Password (FIX tag 554)

StringFIX 4.4

Password (tag 554) is a String field defined in FIX 4.4. It appears in 2 message types, always optionally.

At a glance

Tag
554
Name
Password
Datatype
String
Dialects
FIX 4.4
Messages
2

What the specification says

Password or passphrase.

Descriptions are quoted from the FIX Orchestra sources under the Apache 2.0 licence.

A real message using tag 554

Logon · FIX 4.4
TagFieldWire valueMeaning
8BeginStringFIX.4.4
9BodyLength86
35MsgTypeALogon
49SenderCompIDBOARTEAM
56TargetCompIDCOUNTERPARTY
34MsgSeqNum2
52SendingTime20240101-12:00:00.000
98EncryptMethod0None / other
108HeartBtInt1
554PasswordEXAMPLE
10CheckSum147
Edit and decode it yourself

Shown with | separators for readability. On the wire FIX uses SOH (0x01), an invisible control byte — and because BodyLength and CheckSum are computed over the actual bytes, the two forms have different checksums. Both are valid and both decode here.

Open in the full decoder →

Generated from the FIX 4.4 dictionary and verified at build time: it parses and validates with no issues. Open the decoder to try your own message.

Where tag 554 appears

Requiredness is a property of the message, not of the field: the same tag can be optional in one message and conditionally required in another.

MessageMsgTypeRequirednessWhere in the message
LogonAOptionaldirectly on the message body
UserRequestBEOptionaldirectly on the message body

Wire format

Free-form text. Any byte except the SOH separator is legal, so values are not trimmed or case-folded on the wire. @boarteam/fix keeps the value as a string; format rules are checked by validate(), which reports validate/invalid-value rather than throwing.

Read tag 554 in TypeScript

decode.tsts
import { createFixEngine } from "@boarteam/fix";import { dictionary } from "@boarteam/fix-dict-fix44";const fix = createFixEngine(dictionary);const { message, issues } = fix.parse(raw);const field = message.fields[554];field?.name;   // "Password"field?.raw;    // the verbatim wire stringfield?.value;  // coerced to a string

Other String fields

Decode this in your own code

The same engine that produced the decoded example above is an Apache-2.0 npm package with zero runtime dependencies. It runs in Node and in the browser, and parse() returns problems as data instead of throwing.

npm i @boarteam/fix @boarteam/fix-dict-fix44