Venues and balances
USDC, pUSD and USDT0 are distinct assets: never add their base units.
A margin transfer moves funds from the venue to the linked address on the escrow chain; the server checks the withdrawable balance and the venue applies its own fees and refusals. Venue and chain balances are separate observations: check
read_at/error and chain_read_at/chain_error independently. Polymarket’s withdrawable amount may be an upper-bound estimate. An Aster transfer signs the requested amount plus Aster’s withdrawal fee, read from the venue at preparation; the fee is in the signed message.
Settlement deposits into the receiving venue. When the venue refuses a deposit, or it is below release_minimum, the tokens stay in the recipient’s available escrow balance (the zero-id order), never in a personal wallet. payment_destination and maker_destination report venue or escrow; a claim alone does not prove a venue credit. The owner retries the deposit once the balance meets release_minimum, or withdraws to the wallet, with POST /v1/escrow/close/prepare; on chain, withdrawOffer(0, amount) needs no relayer.
Funded orders
A master session links accounts, manages credentials and prepares financial operations; the linked owner signs permits, venue transfers and funding. Each order records an immutable quote identity and quote signer, so a separate quote key can price funded inventory without the financial key. Create a credential, then pass its identity toPOST /v1/orders with a persisted client_order_id. Sign the returned items and submit them to /v1/orders/{id}/signatures. The order moves through preparing, moving (funds leaving the venue margin), funding and live. A delegated order starts without a quote. A browser order uses the master’s browser identity and an initial quote that never expires by default; its identity needs no lease.
A live order appears in the book only while its quote and admission controls are active.
Quotes, leases and budgets
A credential identity renews its lease for 5–120 seconds; when the strategy stops, admissions stop at lease expiry. Renewing an expired lease advances the generation, so old quotes and drafts never reactivate. The server prepares a draft with a sequence it allocates; never compute the sequence. The quote key signs it and submits{draft_id, signature}. The taker pays ceil(amount_out × receive / supply).
A level admits at most the smaller of the unreserved escrow and the sequence’s remaining quote_size. Accepted fills consume that budget; an EXPIRED fill with no payment releases it. A new sequence renews the budget; a lease renewal does not.
The signed on-chain expiry is valid_until + maker_timeout_seconds + 1, so admitted fills can settle. The signed QuoteSet contains no lease, generation, cancellation epoch or budget: these are server admission controls, not on-chain guarantees.
Cancellation
Pulling quotes advances the order’s cancellation epoch: a draft prepared before it cannot reactivate the order. Identity-wide cancellation advances the generation. Reservations committed before a cancellation continue and may settle; signed QuoteSets stay valid on chain until their expiry. Cancellation never withdraws capital or stops a pending transaction.Closing capital
POST /v1/closes closes managed orders after a master CloseOrders signature. Funded orders become closing; the operator releases unlocked inventory once no fill can still lock it, and closes again if a maker refund restores inventory. The linked owner can always withdraw unlocked inventory on chain.
GET /v1/escrow also lists orders another LaMarge operates; close those by signature. GET /v1/escrow/legacy finds funds in retired deployments and POST /v1/escrow/legacy/reclaim/prepare returns the owner’s reclaim transaction.
Prefunded takes
A taker pays from tokens already at its linked address on the payment chain. If funds are in venue margin, withdraw them withto: signer and wait for a fresh chain balance; relayed alone is only a venue acknowledgement. Never sign a second withdrawal to resolve an unknown one.
POST /v1/takes checks settlement readiness and reserves up to max_parts fills; without enough chain balance it returns PREFUNDING_REQUIRED and reserves nothing. Validate and sign the exact payment items, and the permit when one is asked, before pay_by. The relayer must still land each payment by its deadline: an accepted signature is not a fill guarantee. Fills settle independently, so the total received can be below min_out. The app labels this reservation threshold “Reservation minimum”; it is not a guaranteed final payout.
A reservation is not an on-chain lock: if the maker withdraws unlocked inventory before its lock lands, the taker waits for the payment refund. The short payment window limits how long an unsigned taker holds a price; it does not remove counterparty or operator risk.
Deadlines and outcomes
Defaults, from take preparation:
Use each fill’s values and your reviewed timing pins. New admissions stop when chain observations or relay capacity are unhealthy.
Transaction
pending has no finalized receipt yet. replaced means the nonce went to another action while earlier signed variants are still watched; it does not prove the old action never executed. mined and reverted are observed outcomes; failed was never sent or is conclusively unusable. A fee replacement can change the hash: follow resource state, not the first hash.
Fills end SETTLED, EXPIRED, REFUNDED, TAKER_LOSS or MAKER_LOSS. A public secret with a failed or late claim can leave one side paid and the other refunded. Finality reduces reorganization risk but does not bound inclusion time under congestion.
Signing and trust
SIWE and link challenges usepersonal_sign; financial and quote items use EIP-712. Reject unexpected kinds, duplicates, types, domains, chain IDs, contracts, operator, recipients, amounts, allowances, IDs, nonces or deadlines: a to_sign array is not trusted because the authenticated API returned it.
The operator can lock maker inventory and controls the secret. A compromised operator key can misuse valid quote signatures; a secret leaked before maker inventory is locked can endanger a taker payment. Leases and API cancellation do not revoke on-chain signatures.
If the operator stops before the secret is public, both locks refund after their deadlines. Once a claim reveals the secret, anyone can submit the matching claims while deadlines permit, and anyone can submit eligible refunds. Direct contract calls need gas.
claim credits the recipient’s available escrow balance; claimToVenue attempts a venue deposit and retains funds in escrow if that deposit fails. refund returns a taker payment to the payer’s chain address or restores maker collateral to its offer. withdrawOffer sends unlocked funds to the owner’s chain address. The owner can always recover unlocked inventory through the contract; a database reservation cannot prevent it.