# PIP-0005 · Canonical meaning of receipts.route

Specify the only shape `route` may take, and keep it empty until a router exists that is allowed to fill it.

## Why this exists

[PIP-0004](/pips/0004) refused to fill `route` until three conditions held. The first was a single canonical meaning across networks. This PIP writes that meaning. It does **not** authorise anyone to populate the field.

A receipt with a route and a receipt without one remain the same kind of object — `path.receipt`, same signature rules, `route` nullable. Filling it still must not require PATH to admit members or hold balances. Those two conditions stay; they belong to the PIP that first writes a non-null `route`.

## The shape

```json
{
  "legs": [
    {
      "via": { "rail": "sepa-inst", "asset_type": "fiat", "asset_code": "EUR" },
      "provider": "member-a",
      "share": "1",
      "asset_in": { "asset_type": "fiat", "asset_code": "EUR" },
      "asset_out": { "asset_type": "fiat", "asset_code": "EUR" },
      "eta_seconds": 30
    }
  ],
  "providers": ["member-a"],
  "eta_seconds": 30
}
```

| Field | Meaning |
|---|---|
| `legs[]` | Ordered hops. A one-rail payment is one leg. |
| `legs[].via` | The capability of the hop ([PIP-0006](/pips/0006)). Its `rail` is a rail register identifier ([PIP-0007](/pips/0007)), never a PATH network slug. |
| `legs[].provider` | Optional member that executed that hop. |
| `legs[].share` | Optional decimal fraction of the amount on this hop. Sum of shares on a split is `"1"`. |
| `legs[].asset_in` / `asset_out` | Assets ([PIP-0006](/pips/0006)) that entered and left the hop. |
| `legs[].eta_seconds` | Optional expected duration of the hop. |
| `providers` | Distinct providers across legs, for a reader that does not want to walk them. |
| `eta_seconds` | Optional expected duration of the whole route. |

`route` is either this object or `null`. Any other value is a non-conformity.

## Amendment — 2026-10-04

`legs[].rail` (a string) is replaced by `legs[].via` (a capability), and `asset_in` / `asset_out` are Assets rather than codes. The field is `null` in every conforming receipt, so no emitted object changes.

## Rule, still

Implementations MUST accept this shape and MUST emit `null` until a later PIP names who may fill it. A non-empty `route` today is the same non-conformity PIP-0004 already recorded: inventing PATH Liquidity that was not specified.

SEPA Instant, UPI and a blockchain are rails. They are not PATH networks. A network that writes its own corridor into `route` is still inventing a field this protocol has not opened.