pip / Docs

pip documentation

Everything you need to trade, write, integrate and audit. Start with Getting started if you're new; jump to API or Contracts if you're building.

Overview

pip is an options market for Robinhood Stock Tokens on Robinhood Chain. Every Stock Token becomes two markets, UP and DOWN. Buyers pick a direction, strike, expiry and size; the protocol prices the contract against the Stock Token oracle and settles it in USDG at expiry.

Underneath the app sits Options Protocol, a permissionless set of contracts where anyone can post collateral, write calls and puts, collect premium, and provide liquidity.

MARKETS → TICKER → UP or DOWN → STRIKE → EXPIRY → SIZE → CONFIRM
  • 190+ Stock Tokens eligible; 24 deep markets today
  • Four rolling expiries per token: weekly, bi-weekly, monthly, quarterly
  • Cash-settled in USDG against the oracle print at 20:00 UTC
  • 24/7, including weekends. $25 minimum, fractional contracts

Getting started

1. Connect a wallet

Open the app and press Connect wallet. pip supports any injected EIP-1193 wallet (MetaMask, Coinbase Wallet, Rabby, Brave). Connecting only reads your address and balance.

2. Fund with USDG

Buying options only needs USDG on Robinhood Chain. Writing covered calls needs the Stock Tokens themselves. Your balances appear in Portfolio and in the vault on the Protocol tab.

3. Make your first trade

  1. Pick a token from the Markets list.
  2. Choose UP (buy a call) or DOWN (buy a put).
  3. Drag the strike. The chart draws it live.
  4. Pick an expiry and a size in dollars.
  5. Read the ticket. It states the two outcomes in one sentence each.
  6. Confirm. The contract is minted to your wallet in the same block.
Max loss is the premium. A $50 ticket can never cost more than $50. The ticket shows break-even, max gain and the fee before you confirm.

Core concepts

Stock Token

A token on Robinhood Chain that tracks a listed stock or ETF, with a native oracle price. pip never touches the underlying share; contracts reference the token's oracle price only.

Call and put

A call pays if the token finishes above the strike at expiry. A put pays if it finishes below. In the app these are labelled UP and DOWN.

Strike

The price the outcome is measured against. Each market lists eleven strikes around spot in fixed increments: $2.50 for tokens under $150, $5 up to $400, $10 above.

Expiry

The moment the contract settles: 20:00 UTC on the expiry date. Four expiries are always open per token.

Premium

What a buyer pays per share of exposure. One contract equals 100 shares, so a $4.20 premium is $420 per contract. Contracts are fractional; a $50 ticket at $4.20 buys 0.12 contracts.

Mark

The protocol's fair value for a contract right now, recomputed on every oracle print. Positions are valued at the mark and sold back at the mark.

Break-even

Strike plus premium for a call, strike minus premium for a put. Above (or below) this at expiry, the position is net positive.

Buying options

Every buy is a single confirm from the ticket. Behind it, Clearing mints an ERC-1155 contract token to your address, moves USDG premium plus fee to the writer or LP vault, and records the position.

The ticket

FieldMeaning
PremiumPer-share price, fee included.
ContractsSize ÷ (premium × 100). Fractional.
Break-evenToken price at expiry where P&L is zero.
Max lossAlways equal to size.
Max gainUnlimited for calls; (strike − premium) × 100 × contracts for puts.
Δ Γ Θ VDelta, gamma, theta per day, vega per vol point. Expand the ticket to see them.
Prob ITMRisk-neutral probability the contract finishes in the money.

Scenario panel

The ticket shows P&L at expiry for the token −15%, −5%, 0%, +5% and +15% from spot. Use it to sanity-check a strike before confirming.

Sizing

Preset sizes are $25, $50, $100 and $250. Custom amounts are accepted from $25 up to your buying power. There is no per-order maximum, but open interest per token is capped by governance; if a market is near its cap the ticket says so.

Positions & selling

Every position is a card: contract, expiry, contracts held, days left, option price history, unrealised P&L, entry, mark, value, and spot versus strike.

Selling back

Press Sell on any card to close at the mark. You can sell part of a position. Proceeds land in USDG in the same transaction, minus the 0.5% fee. Selling is available 24/7 until the settlement print at expiry.

Holding to expiry

Nothing to do. In-the-money contracts pay automatically; out-of-the-money contracts expire and the card moves to history.

Theta. An option loses value every day the token does not move. The scenario tool on the Positions page shows the effect of time passing.

Settlement

At 20:00 UTC on the expiry date the Settlement contract freezes the oracle print for that expiry. No trades or buy-backs are accepted for that expiry after the freeze.

PositionConditionPayout per contract
Long callS > K(S − K) × 100 USDG
Long callS ≤ K0, expires worthless
Long putS < K(K − S) × 100 USDG
Long putS ≥ K0, expires worthless
Covered call (writer)S > K(S − K) × 100 paid from locked tokens at oracle price; rest released
Cash-secured put (writer)S < K(K − S) × 100 paid from locked USDG; rest released

If the oracle is halted at 20:00 UTC, settlement uses the first valid print after the halt clears. Payouts are pushed to holders' wallets; no claim transaction is needed.

Writing options

Writers take the other side. Lock collateral, mint a contract, receive the premium the moment a buyer fills. Three modes:

ModeYou writeCollateralMax lossLiquidation
Covered callCall100 Stock Tokens / contractUpside above strikeNever
Cash-secured putPutK × 100 USDG / contractBuying at K if it fallsNever
MarginCall or put20% notional + premium, marked liveUncapped for callsHealth < 80%

Writer flow

  1. Deposit Stock Tokens or USDG into your vault.
  2. Choose token, mode, strike, expiry, contracts. The premium quotes live.
  3. Mint. Collateral locks; the contract is listed.
  4. Fill. Premium minus fee lands in your wallet immediately.
  5. Manage. Buy back at the mark to unlock collateral early, or hold.
  6. Settle. Out of the money: collateral released. In the money: payout taken, remainder released.

Covered call yield

period yield  = premium / (spot × 100 × contracts)
annualised    = period yield × 365 / days to expiry

// 1 × NVDA $200 CALL, Oct 16 (37d), spot $184.20, premium $6.12
period yield  = 612 / 18,420       = 3.32%
annualised    = 3.32% × 365 / 37   = 32.8%
Margin writing is uncapped. A naked call can lose more than the collateral posted. Only use it if you understand liquidation.

Collateral & vault

Each writer has a vault on Robinhood Chain. Collateral is segregated per writer and per expiry; one writer's shortfall cannot touch another's assets.

  • Accepted: any listed Stock Token (for covered calls) and USDG.
  • Deposit / withdraw: no protocol fee, gas only. Withdrawals of locked collateral are blocked until the obligation is closed or settled.
  • Locked vs free: the vault view shows both; the bar under each asset is the locked share.

Covered and cash-secured positions hold the full worst-case payout in the vault, which is why they can never be liquidated.

Margin & liquidation

Applies to margin (naked) writers only.

initial margin      = 20% × spot × 100 × contracts + premium
health              = collateral value / required margin
maintenance         = health ≥ 80%

// below 80%: partial liquidation until health ≥ 100%
// penalty 2% of collateral → 50% liquidator, 50% insurance fund

Liquidations pause while the oracle deviation guard is active. The insurance fund backstops any shortfall after liquidation; it is funded by penalties and 10% of protocol fees.

Pricing

Three inputs produce every premium: the oracle spot, a fitted volatility surface, and time to expiry.

σ(K, T)   = σ_atm(T) · skew(K / S) · term(T)
fair      = BlackScholes(S, K, T, σ(K,T), r)
premium   = fair + spread(σ, OI)         // buyers
premium   = fair − spread(σ, OI)         // writers
fee       = max($0.25, 0.5% × premium × 100 × contracts)
  • σ_atm(T) is fitted from protocol fills and writer quotes per token and expiry, smoothed over a rolling window.
  • skew makes downside strikes richer than upside, matching listed markets.
  • spread widens with volatility and narrows with open interest. It is the LP's compensation.
  • r is the USDG lending rate on Robinhood Chain, updated daily.

All inputs are onchain. Two users viewing the same market in the same second see the same premium.

Oracle

The Stock Token oracle is the only price pip uses, for quoting, marking and settlement.

PropertyValue
CadenceOne signed print every 1.2s (median)
SignersThree independent; the adapter takes the median
Deviation guardPrint > 8% from the last is rejected; market halts until three consistent prints
StalenessNo fills on a print older than 10s
Settlement printFrozen at 20:00 UTC on expiry

Fees

ActionFeeMinimum
Buy0.50% of premium$0.25
Sell back0.50% of proceeds$0.25
Write (on fill)0.50% of premium$0.25
Expiry settlement0%
Deposit / withdraw0%
Liquidation penalty2% of collateral

Fee split: 70% to LPs, 20% to treasury, 10% to the insurance fund. No payment for order flow, no exercise or assignment fees.

Risk parameters

ParameterValue
Initial margin (naked)20% of notional + premium
Maintenance health80%
Liquidation penalty2%
Oracle deviation halt8% between prints
Oracle staleness10 seconds
Max open interest per token5% of token float
Strike increments$2.50 / $5 / $10 by price band
Strikes per market11
Expiries per token4
Settlement time20:00 UTC
Governance timelock48 hours

Governance

Parameters are set by a multisig behind a 48-hour public timelock. Every change is announced onchain before it takes effect. There is no protocol token; governance opens to LPs and writers per the roadmap on the Network page.

Listing a new token market requires an oracle feed with 30 days of history and three signers, $250K seed writer collateral across the four expiries, a vol fit that stabilises within 5% over 7 days, and a governance vote on max open interest and margin tier.

Read API

Public, unauthenticated, JSON. Base URL https://api.pip.xyz/v1. Rate limit 60 requests per minute per IP. Market makers get authenticated write access under agreement; email liquidity@pip.xyz.

GET/markets

All listed tokens with spot, 24h change, implied vol, open interest and available expiries.

{
  "markets": [
    { "token": "NVDA", "spot": 184.20, "change24h": 0.0124,
      "iv": 0.52, "openInterest": 4200000,
      "expiries": ["2026-09-12", "2026-09-18", "2026-10-16", "2026-12-18"] }
  ],
  "oracleTs": 1788968001
}

GET/markets/{token}/chain?expiry=2026-09-18

Every strike for one expiry with call and put premiums, Greeks and probability in the money.

{
  "token": "NVDA", "expiry": "2026-09-18", "spot": 184.20,
  "strikes": [
    { "K": 190, "call": { "premium": 4.20, "delta": 0.42, "theta": -0.18, "pitm": 0.39 },
                  "put":  { "premium": 9.85, "delta": -0.58, "theta": -0.17, "pitm": 0.61 } }
  ]
}

GET/positions/{address}

Open positions and written contracts for a wallet, each with entry, mark, value and unrealised P&L.

GET/oracle/{token}

Latest print, signer count, staleness and halt status.

GET/stats

TVL, open interest, 24h premium volume, tokens listed, and 30-day series for each.

Example

curl https://api.pip.xyz/v1/markets/NVDA/chain?expiry=2026-09-18 | jq '.strikes[] | select(.K==190)'

Contracts

Five Solidity contracts on Robinhood Chain. Verified source and addresses are published on the Protocol page at every release.

ContractResponsibilityKey functions
OracleAdapterMedian of signers, deviation guard, staleness, settlement freezelatest(token) settlementPrice(token, expiry)
VaultPer-writer collateral, lock and releasedeposit(asset, amount) withdraw(asset, amount) lockedOf(writer, expiry)
PricingEngineVol surface, Black-Scholes, spreadquote(token, K, expiry, isCall, qty) mark(positionId)
ClearingMint, fill, buy-back, fee routingbuy(token, K, expiry, isCall, usdc) sell(positionId, qty) write(mode, token, K, expiry, qty) buyBack(writtenId)
SettlementFreeze, payout, release, liquidationsettle(token, expiry) liquidate(writer) health(writer)

Position tokens

Long positions are ERC-1155 tokens. The id encodes token, strike, expiry and direction, so identical contracts are fungible and transferable between wallets. Written obligations are non-transferable records in Clearing tied to the writer's vault.

Events

event Bought(address indexed buyer, uint256 indexed id, uint256 qty, uint256 premium, uint256 fee);
event Sold(address indexed seller, uint256 indexed id, uint256 qty, uint256 proceeds);
event Written(address indexed writer, uint256 indexed id, uint8 mode, uint256 qty, uint256 premium);
event Settled(bytes32 indexed token, uint64 expiry, uint256 price);
event Liquidated(address indexed writer, uint256 collateralSeized, uint256 penalty);

Glossary

ATM / ITM / OTMAt, in, or out of the money: strike equal to, favourable to, or unfavourable to spot.
AssignmentOn pip, the cash-settled outcome of a written option finishing in the money. No shares change hands.
Covered callA call written against 100 Stock Tokens per contract held in the vault.
Cash-secured putA put written against K × 100 USDG per contract held in the vault.
DeltaChange in premium per $1 move in the token.
HealthCollateral value divided by required margin, for margin writers.
Implied volatilityThe vol input that reproduces current premiums; higher IV, pricier options.
MarkProtocol fair value of a contract at the latest oracle print.
NotionalSpot × 100 × contracts; the exposure a contract controls.
Oracle printOne signed Stock Token price from the oracle.
PremiumPrice of an option per share; × 100 per contract.
ThetaPremium lost per day from time passing, all else equal.
VegaChange in premium per one-point move in implied vol.

Support

Or use the contact form. Typical reply within one business day.

Risk. Options can expire worthless and writers can lose more than the premium collected. Nothing here is investment advice. pip is not affiliated with or endorsed by Robinhood Markets, Inc.