Skip to content
Temporal Docs← Back to the app

03 · Wallet & accounts

Wallet & accounts

Wallet, accounts and equity#

Your wallet is your money outside any venue account. An account holds its own equity — the cash deposited into it plus its own profit and loss — and its own positions. Margin, the leverage cap and the solvency test read the account's equity and nothing else. A freshly connected wallet has no accounts; the act that needs one opens it.

Nothing is pulled from your wallet except margin and deposits you press for. A DEPOSIT or an ADD MARGIN moves cash from the wallet into an account, with the amount printed on the button. An open that would leave the account short says so, and its button carries the amount (ADD $X AND TRANSACT). Fees, funding, shortfalls and liquidations never reach into the wallet. WITHDRAW releases equity above what the account must keep behind what it holds, and is refused below that, with both numbers named.

There is no house#

The venue owns nothing and quotes nothing. The first curve on the book is the first one a person funds and posts; until then nothing trades. Every quote is backed by an account's own deposit.

Four account kinds#

The kind is fixed when the account is opened. OPTIONS holds the options you open from the OPTION ticket, with no perp behind them (accounts opened before the rename, such as TRADE 1, keep their name and wear the OPTIONS badge). PROTECT and FARM each hold exactly one perp and one option pair. EARN holds one quoted curve and the positions it accrues against traders; a maker holds no perp of its own.

A name is the kind and a number — OPTIONS 1, PROTECT 1, EARN 1 — counting every account of that kind the wallet has opened. It is given once and never changes. An account is active until CLOSE ACCOUNT ends it; an ended account is inactive and sits behind SHOW INACTIVE.

Margin: one closed form, summed at the account#

Every sold option is margined by the traditional closed form, with no scenario and no path length. Per unit of coin written: the initial margin is the larger of (15 % − how far out of the money the strike is) and 10 %, times spot, plus the option's mark. The maintenance margin is 7.5 % of spot plus the mark. An in-the-money option has zero distance out of the money, so it takes the full 15 %, and its mark is never below its intrinsic.

The legs add up at the account. An open must fit the initial margin; liquidation starts when equity is at or below the maintenance margin. Bought options count as collateral at their mark, and a sold vertical is margined at its width. Makers and takers use the same formula: an EARN account's sold rows are margined at the maker's own mark, exactly as an OPTIONS account's are.

The covered wing is exempt in PROTECT and FARM: the perp covers the sold option up to its quantity (a long perp covers calls, a short perp puts), and only the excess is margined. Perps keep their own margin at the leverage you choose. The contract runs this formula on chain; the keeper pushes the marks it reads.

Liquidation closes the account's positions at the front, like any other close. If no maker stands there, the leg stays open, the account stays flagged and the keeper tries again next tick. If a liquidated writer cannot cover the intrinsic it owes, the buyer is still paid in full and the shortfall is absorbed by an insurance account on the ledger (a placeholder until a standard mechanism is chosen).

PROTECT: buy a floor, solved for you#

Choose PROTECT on CREATE PERP and the perp opens straight into its own PROTECT account. You type a FLOOR in dollars and a TARGET ROE as a return on equity. The venue buys a put near the floor and sells a call near the target, picking each strike and decay itself. The two legs are worth the same at their fill prices, so no premium changes hands. The floor you type never snaps to less protection than you asked for; if the makers cannot fill the structure, nothing opens.

The ticket shows FUNDING / YR: what the two legs cost or earn over a year at the oracle's relevant sides, with the bought leg paying and the sold leg receiving. The PAYOFF tab draws the structure against a de-levered perp with the same floor (a dashed line), so you can see what the options bought you. Protecting an existing perp moves that perp into a new PROTECT account and books the pair there.

FARM: sell the covered side, get paid#

FARM takes the same two numbers and the same solver with the sides swapped. It sells the side the perp already covers — a call at the target over a long perp, a put under a short — and buys the other wing at the floor. The floor is worse than PROTECT's, and the funding is received instead of paid. It holds exactly one perp and one option pair, and CLOSE ACCOUNT is its only close verb.

PORTFOLIO#

PORTFOLIO lists every account with its figures in the asset's own coin; the one place that sums across assets, the wallet TOTAL, is in dollars. The perp rows carry size, entry, mark, P/L and perp equity. The option rows carry strike (in dollars, at entry as a % from the mark, and now), entry price, current price, P/L and equity. Closed legs are kept behind SHOW CLOSED POSITIONS.

FUNDING is its own figure: the wallet-wide sum paid (−) or received (+) on option legs, with each leg's yearly run rate in its hover. The strip also shows Perps P/L, Options P/L, Earn P/L, free cash, the positions' equity and the MAINTENANCE LEVEL — the equity at which the account liquidates.

A booked shortfall is what an account's deposit could not cover when a fee or a loss was booked. It is the account's own debt, printed on its card as SHORTFALL, and cleared by your next deposit. On a chain wallet, accounts that exist only in the venue's old test history are legacy (pre-ledger) accounts: they are counted in one muted line, not in the totals, because the ledger is the account of record.

Assets#

The venue trades BTC, HYPE and SPX (the S&P 500). Each asset is its own book with its own marks, makers and positions, and a maker's curve quotes exactly one of them. Marks come from Hyperliquid. Two coins have no common unit, so anything summed across assets is in dollars.

Signing in#

Connect your own wallet; the venue asks for a signature and your accounts live under that address. This deployment is a TESTNET venue: no real money is at risk, so it also offers a throwaway testnet wallet, a key generated in your browser. You sign an intent for each act; the venue's own signer submits it and pays the gas, so a wallet never needs to hold the chain's gas coin. On testnet a wallet's own accounts may fill each other, which lets one person hold both sides of a test. Mainnet runs the same venue on real funds — see section 8.

Everything above is the short form. The canon — every ruling, every rejected alternative with the reason it was rejected, and the measurements behind each number — is the design spec, and the corroboration procedure is the audit protocol. Both live in the repository this venue is built from.