SecureData (FIX tag 91)
SecureData (tag 91) is a data field defined in FIX 4.4 and FIX 4.2. It belongs to the session envelope: every FIX 4.4 message carries it, so it identifies the session rather than describing the business event. It is length-prefixed — tag 90 carries the byte count, so the value may contain the SOH separator without breaking the message.
At a glance
What the specification says
Actual encrypted data stream
Descriptions are quoted from the FIX Orchestra sources under the Apache 2.0 licence.
A real message using tag 91
| Tag | Field | Wire value | Meaning |
|---|---|---|---|
| 8 | BeginString | FIX.4.4 | |
| 9 | BodyLength | 127 | |
| 35 | MsgType | D | Order – Single |
| 49 | SenderCompID | BOARTEAM | |
| 56 | TargetCompID | COUNTERPARTY | |
| 90 | SecureDataLen | 7 | |
| 91 | SecureData | EXAMPLE | |
| 34 | MsgSeqNum | 2 | |
| 52 | SendingTime | 20240101-12:00:00.000 | |
| 11 | ClOrdID | ORD-10042 | |
| 54 | Side | 1 | Buy |
| 60 | TransactTime | 20240101-12:00:00.000 | |
| 40 | OrdType | 1 | Market |
| 10 | CheckSum | 137 |
Shown with | separators for readability. On the wire FIX uses SOH (0x01), an invisible control byte — and because BodyLength and CheckSum are computed over the actual bytes, the two forms have different checksums. Both are valid and both decode here.
Generated from the FIX 4.4 dictionary and verified at build time: it parses and validates with no issues. Open the decoder to try your own message.
Where tag 91 appears
Wire format
Raw bytes, length-prefixed by a partner field. The value may legally contain the SOH separator, which is why the length matters. @boarteam/fix reads the partner length field first and takes exactly that many bytes, so an embedded separator does not truncate the value.
Read tag 91 in TypeScript
import { createFixEngine } from "@boarteam/fix";import { dictionary } from "@boarteam/fix-dict-fix44";const fix = createFixEngine(dictionary);const { message, issues } = fix.parse(raw);// Length-prefixed: tag 90 carries the byte count, so the// value may contain the SOH separator without breaking the message.const length = message.fields[90]?.value;const secureData = message.fields[91]?.raw;Other data fields
Decode this in your own code
The same engine that produced the decoded example above is an Apache-2.0 npm package with zero runtime dependencies. It runs in Node and in the browser, and parse() returns problems as data instead of throwing.
npm i @boarteam/fix @boarteam/fix-dict-fix44