DerivativeSecurityXML (FIX tag 1283)
DerivativeSecurityXML (tag 1283) is a data field defined in FIX 5.0 SP2. It appears in 3 message types, always optionally. It is length-prefixed — tag 1282 carries the byte count, so the value may contain the SOH separator without breaking the message.
At a glance
What the specification says
XML definition for the security.
Descriptions are quoted from the FIX Orchestra sources under the Apache 2.0 licence.
A real message using tag 1283
| Tag | Field | Wire value | Meaning |
|---|---|---|---|
| 8 | BeginString | FIXT.1.1 | |
| 9 | BodyLength | 101 | |
| 35 | MsgType | z | DerivativeSecurityListRequest |
| 49 | SenderCompID | BOARTEAM | |
| 56 | TargetCompID | COUNTERPARTY | |
| 34 | MsgSeqNum | 2 | |
| 52 | SendingTime | 20240101-12:00:00.000 | |
| 320 | SecurityReqID | EXAMPLE | |
| 559 | SecurityListRequestType | 0 | Symbol |
| 1282 | DerivativeSecurityXMLLen | 7 | |
| 1283 | DerivativeSecurityXML | EXAMPLE | |
| 10 | CheckSum | 185 |
Shown with | separators for readability. On the wire FIX uses SOH (0x01), an invisible control byte — and because BodyLength and CheckSum are computed over the actual bytes, the two forms have different checksums. Both are valid and both decode here.
Generated from the FIX 5.0 SP2 dictionary and verified at build time: it parses and validates with no issues. Open the decoder to try your own message.
Where tag 1283 appears
Requiredness is a property of the message, not of the field: the same tag can be optional in one message and conditionally required in another.
| Message | MsgType | Requiredness | Where in the message |
|---|---|---|---|
| DerivativeSecurityList | AA | Optional | inside DerivativeSecurityDefinition › DerivativeInstrument › DerivativeSecurityXML |
| DerivativeSecurityListRequest | z | Optional | inside DerivativeInstrument › DerivativeSecurityXML |
| DerivativeSecurityListUpdateReport | BR | Optional | inside DerivativeSecurityDefinition › DerivativeInstrument › DerivativeSecurityXML |
Wire format
Raw bytes, length-prefixed by a partner field. The value may legally contain the SOH separator, which is why the length matters. @boarteam/fix reads the partner length field first and takes exactly that many bytes, so an embedded separator does not truncate the value.
Read tag 1283 in TypeScript
import { createFixEngine } from "@boarteam/fix";import { dictionary } from "@boarteam/fix-dict-fix50sp2";const fix = createFixEngine(dictionary);const { message, issues } = fix.parse(raw);// Length-prefixed: tag 1282 carries the byte count, so the// value may contain the SOH separator without breaking the message.const length = message.fields[1282]?.value;const derivativeSecurityXML = message.fields[1283]?.raw;Other data fields
- 1281DerivativeEncodedSecurityDesc
- 1278DerivativeEncodedIssuer
- 1398EncodedMktSegmDesc
- 1402EncryptedPassword
- 1404EncryptedNewPassword
- 1469EncodedSecurityListDesc
- 622EncodedLegSecurityDesc
- 619EncodedLegIssuer
- 446EncodedListStatusText
- 365EncodedUnderlyingSecurityDesc
- 363EncodedUnderlyingIssuer
- 361EncodedAllocText
- 359EncodedHeadline
- 357EncodedSubject
- 355EncodedText
- 353EncodedListExecInst
- 351EncodedSecurityDesc
- 349EncodedIssuer
- 213XmlData
- 96RawData
- 91SecureData
- 89Signature
Decode this in your own code
The same engine that produced the decoded example above is an Apache-2.0 npm package with zero runtime dependencies. It runs in Node and in the browser, and parse() returns problems as data instead of throwing.
npm i @boarteam/fix @boarteam/fix-dict-fix50sp2