NixoraTrade

How alerts are routed

The three webhook addresses, how many accounts each one reaches, why one account refusing is normal, and why a ticket number can never be broadcast.

This is the part of the product most people meet first and understand last. It is worth doing properly, because almost every "why did it place two orders?" question traces back to one of the ideas on this page.

We will start from what a webhook actually is, then look at the three kinds this system issues, and finish with the rules that decide what you are allowed to put in an alert.

What a webhook is

A webhook is a private address that something else can send a message to.

Think of it as a PO box that you own. You hand the box number to anyone you want to hear from — your charting platform, a script, a colleague's system. When they have something to tell you, they drop a note in. Nobody has to be standing there waiting; the note arrives, and it gets acted on.

The important reversal is this. Normally your software asks a server for something — you open a page, it fetches data. A webhook runs the other way: someone else's software makes a request to us, without being asked. That is what makes automation at 3am possible. TradingView notices your condition, posts a small message to your address, and an order reaches your broker while you sleep.

Three things follow from that, and they matter:

  1. Anyone holding the address can post to it. There is no username or password step — the address is the credential. Treat it exactly like a password.
  2. It is one-way and immediate. The sender posts and moves on. It does not wait to hear whether your broker filled anything. That is why the result comes back to you through the Journal and your notifications, not through the alert.
  3. We must decide what to do with the message on our own. Nothing about the sender tells us which account you meant. The address does. That is the whole subject of this page.

The anatomy of your webhook address

Every address we issue looks like this:

https://hook.nixoratrade.com/h/a7f3c9e2b4d18f60c5a2e9b7d4f1 our server — always the same which KIND of address your token — the destination AND the secret never share it, never screenshot it

The last part is the only bit that varies, and it does two jobs at once. It tells us where the message is going, and it proves you are the one who sent it. There is nothing else to check.

So: do not paste a webhook address into a public forum, a support ticket, or a screenshot. If one does escape, regenerate it — the old address stops working immediately.

The three kinds of address

Here is the idea the rest of the page rests on. When an alert arrives, we must work out which accounts it is for. The three kinds of address differ only in how many accounts that turns out to be.

YOU SEND TO IT REACHES Account address /h/… one account, no strategy 1 account Strategy address /hs/grp_… one strategy, every account subscribed to it account 1 account 2 account 3 N accounts Subscription address /hs/sub_… one strategy, one account 1 account

Read the middle row carefully — it is the one that changes how you think. The strategy address is not tied to an account at all. It is tied to a strategy, and it reaches however many accounts you have subscribed to that strategy: one today, four next month, without you touching the alert.

In plain terms:

You want to… Use
run an automated strategy, possibly on several accounts the strategy address
do something to one specific account, or name a specific order the account address
treat one account differently from the rest of a strategy that account's subscription address

If you have one account and one strategy, all three do the same thing, and the strategy address is the one to start with — it is the one that still works when you add a second account.

Where to find them in the app

The account address is on the Auto Signals screen, shown once when it is created. Copy it then; for security we do not show it again, though you can always regenerate.

The strategy and subscription addresses live on the Strategies tab of Auto Signals, which is part of the strategy webhooks feature. That feature is live and production-verified, but it currently ships switched off while it is rolled out — an administrator turns it on under Admin → Labs → "Strategy webhooks". If you cannot see a Strategies tab, that switch is why.

What you actually send

The message body is a small piece of JSON — a list of "name": value pairs in braces. A market buy is three fields:

{"action": "open", "side": "buy", "symbol": "EURUSD"}

Note the shape, because it catches people out: the verb is action, and the direction is a separate field, side. There is no "action": "buy". Opening is open plus a side; the many other verbs exist for closing and managing what is already there.

Field Meaning
action what to do. Defaults to open if you leave it out
side buy or sell — the direction of an opening order
symbol the instrument. An exchange prefix is stripped for you, so OANDA:EURUSD works
orderType market (the default), limit, or stop
price the level to wait at, for a limit or stop order
lots an exact size (vol_lots is accepted as an alias)
risk size from risk instead, and the system works out the lots
sl / tp stop loss and take profit
ticket a specific existing order, by its broker ticket number

Two worked examples. "Buy EURUSD, half a lot, stop at 1.0800, target 1.0950":

{"action": "open", "side": "buy", "symbol": "EURUSD", "vol_lots": 0.5, "sl": 1.0800, "tp": 1.0950}

And "close my long EURUSD position":

{"action": "closelong", "symbol": "EURUSD"}

There are thirty verbs in total, grouped into opens, closes, partial closes, reversals, pending-order edits and account switches — and which of them a given webhook address will accept is not the same for all three. That is a subject of its own: see Alert syntax for the full vocabulary, worked examples of each group, and the table of what each address is allowed to do.

In TradingView, the JSON goes in the alert's Message box, and the webhook address goes in the Webhook URL field under Notifications. Nothing else is required.

What happens after you press send

A fanned-out alert is read once, and then each account decides for itself. Your per-account settings — sizing, symbol mapping, the safety rails — are applied separately.

READ ONCE EACH ACCOUNT DECIDES ON ITS OWN Your alert read and checked once account 1 · its own sizing and rails placed account 2 · its own sizing and rails placed account 3 · its own sizing and rails refused — a rail on THIS account said no the others are unaffected

One account refusing is normal, not a malfunction. Account 3 might have a wider spread right now, a different symbol map, or less free margin. Each refusal is recorded against the alert that caused it, with its reason, so it is something you look up rather than something you have to guess at.

The one rule that decides what you may say

A quantity can be broadcast to many accounts. An identity cannot.

"Buy half a lot" makes sense sent to five accounts. "Close order #148302" does not — that ticket number exists at exactly one broker, on exactly one account, and means nothing on the other four.

So a command naming a specific ticket is refused on the strategy address rather than quietly reinterpreted. That refusal is deliberate, and the reason is worth knowing: a dropped ticket once turned "close order #148302" into "close everything in that direction". An instruction we cannot honour exactly must be rejected, never silently widened into a different one.

Send ticket-specific instructions to the account or subscription address, where there is exactly one account to apply them to.

The same logic governs the execution switches. eaoff stops trading for a whole account, so it is accepted only on the account address — sent to a strategy that several accounts share, it would silently disarm strategies you never intended to touch.

The strategy address speaks a smaller language

This is the single most common surprise, so it gets its own section.

The thirty verbs above are the account vocabulary. A strategy or subscription address (/hs/…) accepts only five:

open · close · modify · cancel · reverse

Send closelong to a strategy address and it is refused with unknown action — even though closelong is perfectly valid on an account address. The five verbs are not a reduced feature set; they are the same capabilities expressed with fields instead of longer verb names, because an instruction that fans out to several accounts has to stay unambiguous. Eleven of the account vocabulary's fourteen shapes are reachable this way.

What you want Account address Strategy / subscription address
open long open + side: buy same
close the long side closelong close + side: sell
close half the long closelongpct, lots: 50 close + side: sell + close_pct: 50
close a quarter lot closelongvol, lots: 0.25 close + side: sell + close_lots: 0.25
close both directions closelongshort close + both: true
…and remove pendings too closeall close + both: true + include_pending: true
flip long to short closelongopenshort reverse + side: sell
cancel buy pendings cancellong cancel + side: buy
change stops on longs modifylong modify + side: buy
set stops on a resting buy-limit newsltpbuylimit modify + order_type: buylimit
close this side, then open closelongopenlong open + side: buy + close_first: same
close both sides, then open closelongshortopenlong open + side: buy + close_first: both
{"action": "close", "side": "sell", "symbol": "EURUSD", "close_pct": 50}

The side trap, which has bitten in production

side does not mean the same thing on every verb, and getting it backwards is silent:

Verb side means
open the direction you want to be in — buy goes long
close the direction of the closing order, which is the OPPOSITE of the position. side: sell closes a LONG
cancel the pending order's own side. side: buy cancels buy-stops and buy-limits
modify the position's own side. side: buy changes the stops on your longs

So close is the odd one out: it is the only verb where side is inverted, because it names the order that does the closing rather than the thing being closed. A close has a position to invert against; a pending order and a modify target do not. Sharing one rule between them once cancelled the wrong direction's pending orders and stranded twelve live buy-limits.

Two more refusals worth knowing, both deliberate: both has no percentage or exact-lot form (a single number cannot mean two different positions — send one per side), and include_pending only means anything alongside both (to clear one side's pendings, use cancel).

Which address may send which

Three rules produce the whole table, and every restriction follows from one of them.

Alert arrives on /hs/ (strategy) names a ticket? refused — one order, one account an account switch? refused — would disarm the account outside the five verbs? refused — unknown action an open, on a managed-only sub? refused — entries come from the group otherwise — admitted Every refusal is journalled with its reason.

Account /h/ Strategy /hs/grp_ Subscription /hs/sub_
The thirty verbs yes no — the five canonical verbs only no — the five canonical verbs only
open yes yes yes, unless set to management-only
close (with side, close_pct, close_lots, both) yes yes yes
modify (by side, or order_type for a resting pending) yes yes yes
cancel (by side) yes yes yes
open + close_first (close, then open) yes yes yes, unless management-only
reverse yes yes yes, unless management-only
TradingView events dialect yes yes yes
Anything carrying a ticket yes refused refused
eaon eaoff closealleaoff yes refused refused

A quantity can be broadcast; an identity cannot. "Close half a lot" is meaningful on five accounts. "Close order #148302" is meaningful on exactly one — the ticket exists at a single broker. Rather than guess, we refuse. A dropped ticket once turned "close order #148302" into "close every position in that direction", on every subscribed account.

A command may only touch what its own scope owns. The execution switches reach the entire account. Sent to a strategy that three accounts share, eaoff would silently disarm every other strategy running on them — including ones you were not thinking about.

The only shapes a strategy address genuinely cannot express are eaon, eaoff and closealleaoff — and that is deliberate rather than a gap: they switch execution for the WHOLE account, so on a strategy several accounts share they would disarm every other strategy running on them.

One signal must not open the same account twice. A subscription can be set to accept management only, so its own address cannot also open a position for a signal the strategy address already handled. Off by default: every subscription address can open unless you change it.

Running several strategies on one account

Most platforms tell you to open a second account when you want two strategies on the same symbol, because a position belongs to the account — so an exit from either one closes the whole thing.

Here a position belongs to (account, strategy). An exit closes only the slice belonging to the strategy that sent it, and the other strategy's position is untouched. One account, several strategies, no second account to fund.

BEFORE AFTER A EXITS What we track strategy A · long 100 strategy B · long 50 What your broker holds AAPL 150 shares one position · no strategy on it A sends "close" sells its own 100 only strategy A · flat strategy B · long 50 — untouched AAPL 50 shares still one position

Two things follow, and both are worth understanding before you rely on it.

The split is ours to track — your broker does not see it. On a netting account (stocks, and MetaTrader 5 in netting mode) the broker holds one blended position and has no idea two strategies are involved. MetaTrader 4 hedges by nature and already carries the strategy in the order comment, so there the attribution is readable at the broker itself.

If our books and the broker ever disagree, the system stops rather than guesses. Close a trade by hand in MetaTrader, or take an unusual partial fill, and the slices stop adding up to what the broker holds. When that happens, a scoped exit on that account is refused with a reason — because the alternative is computing a close against a number we are not sure of, and a position read that is wrongly treated as "flat" does not close anything: it opens a second full position. Refusing is the safe direction.

Common mistakes, and what they look like

Before you automate anything

Send one alert to a demo or paper account and watch it arrive end to end. The first order you see placed, journalled and notified is what turns all of the above from a description into something you can trust — and it costs nothing to be wrong on a demo account. When you move to a funded account, the one extra step is turning on Allow trading on a real account in the EA.