Overview
pip is an options market for Robinhood Stock Tokens on Robinhood Chain. Every Stock Token becomes two markets, UP and DOWN. Buyers pick a direction, strike, expiry and size; the protocol prices the contract against the Stock Token oracle and settles it in USDG at expiry.
Underneath the app sits Options Protocol, a permissionless set of contracts where anyone can post collateral, write calls and puts, collect premium, and provide liquidity.
- 190+ Stock Tokens eligible; 24 deep markets today
- Four rolling expiries per token: weekly, bi-weekly, monthly, quarterly
- Cash-settled in USDG against the oracle print at 20:00 UTC
- 24/7, including weekends. $25 minimum, fractional contracts
Getting started
1. Connect a wallet
Open the app and press Connect wallet. pip supports any injected EIP-1193 wallet (MetaMask, Coinbase Wallet, Rabby, Brave). Connecting only reads your address and balance.
2. Fund with USDG
Buying options only needs USDG on Robinhood Chain. Writing covered calls needs the Stock Tokens themselves. Your balances appear in Portfolio and in the vault on the Protocol tab.
3. Make your first trade
- Pick a token from the Markets list.
- Choose UP (buy a call) or DOWN (buy a put).
- Drag the strike. The chart draws it live.
- Pick an expiry and a size in dollars.
- Read the ticket. It states the two outcomes in one sentence each.
- Confirm. The contract is minted to your wallet in the same block.
Core concepts
Stock Token
A token on Robinhood Chain that tracks a listed stock or ETF, with a native oracle price. pip never touches the underlying share; contracts reference the token's oracle price only.
Call and put
A call pays if the token finishes above the strike at expiry. A put pays if it finishes below. In the app these are labelled UP and DOWN.
Strike
The price the outcome is measured against. Each market lists eleven strikes around spot in fixed increments: $2.50 for tokens under $150, $5 up to $400, $10 above.
Expiry
The moment the contract settles: 20:00 UTC on the expiry date. Four expiries are always open per token.
Premium
What a buyer pays per share of exposure. One contract equals 100 shares, so a $4.20 premium is $420 per contract. Contracts are fractional; a $50 ticket at $4.20 buys 0.12 contracts.
Mark
The protocol's fair value for a contract right now, recomputed on every oracle print. Positions are valued at the mark and sold back at the mark.
Break-even
Strike plus premium for a call, strike minus premium for a put. Above (or below) this at expiry, the position is net positive.
Buying options
Every buy is a single confirm from the ticket. Behind it, Clearing mints an ERC-1155 contract token to your address, moves USDG premium plus fee to the writer or LP vault, and records the position.
The ticket
| Field | Meaning |
|---|---|
| Premium | Per-share price, fee included. |
| Contracts | Size ÷ (premium × 100). Fractional. |
| Break-even | Token price at expiry where P&L is zero. |
| Max loss | Always equal to size. |
| Max gain | Unlimited for calls; (strike − premium) × 100 × contracts for puts. |
| Δ Γ Θ V | Delta, gamma, theta per day, vega per vol point. Expand the ticket to see them. |
| Prob ITM | Risk-neutral probability the contract finishes in the money. |
Scenario panel
The ticket shows P&L at expiry for the token −15%, −5%, 0%, +5% and +15% from spot. Use it to sanity-check a strike before confirming.
Sizing
Preset sizes are $25, $50, $100 and $250. Custom amounts are accepted from $25 up to your buying power. There is no per-order maximum, but open interest per token is capped by governance; if a market is near its cap the ticket says so.
Positions & selling
Every position is a card: contract, expiry, contracts held, days left, option price history, unrealised P&L, entry, mark, value, and spot versus strike.
Selling back
Press Sell on any card to close at the mark. You can sell part of a position. Proceeds land in USDG in the same transaction, minus the 0.5% fee. Selling is available 24/7 until the settlement print at expiry.
Holding to expiry
Nothing to do. In-the-money contracts pay automatically; out-of-the-money contracts expire and the card moves to history.
Settlement
At 20:00 UTC on the expiry date the Settlement contract freezes the oracle print for that expiry. No trades or buy-backs are accepted for that expiry after the freeze.
| Position | Condition | Payout per contract |
|---|---|---|
| Long call | S > K | (S − K) × 100 USDG |
| Long call | S ≤ K | 0, expires worthless |
| Long put | S < K | (K − S) × 100 USDG |
| Long put | S ≥ K | 0, expires worthless |
| Covered call (writer) | S > K | (S − K) × 100 paid from locked tokens at oracle price; rest released |
| Cash-secured put (writer) | S < K | (K − S) × 100 paid from locked USDG; rest released |
If the oracle is halted at 20:00 UTC, settlement uses the first valid print after the halt clears. Payouts are pushed to holders' wallets; no claim transaction is needed.
Writing options
Writers take the other side. Lock collateral, mint a contract, receive the premium the moment a buyer fills. Three modes:
| Mode | You write | Collateral | Max loss | Liquidation |
|---|---|---|---|---|
| Covered call | Call | 100 Stock Tokens / contract | Upside above strike | Never |
| Cash-secured put | Put | K × 100 USDG / contract | Buying at K if it falls | Never |
| Margin | Call or put | 20% notional + premium, marked live | Uncapped for calls | Health < 80% |
Writer flow
- Deposit Stock Tokens or USDG into your vault.
- Choose token, mode, strike, expiry, contracts. The premium quotes live.
- Mint. Collateral locks; the contract is listed.
- Fill. Premium minus fee lands in your wallet immediately.
- Manage. Buy back at the mark to unlock collateral early, or hold.
- Settle. Out of the money: collateral released. In the money: payout taken, remainder released.
Covered call yield
period yield = premium / (spot × 100 × contracts)
annualised = period yield × 365 / days to expiry
// 1 × NVDA $200 CALL, Oct 16 (37d), spot $184.20, premium $6.12
period yield = 612 / 18,420 = 3.32%
annualised = 3.32% × 365 / 37 = 32.8%
Collateral & vault
Each writer has a vault on Robinhood Chain. Collateral is segregated per writer and per expiry; one writer's shortfall cannot touch another's assets.
- Accepted: any listed Stock Token (for covered calls) and USDG.
- Deposit / withdraw: no protocol fee, gas only. Withdrawals of locked collateral are blocked until the obligation is closed or settled.
- Locked vs free: the vault view shows both; the bar under each asset is the locked share.
Covered and cash-secured positions hold the full worst-case payout in the vault, which is why they can never be liquidated.
Margin & liquidation
Applies to margin (naked) writers only.
initial margin = 20% × spot × 100 × contracts + premium
health = collateral value / required margin
maintenance = health ≥ 80%
// below 80%: partial liquidation until health ≥ 100%
// penalty 2% of collateral → 50% liquidator, 50% insurance fund
Liquidations pause while the oracle deviation guard is active. The insurance fund backstops any shortfall after liquidation; it is funded by penalties and 10% of protocol fees.
Pricing
Three inputs produce every premium: the oracle spot, a fitted volatility surface, and time to expiry.
σ(K, T) = σ_atm(T) · skew(K / S) · term(T)
fair = BlackScholes(S, K, T, σ(K,T), r)
premium = fair + spread(σ, OI) // buyers
premium = fair − spread(σ, OI) // writers
fee = max($0.25, 0.5% × premium × 100 × contracts)
- σ_atm(T) is fitted from protocol fills and writer quotes per token and expiry, smoothed over a rolling window.
- skew makes downside strikes richer than upside, matching listed markets.
- spread widens with volatility and narrows with open interest. It is the LP's compensation.
- r is the USDG lending rate on Robinhood Chain, updated daily.
All inputs are onchain. Two users viewing the same market in the same second see the same premium.
Oracle
The Stock Token oracle is the only price pip uses, for quoting, marking and settlement.
| Property | Value |
|---|---|
| Cadence | One signed print every 1.2s (median) |
| Signers | Three independent; the adapter takes the median |
| Deviation guard | Print > 8% from the last is rejected; market halts until three consistent prints |
| Staleness | No fills on a print older than 10s |
| Settlement print | Frozen at 20:00 UTC on expiry |
Fees
| Action | Fee | Minimum |
|---|---|---|
| Buy | 0.50% of premium | $0.25 |
| Sell back | 0.50% of proceeds | $0.25 |
| Write (on fill) | 0.50% of premium | $0.25 |
| Expiry settlement | 0% | — |
| Deposit / withdraw | 0% | — |
| Liquidation penalty | 2% of collateral | — |
Fee split: 70% to LPs, 20% to treasury, 10% to the insurance fund. No payment for order flow, no exercise or assignment fees.
Risk parameters
| Parameter | Value |
|---|---|
| Initial margin (naked) | 20% of notional + premium |
| Maintenance health | 80% |
| Liquidation penalty | 2% |
| Oracle deviation halt | 8% between prints |
| Oracle staleness | 10 seconds |
| Max open interest per token | 5% of token float |
| Strike increments | $2.50 / $5 / $10 by price band |
| Strikes per market | 11 |
| Expiries per token | 4 |
| Settlement time | 20:00 UTC |
| Governance timelock | 48 hours |
Governance
Parameters are set by a multisig behind a 48-hour public timelock. Every change is announced onchain before it takes effect. There is no protocol token; governance opens to LPs and writers per the roadmap on the Network page.
Listing a new token market requires an oracle feed with 30 days of history and three signers, $250K seed writer collateral across the four expiries, a vol fit that stabilises within 5% over 7 days, and a governance vote on max open interest and margin tier.
Read API
Public, unauthenticated, JSON. Base URL https://api.pip.xyz/v1. Rate limit 60 requests per minute per IP. Market makers get authenticated write access under agreement; email liquidity@pip.xyz.
GET/markets
All listed tokens with spot, 24h change, implied vol, open interest and available expiries.
{
"markets": [
{ "token": "NVDA", "spot": 184.20, "change24h": 0.0124,
"iv": 0.52, "openInterest": 4200000,
"expiries": ["2026-09-12", "2026-09-18", "2026-10-16", "2026-12-18"] }
],
"oracleTs": 1788968001
}
GET/markets/{token}/chain?expiry=2026-09-18
Every strike for one expiry with call and put premiums, Greeks and probability in the money.
{
"token": "NVDA", "expiry": "2026-09-18", "spot": 184.20,
"strikes": [
{ "K": 190, "call": { "premium": 4.20, "delta": 0.42, "theta": -0.18, "pitm": 0.39 },
"put": { "premium": 9.85, "delta": -0.58, "theta": -0.17, "pitm": 0.61 } }
]
}
GET/positions/{address}
Open positions and written contracts for a wallet, each with entry, mark, value and unrealised P&L.
GET/oracle/{token}
Latest print, signer count, staleness and halt status.
GET/stats
TVL, open interest, 24h premium volume, tokens listed, and 30-day series for each.
Example
curl https://api.pip.xyz/v1/markets/NVDA/chain?expiry=2026-09-18 | jq '.strikes[] | select(.K==190)'
Contracts
Five Solidity contracts on Robinhood Chain. Verified source and addresses are published on the Protocol page at every release.
| Contract | Responsibility | Key functions |
|---|---|---|
| OracleAdapter | Median of signers, deviation guard, staleness, settlement freeze | latest(token) settlementPrice(token, expiry) |
| Vault | Per-writer collateral, lock and release | deposit(asset, amount) withdraw(asset, amount) lockedOf(writer, expiry) |
| PricingEngine | Vol surface, Black-Scholes, spread | quote(token, K, expiry, isCall, qty) mark(positionId) |
| Clearing | Mint, fill, buy-back, fee routing | buy(token, K, expiry, isCall, usdc) sell(positionId, qty) write(mode, token, K, expiry, qty) buyBack(writtenId) |
| Settlement | Freeze, payout, release, liquidation | settle(token, expiry) liquidate(writer) health(writer) |
Position tokens
Long positions are ERC-1155 tokens. The id encodes token, strike, expiry and direction, so identical contracts are fungible and transferable between wallets. Written obligations are non-transferable records in Clearing tied to the writer's vault.
Events
event Bought(address indexed buyer, uint256 indexed id, uint256 qty, uint256 premium, uint256 fee);
event Sold(address indexed seller, uint256 indexed id, uint256 qty, uint256 proceeds);
event Written(address indexed writer, uint256 indexed id, uint8 mode, uint256 qty, uint256 premium);
event Settled(bytes32 indexed token, uint64 expiry, uint256 price);
event Liquidated(address indexed writer, uint256 collateralSeized, uint256 penalty);
Deep links
The app accepts query and hash parameters so you can link straight into a market or tab.
| URL | Opens |
|---|---|
app.html?tk=NVDA | Markets tab with NVDA selected |
app.html#protocol | Protocol tab (write options) |
app.html#connect | Opens the wallet dialog on load |
Glossary
| ATM / ITM / OTM | At, in, or out of the money: strike equal to, favourable to, or unfavourable to spot. |
| Assignment | On pip, the cash-settled outcome of a written option finishing in the money. No shares change hands. |
| Covered call | A call written against 100 Stock Tokens per contract held in the vault. |
| Cash-secured put | A put written against K × 100 USDG per contract held in the vault. |
| Delta | Change in premium per $1 move in the token. |
| Health | Collateral value divided by required margin, for margin writers. |
| Implied volatility | The vol input that reproduces current premiums; higher IV, pricier options. |
| Mark | Protocol fair value of a contract at the latest oracle print. |
| Notional | Spot × 100 × contracts; the exposure a contract controls. |
| Oracle print | One signed Stock Token price from the oracle. |
| Premium | Price of an option per share; × 100 per contract. |
| Theta | Premium lost per day from time passing, all else equal. |
| Vega | Change in premium per one-point move in implied vol. |
Support
- General: hello@pip.xyz
- Market makers and API: liquidity@pip.xyz
- Listings: listings@pip.xyz
- Security and bug bounty: security@pip.xyz
Or use the contact form. Typical reply within one business day.