SecureDataLen (FIX tag 90)
SecureDataLen (tag 90) is a Length field defined in FIX 4.4 and FIX 4.2. It belongs to the session envelope: every FIX 4.4 message carries it, so it identifies the session rather than describing the business event.
At a glance
- Tag
- 90
- Name
- SecureDataLen
- Datatype
- Length (int)
- Dialects
- FIX 4.4 and FIX 4.2
- Messages
- 93
What the specification says
Length of encrypted message
Descriptions are quoted from the FIX Orchestra sources under the Apache 2.0 licence.
A real message using tag 90
| Tag | Field | Wire value | Meaning |
|---|---|---|---|
| 8 | BeginString | FIX.4.4 | |
| 9 | BodyLength | 116 | |
| 35 | MsgType | D | Order – Single |
| 49 | SenderCompID | BOARTEAM | |
| 56 | TargetCompID | COUNTERPARTY | |
| 90 | SecureDataLen | 7 | |
| 34 | MsgSeqNum | 2 | |
| 52 | SendingTime | 20240101-12:00:00.000 | |
| 11 | ClOrdID | ORD-10042 | |
| 54 | Side | 1 | Buy |
| 60 | TransactTime | 20240101-12:00:00.000 | |
| 40 | OrdType | 1 | Market |
| 10 | CheckSum | 211 |
Shown with | separators for readability. On the wire FIX uses SOH (0x01), an invisible control byte — and because BodyLength and CheckSum are computed over the actual bytes, the two forms have different checksums. Both are valid and both decode here.
Generated from the FIX 4.4 dictionary and verified at build time: it parses and validates with no issues. Open the decoder to try your own message.
Where tag 90 appears
Wire format
A byte count for the length-prefixed field that follows it. Count bytes, not characters — a multi-byte UTF-8 value makes the two differ. @boarteam/fix parses the value as a number and reports parse/invalid-int when it does not lex as one; the raw string is kept either way.
Read tag 90 in TypeScript
import { createFixEngine } from "@boarteam/fix";import { dictionary } from "@boarteam/fix-dict-fix44";const fix = createFixEngine(dictionary);const { message, issues } = fix.parse(raw);const field = message.fields[90];field?.name; // "SecureDataLen"field?.raw; // the verbatim wire stringfield?.value; // coerced to a numberOther Length fields
- 93SignatureLength
- 95RawDataLength
- 9BodyLength
- 212XmlDataLen
- 348EncodedIssuerLen
- 350EncodedSecurityDescLen
- 352EncodedListExecInstLen
- 354EncodedTextLen
- 356EncodedSubjectLen
- 358EncodedHeadlineLen
- 360EncodedAllocTextLen
- 362EncodedUnderlyingIssuerLen
- 364EncodedUnderlyingSecurityDescLen
- 383MaxMessageSize
- 445EncodedListStatusTextLen
- 618EncodedLegIssuerLen
- 621EncodedLegSecurityDescLen
Decode this in your own code
The same engine that produced the decoded example above is an Apache-2.0 npm package with zero runtime dependencies. It runs in Node and in the browser, and parse() returns problems as data instead of throwing.
npm i @boarteam/fix @boarteam/fix-dict-fix44