Automations are Trader and above. See plan comparison.
In plain English
A webhook is Tradion phoning your server, not your server phoning Tradion. You give an automation an HTTPS address; when it fires, Tradion sends one JSON message there. Traffic only goes that direction. Three consequences:- You need somewhere for it to land — an address on the public internet that answers HTTPS. Nothing on your laptop, nothing behind a company firewall.
- Anyone who learns your address can post to it. That is what the signature is for: a fingerprint proving Tradion sent the message. Read verifying the signature before trusting anything that arrives.
- Answer fast, work later. Tradion gives up after 8 seconds. Reply
200first, then act on the message.
The signature is computed over the exact bytes Tradion sends. Verify before you parse.
Setting a webhook action
In the automation canvas, open the Action node, enable the Webhook channel, and paste your endpoint into Webhook URL. Save the automation. The URL is checked at save time, and an automation with the webhook channel on and no URL will not save. One automation can send to a webhook and to Discord, Telegram, email, and in-app at once. The webhook payload is independent of what the other channels render.The request
Payload schema
Inside indicatorValues
Keys are the uppercase indicator code — RSI, MACD, ATR. A condition using a non-default period or parameters adds a second key shaped CODE:period:{params} carrying the same value under those settings. Candlestick patterns arrive as 1 when detected and 0 when not. Every value is a finite number; nothing is null.
Inside agentResult
Depending on the agent’s instruction,
thesis (string) and keyFindings (array of strings) may also appear. Treat unrecognised keys as optional and ignore them — fields are added without notice, and empty fields are omitted rather than sent as null.
Behavioural personalisation — your risk score, your documented patterns, references to your own trade history — is removed from webhook payloads by default, as it is for Discord and Telegram. Turn personalisation on for the channel if you want it included.
Verifying the signature
A signed request carriesX-Tradion-Signature. It is an HMAC — a scrambled fingerprint of the request body mixed with a secret only you and Tradion hold. Nobody can compute it without the secret, so a matching signature proves the request came from Tradion and the body was not altered in transit.
The value is sha256= followed by the HMAC-SHA256 digest of the raw request body, in lowercase hexadecimal. Three rules:
- Hash the raw bytes, not a re-serialised object. If your framework parses JSON before you see it, key order and whitespace change and the digest will not match.
- Compare in constant time. A plain
==leaks how many leading characters matched, which is enough to forge a signature given enough attempts. - Reject on mismatch, and reject when the header is missing. Fail closed.
Not acting on the same alert twice
Every delivery carries anIdempotency-Key header — a label that stays identical across retries of one alert, so you can recognise a repeat and ignore it. Its form is <automation id>_webhook_<minute bucket>, the minute bucket being the Unix timestamp in milliseconds divided by 60,000 and rounded down.
Store the keys you have handled and drop anything you have seen before. Without that, a retry sent after your endpoint accepted the request but timed out on the reply runs your handler twice. The same key also collapses repeated firings of one automation inside a minute into a single delivery.
Retry behaviour
Each attempt times out after 8 seconds. Return a2xx quickly and do the real work afterwards; a slow handler reads as a failure and gets retried.
A rejected signature should return
401, which stops the retries — correct, because a retry would fail the same way.
Requirements
Your endpoint URL must use HTTPS (plainhttp:// is rejected on save and again at send time), have a dotted hostname (a bare name like internal is rejected), stay under 2048 characters, and not resolve to a private or loopback address. localhost, 127.0.0.1, 0.0.0.0, ::1, 10.x.x.x, 192.168.x.x, 172.16.x.x through 172.31.x.x, 169.254.x.x, and cloud metadata hostnames are all blocked.
Why private addresses are blocked
This is SSRF protection — Server-Side Request Forgery, an attack where someone gets a server to fetch something on their behalf that they could not reach themselves. A webhook URL is an address a user picks and Tradion’s servers then call. Without the block, someone could point one at169.254.169.254, the cloud metadata address, and have Tradion’s own infrastructure read internal credentials and post them onward.
It costs you nothing in production. It does mean you cannot test against localhost: use a public tunnel with an HTTPS address, or a request-inspection service.
When deliveries stop arriving
- Nothing at all. Check the automation is active and that its conditions fired — the run history shows every evaluation.
- No signature header. See the warning above: it is omitted when the platform secret is unset.
- Signature never matches. Your framework is parsing the body before you hash it. Use the raw-body option.
- Arrives twice. You are not deduplicating on
Idempotency-Key. - Stopped after a deploy. A
4xxduring the deploy window permanently ends the retries for that delivery. Those alerts are gone.
Notification channels
The other four ways an automation can reach you.
Runs and history
Every evaluation, and whether delivery succeeded.
The AI Agent node
What produces the
agentResult block.Signal types
What can make an automation fire in the first place.