- Types 2 and 3, triggered when the mark price crosses the trigger price.
- In ConaPerps
- Available
Take-profit (market or limit)
- How the venue runs it
- Types 4 and 5, triggered on the mark price in the same way.
- In ConaPerps
- Available
TWAP
- How the venue runs it
- Type 6: the venue splits a large order into smaller market orders over a set time.
- In ConaPerps
- Not exposed
Stop-loss and take-profit orders live on the venue.
They are held and triggered by the venue sequencer on the mark price. They are not on-chain orders and not a ConaPerps service: ConaPerps submits them, the venue watches the price.
Source: lighter-go create_order.go (opens in a new tab) · docs.lighter.xyz · Order types & matching (opens in a new tab)
03
Integration status
What works against the live venue today, what is blocked and why, and what is planned. Each status follows the verified integration facts and changes only when they do.
Working 13Blocked 2Planned 2
Market data
WorkingMarket registry, candles, order book, trades and funding, read from api.rh.lighter.xyz.
Wallet connect and network switch
WorkingConnects an EVM wallet and switches it to Robinhood Chain.
USDG balance and allowance reads
WorkingRead from the chain through the same-origin relay.
Approve and deposit
Workingdeposit(address,uint16,uint8,uint256)with USDG asset 3 and route 0, after an ERC-20 approve; simulated before signing. The venue account is created by the first deposit (minimum 1 USDG).Trading key registration
WorkingOne personal_sign of the venue's registration message, then a ChangePubKey transaction that registers a browser-generated key in API key slot 11.
Market and limit orders
WorkingMarket: immediate-or-cancel with a price bound. Limit: good-till-time or post-only, expiry 5 minutes to 30 days.
Reduce-only, post-only
WorkingOrder options passed to the venue as signed.
Cancel, cancel all
WorkingCancelOrder (type 15) and CancelAllOrders (type 16).
Leverage and margin mode
WorkingUpdateLeverage (type 20) sets the initial margin fraction per market and cross or isolated mode.
Take-profit, stop-loss
WorkingVenue-managed trigger orders on the mark price, held by the venue sequencer.
Position PnL, margin health, venue liquidation price
WorkingRead from the venue’s public account API by L1 address.
Funding payments, order and trade history
WorkingNeeds a registered trading key: these are private reads, authorised by a token signed with it.
Withdraw request (secure)
WorkingL2Withdraw (type 13), asset 3, route 0, to the account’s own L1 address. It becomes claimable after the venue’s delay (446 s on 2026-10-08).
Claim of a claimable secure withdrawal
BlockedThe claim call on the venue contract is not source-verified, so ConaPerps does not send it. Claim in the venue UI (robinhoodchain.lighter.xyz (opens in a new tab)).
Fast withdraw
PlannedExists on the venue for USDG, but its fee and claim mechanics are not documented publicly.
Private submission
BlockedNo mechanism exists on the venue.
Testnet trading
PlannedThe testnet domain exists (contract 0xDEE9…B0f5), but no testnet account was funded during the build.
Exact remaining external dependencies
- Source verification of the venue's implementation contract. The proxy 0x94bA…fF9d points to an implementation (0x82de…1d90) that is not verified on Sourcify or Blockscout. Until it is, ConaPerps sends only the documented deposit call (selector
0x8a857083) and simulates it before every send. - Fast-withdraw documentation. The venue's fee and claim mechanics for fast withdrawals are not published.
- A production RPC provider key. The public Robinhood Chain RPC is rate limited; heavy traffic needs a provider endpoint (Alchemy is the one the Robinhood docs recommend).
Source: docs/integration-facts.md, “What is NOT verified / not built” · docs.robinhood.com/chain/connecting (opens in a new tab)
04
Privacy limitations
There is no private way to submit an order on this venue. ConaPerps says so plainly and does not imitate one.
Status
These four facts hold for every order placed through ConaPerps:
- 01Orders are sent to the venue sequencer as signed transactions and rest in a public order book keyed by account index.
- 02Executed trades are public: price, size, time and both account indexes appear in the public trade feed.
- 03Account collateral and open positions are readable by anyone who knows the L1 address (the venue account API is public).
- 04No encrypted-order, commit–reveal or private mempool path exists on this venue. ConaPerps does not simulate one.
What a private RPC or a hidden field does not change
A private RPC changes only the route your wallet uses to reach Robinhood Chain for approvals and deposits. Orders never pass through an RPC: they are signed in your browser and posted to the venue sequencer, which places them in the public book. A field hidden in an interface is hidden on your screen only; the venue's order book, trade feed and account API stay public.
What remains public after execution
- Every fill: price, size, time and both account indexes, in the venue’s public trade feed.
- Your collateral, available balance and open positions (entry price, size, unrealized PnL and the venue’s liquidation price), readable by anyone who knows your L1 address.
- Your approvals, deposits and other Robinhood Chain transactions, on the public explorer.
Receipts are records, not proofs
A ConaPerps receipt is the venue's record of a transaction (hash, status, matching-engine event, order state) together with the Robinhood Chain receipt for wallet transactions. Both can be checked independently, as described in Verifying a receipt. Neither is a cryptographic proof that the venue executed correctly: they show what the venue and the chain recorded.
05
Verifying a receipt
Every receipt carries identifiers you can check without ConaPerps: against the venue’s public API, against the chain explorer, and against the signer’s published source.
1 · Venue transaction hash
Orders, cancels, leverage changes, key registration and withdrawal requests are venue transactions. Look one up with:
GET https://api.rh.lighter.xyz/api/v1/tx?by=hash&value=<venue tx hash>The answer carries the transaction's status code and the matching-engine event with the fill price and size:
- 0failed
- 1pending
- 2executed
- 3packed
- 4committed
- 5verified
Source: apidocs.rh.lighter.xyz (opens in a new tab) · lighter-ts transaction status codes
2 · Order identifiers
- Client order index: chosen by ConaPerps when it signs the order, unique per order.
- Order index: assigned by the venue when it accepts the order.
- Market index: the venue's market id (BTC 1, ETH 0).
The venue's active and inactive order lists return the same identifiers with the order's status and filled amounts. They are private reads: they need an auth token signed by your registered trading key.
Source: lighter-go create_order.go · apidocs.rh.lighter.xyz (private reads)
3 · Chain receipts
Approvals and deposits are ordinary Robinhood Chain transactions sent by your wallet. Open the hash on Blockscout: https://robinhoodchain.blockscout.com/tx/<hash>. A deposit is a call to the venue contract with selector 0x8a857083, which is deposit(address,uint16,uint8,uint256), carrying USDG asset 3 and route 0.
Source: docs.robinhood.com/chain/lighter-domains (opens in a new tab)
4 · Signer binary
Orders are signed by the official lighter-go WASM signer, pinned to one build. ConaPerps checks the file's SHA-256 against the pinned value before it loads it.
- SHA-256
- 5372ac1daa47460fd6bbcfb6d8bdb1a847bac61ba6f54ed770c3ac4faa32bf6b
- Commit
- 9d38261d1a4cc5c7211b383ba07a4d6e41604708
- Served by ConaPerps at
/signer/lighter-signer.wasm
To check it yourself, download /signer/lighter-signer.wasm from this site and hash it (for example with sha256sum); the result must equal the SHA-256 above. The binary's source is the web-wasm directory of lighter-go at the pinned commit, where it can be read and rebuilt.
Source: github.com/elliottech/lighter-go (opens in a new tab)
5 · Contracts
- Venue contract (proxy)
- 0x94bAB9693Ba2f6358507eFfcbd372b0660AFfF9d
- Venue implementation
- 0x82de…1d90 : not source-verified on Sourcify or Blockscout.
- USDG (collateral, 6 decimals)
- 0x5fc5360D0400a0Fd4f2af552ADD042D716F1d168
Source: docs.robinhood.com/chain/lighter-domains (opens in a new tab)
06
Environment
Identifiers this build uses. It targets Robinhood Chain (chain 4663); one build serves one network.
Network
- Chain
- Robinhood Chain (Arbitrum Orbit L2 on Ethereum, ETH for gas)
- Chain id
- 4663
- Public RPC
https://rpc.mainnet.chain.robinhood.comrate limited; a provider endpoint (Alchemy) is recommended for production- Collateral token
- USDG 0x5fc5360D0400a0Fd4f2af552ADD042D716F1d168 (opens in a new tab), 6 decimals
Robinhood Chain Testnet: chain 46630, explorer explorer.testnet.chain.robinhood.com, USDG 0xF694…6220. Its venue API base is api.rh-testnet.lighter.xyz and its signing chain id is 300; no testnet account was funded during the build.
Source: docs.robinhood.com/chain/connecting (opens in a new tab)
Venue
- Venue
- Lighter · Robinhood Chain domain
- Contract (proxy)
- 0x94bAB9693Ba2f6358507eFfcbd372b0660AFfF9d (opens in a new tab)
- REST API
https://api.rh.lighter.xyz- WebSocket
wss://api.rh.lighter.xyz/streamchannelsorder_book/{id}trade/{id}market_stats/{id}account_all/{account}- Signing chain id
- 466324 inside Lighter signatures, not the EVM chain id
- Collateral route
- USDG asset index 3, deposit route 0; minimum deposit 1 USDG
- Funding interval
- 1 hour
- Secure withdrawal delay
- 446 s, measured 2026-10-08
- API key slot
- 11 (slots 0–3 belong to Lighter’s own apps)
- Order execution in this build
- Read-only: market data, calculators, balances and deposits
Source: docs.robinhood.com/chain/lighter-domains (opens in a new tab) · apidocs.rh.lighter.xyz (opens in a new tab) · GET /info · withdrawalDelay
How ConaPerps reaches the chain and the venue
- Chain reads (balances, allowances, receipts, simulations) go to
/api/rpc, a same-origin relay that forwards read-only JSON-RPC methods to rpc.mainnet.chain.robinhood.com, falling back to robinhood-rpc.publicnode.com and robinhood.drpc.org. It relays no transactions: your wallet sends approvals and deposits itself. - Market data comes from ConaPerps server routes (
/api/markets,/api/candles,/api/book,/api/funding,/api/account) that read the venue's public API and cache it for a few seconds. - Signed venue transactions (key registration, orders, cancels, leverage, withdrawals) go from your browser directly to the venue's
sendTxendpoint.
Environment variables
No secrets are required to run ConaPerps: signing happens in the visitor's browser, and every read uses public endpoints.
NEXT_PUBLIC_NETWORK- Purpose
- Network this build targets: robinhood (chain 4663) or robinhood-testnet (chain 46630). One build, one network.
- When unset
- robinhood
NEXT_PUBLIC_SITE_URL- Purpose
- Public origin of the deployment, for metadata and canonical links.
- When unset
- Vercel production URL, else http://localhost:23500
NEXT_PUBLIC_EXECUTION- Purpose
- “live” lets a visitor register a trading key and sign venue transactions; anything else keeps the terminal read-only (market data, calculators, balances and deposits stay available).
- When unset
- read-only
NEXT_PUBLIC_VENUE_API_KEY_INDEX- Purpose
- API key slot ConaPerps registers on the visitor’s venue account. Slots 0–3 belong to Lighter’s own apps.
- When unset
- 11
RPC_UPSTREAM_URL- Purpose
- Server-side upstream for the /api/rpc relay. A provider endpoint (Alchemy) is better than the rate-limited public RPC in production.
- When unset
- the network’s public RPC
UPSTREAM_DOH- Purpose
- Set to 1 where the DNS resolver hijacks *.robinhood.com: the RPC host is resolved over DNS-over-HTTPS and TLS is still verified.
- When unset
- off
VENUE_API_BASE- Purpose
- Server-side override of the venue API base.
- When unset
- the network’s Lighter domain
Source: .env.example