What Is a Webhook in Crypto Trading? TradingView Guide
A webhook is an automatic HTTP POST that carries a TradingView alert to your bot. See the setup, payload fields, IP list and key security rules.
A webhook in crypto trading is an automatic message that one app sends to a web address the moment something happens, most often a TradingView alert that fires when your strategy's condition is met. Technically it is an HTTP POST request that carries your alert text to a webhook URL. The webhook cannot trade by itself: a receiver (your own bot, a paid service or an exchange's built-in webhook bot) reads the message and places the order through the exchange's API with your API key.
Key takeaways
- An API call is your program asking an exchange for something. A webhook is another app pushing a message to you without being asked.
- TradingView webhooks need a paid plan (Essential or higher) and two-factor authentication, accept only ports 80 and 443, and time out after three seconds.
- You still need an exchange API key with trading permission. It stays on the receiver and never goes inside the alert message.
- Protect the receiver with HTTPS, a secret passphrase in the payload and an allow-list of TradingView's four sending IP addresses.
- Webhooks can be missed, duplicated or delayed, and a signal is only as good as the strategy behind it. Most retail strategies lose money after fees.
Webhook vs API: what is the difference?
Both use the same web technology, but the direction is opposite. With an API call, your program decides when to ask: "what is the BTC price?" or "place this order". With a webhook, you give another service a URL in advance and it calls you when an event happens. Traders usually use both in one chain: TradingView calls your receiver with a webhook, and your receiver calls the exchange's API.
| Question | API call | Webhook |
|---|---|---|
| Who starts it? | Your program | The other service, such as TradingView |
| When does it happen? | Whenever your code asks, for example every few seconds | Only when an event happens, such as an alert firing |
| What it needs | An API key and secret, and signed requests | A public HTTPS address that is always online |
| Typical use | Reading balances, placing and cancelling orders | Delivering a buy or sell signal |
| Can it place a trade on its own? | Yes, if the key has trading permission | No, something must turn it into an API order |
The full order pipeline, from price data to a stop-loss sitting on the exchange, is explained in our guide on how crypto trading bots place trades.
How a TradingView alert becomes an exchange order
| Step | What happens | What can go wrong |
|---|---|---|
| 1 | Your strategy or indicator condition is met on the chart | The signal comes from a repainting indicator and later disappears |
| 2 | TradingView fires the alert and sends an HTTP POST with your message to the webhook URL | Your receiver is offline, or delivery fails |
| 3 | The receiver checks the passphrase, the sender's IP address and the fields | Without checks, anyone who finds the URL can send fake orders |
| 4 | The receiver runs risk checks: allowed symbol, maximum size, open positions, daily loss limit | With no cap, one bad alert opens a huge position |
| 5 | The receiver signs an order request with your API key and secret and sends it to the exchange API | Wrong IP binding, deleted key, clock drift or missing permission |
| 6 | The exchange accepts or rejects the order and returns an order ID | Partial fill, or rejection for minimum size or margin |
| 7 | The receiver places or confirms the stop-loss on the exchange and logs everything | The stop is never placed, so a crash leaves the trade unprotected |
Speed matters. TradingView cancels the request if the receiving server takes longer than three seconds, so well-built receivers reply at once and do the exchange work in the background.
TradingView webhook rules at a glance
These rules come from TradingView's own help pages. Plans and features change, so check the alert settings in your account.
| Rule | Detail |
|---|---|
| Plan | Webhook notifications are not in the free Basic plan. Essential is the lowest plan with them; Plus, Premium and Ultimate also include them. |
| Security | Webhook alerts work only when two-factor authentication is on for your TradingView account. |
| Method | An HTTP POST with your alert message as the body. |
| Ports | Only 80 and 443. A URL with any other port is rejected. |
| IPv6 | Not supported for webhooks. |
| Timeout | If your server takes more than three seconds, the request is cancelled. |
| Format | If the message is valid JSON it is sent as application/json; otherwise as text/plain. |
| Sending IP addresses | 52.89.214.238, 34.212.75.30, 54.218.53.128 and 52.32.178.7, for your allow-list. |
| Alert limit | An alert that triggers more than 15 times in 3 minutes is stopped. |
| Delivery | Webhooks may occasionally fail. The alert log has a webhook status column showing whether each one got through. |
| Credentials | TradingView says not to put login credentials or passwords in the webhook body. |
What goes in the alert message
The message is text you type into the alert. When the alert fires, TradingView swaps placeholders in double curly brackets for live values, so one alert can describe any trade. These are some of the placeholders TradingView documents:
| Placeholder | What it inserts |
|---|---|
{{ticker}} | The symbol, such as BTCUSDT |
{{exchange}} | The exchange of the chart's symbol |
{{interval}} | The chart timeframe |
{{close}} | The closing price of the bar that triggered the alert |
{{timenow}} | The time the alert fired |
{{strategy.order.action}} | "buy" or "sell" for a strategy order |
{{strategy.order.contracts}} | The quantity of that strategy order |
{{strategy.order.id}} | The name of the strategy order |
{{strategy.market_position}} | "long", "flat" or "short" after the order |
{{plot_0}} | The value of your script's first plot (up to {{plot_19}}) |
Your receiver decides which field names it expects. A typical JSON payload for your own bot, set out as a table, looks like this:
| Field | Example value | What it does |
|---|---|---|
| passphrase | A long random string you made up | Proves the alert came from you. It is not your exchange API secret. |
| symbol | {{ticker}} | Tells the receiver which market to trade |
| side | {{strategy.order.action}} | Buy or sell |
| qty | {{strategy.order.contracts}} | Size, in the units your strategy uses |
| price | {{close}} | Reference price, used to reject signals far from the market |
| sent_at | {{timenow}} | Lets the receiver ignore alerts that arrive late |
| order_id | {{strategy.order.id}} | Helps the receiver spot and drop duplicates |
Write the message as valid JSON, with double quotes around names and text values, so it is sent as application/json. One missing comma turns it into plain text, and most receivers will then reject it.
Why you still need an exchange API key
TradingView only sends a message. It has no access to your exchange account, so something else must act on the exchange for you. That is the job of an API key with trading permission, and it lives on the receiver, never in the alert. You have three broad choices:
- Your own bot on a server. You run code, for example in Python, on a cloud server or VPS that stays online all day. You control everything and are responsible for everything, including security and uptime.
- A third-party automation service. You paste your exchange API key into their platform and point the TradingView webhook at their URL. It is convenient, but you are trusting another company with a key that can trade your money, so first read whether it is safe to give an API key to a trading bot.
- An exchange's own webhook bot. Delta Exchange India has one built in, covered below, so no separate key or server is needed.
Whichever route you choose, follow the basic key rules. Give the key trading permission only and never withdrawal permission. Bind it to fixed IP addresses where the exchange allows it. Store the secret like a password, delete keys you no longer use, and never paste a secret into Telegram, WhatsApp, a Google Form or any website you do not trust. Anyone who promises guaranteed returns from a bot in exchange for your API key is showing a classic scam sign. Our guide to API keys on Indian exchanges compares what each platform offers.
Delta Exchange India's built-in TradingView webhook
Delta Exchange India, operated by Excelium Technologies Pvt Ltd, which states it is registered with FIU-IND, runs a webhook receiver of its own. TradingView alerts can then place orders on your Delta account without your own server. Based on Delta's tutorial, the steps are:
- Turn on two-factor authentication on your Delta account; the feature does not work without it.
- Open the "Algo" menu and choose "Trading Bot".
- Enter a "Webhook Name", choose the "Account Name" to trade on, tick the risk acknowledgement and click "Create Webhook".
- Confirm with the email OTP and your 2FA code.
- Copy the webhook URL and the TradingView message from the pop-up. Delta says the URL is not available again after you leave the page and should not be shared with anyone.
- In TradingView, add your strategy to the chart, create an alert on it, paste the message into the message box and the URL into the webhook field under notifications.
Menu names can differ slightly in your app version. Delta's message uses four fields:
| Field | Value in the message | What it does |
|---|---|---|
| symbol | {{ticker}} | The contract to trade |
| side | {{strategy.order.action}} | Buy or sell |
| qty | {{strategy.order.contracts}} | Number of contracts |
| trigger_time | {{timenow}} | When the alert fired |
Delta says you can use the Trading Bot at no additional cost; normal trading fees still apply to each order. It also advises opening the first position by hand, because TradingView strategy alerts reverse an existing position. Without one, a sell alert can open a fresh short instead of closing your long. If you would rather build your own receiver, you need a normal API key, and on Delta IP whitelisting is mandatory for trading keys; see how to create a Delta Exchange India API key. Our Delta Exchange review covers its fees and products.
How to secure your webhook receiver
TradingView does not document any signature on its webhook requests. Some services sign each webhook with a shared secret, an HMAC code sent in a header, so the receiver can prove who sent it. With TradingView you build that trust yourself:
- Use HTTPS on port 443, so the payload, including your passphrase, is encrypted in transit.
- Put a secret passphrase in the payload and reject any request without the exact value. Make it long and random, and change it if it may have leaked.
- Allow-list TradingView's four IP addresses in your firewall or code, and reject everything else.
- Never put your exchange API secret in the alert message. Alert text is stored in your TradingView account, shows up in the alert log and notifications, and easily ends up in screenshots. A leaked passphrase can be changed in a minute; a leaked API secret can trade your account.
- Treat the webhook URL as a secret. Anyone who has it can try to send orders.
- Validate every field. Allow only the symbols you trade, cap the quantity, and ignore alerts whose
{{timenow}}is more than a few seconds old. - Make orders safe to repeat. Keep a record of processed alerts and use a client order ID where the exchange supports one, so a repeated alert cannot open a second position.
What can go wrong with webhook trading
| Problem | What it looks like | How to reduce it |
|---|---|---|
| Missed alert | The server was down, took over three seconds, or delivery failed | Reply instantly, monitor uptime, check the webhook status column, and keep a stop-loss on the exchange so an open trade is protected even if the exit alert never arrives |
| Duplicate alert | Two identical messages, or an alert firing on every price tick, opens two positions | Trigger once per bar close, store processed IDs, check the current position before ordering |
| Delay | Seconds pass between the signal and the fill in a fast market | Use a maximum-slippage check or limit orders; see what slippage is |
| Repainting indicator | A signal shows on past bars but changes or vanishes in real time, so live alerts never match the chart | Alert on bar close, be wary of scripts that use higher-timeframe or future data, and forward test first |
| Alert stopped | The alert triggered more than 15 times in 3 minutes and TradingView switched it off | Fix the logic so it fires once per signal |
| Position mismatch | The strategy thinks you are flat while the exchange shows an open trade | Compare the receiver's view with the exchange's positions on every alert |
Repainting deserves special care. Many free scripts look brilliant on historical bars because they quietly use information that was not available at the time. That is one reason backtests overstate results; our guide on how to backtest a crypto trading strategy explains how to catch it.
Costs, tax and a reality check
- Tools: a paid TradingView plan for webhooks, plus a server if you run your own receiver.
- Trading costs: exchange fees on every order with 18% GST added on the fees, plus funding on perpetual futures and slippage.
- TDS: on Indian exchanges, 1% TDS is deducted on each qualifying sale of crypto on the spot market, so a busy spot bot ties up a lot of cash in TDS until you claim it back. Read how 1% TDS on crypto works.
- Tax: crypto gains are taxed at a flat 30% plus 4% cess, and losses cannot be set off against other income or carried forward. Futures tax is not settled; see our crypto futures legal and tax guide.
Automation does not create an edge. It carries out your rules faster and without emotion, but it also repeats your mistakes faster. Most retail strategies and bots lose money once fees, slippage and funding are counted, and backtests nearly always look better than live results. Trade only on exchanges registered with FIU-IND (see our list of FIU-registered exchanges), start with tiny sizes, and read our beginner's guide to crypto algo trading in India for the full roadmap.
FAQ
What is a webhook URL in trading?
It is the web address that receives your alert. When a TradingView alert fires, TradingView sends an HTTP POST with your alert message to that URL, and the program behind it decides whether to place an order.
Is the TradingView webhook free?
No. Webhook notifications are not part of TradingView's free Basic plan; Essential is the lowest plan that includes them, and two-factor authentication must be switched on.
Can TradingView place orders directly on an Indian exchange?
TradingView only sends the alert, and a receiver must turn it into an order through the exchange's API. Delta Exchange India has a built-in receiver; for other exchanges you need your own bot or a third-party service.
Should I put my API key in the TradingView alert message?
Never put your API secret in an alert message. Keep the key on the receiver, use a separate passphrase in the payload, and give the key trading permission only, with no withdrawals.
Why did my TradingView webhook not place a trade?
Common causes are a server that took longer than three seconds, a URL with a port other than 80 or 443, invalid JSON, a wrong passphrase, or the exchange rejecting the order over IP, permission or size. Check the webhook status column in the alert log and your receiver's logs.
Do I need coding skills to use webhooks for crypto trading?
Not always. An exchange's built-in webhook bot or a third-party service needs no code, but building your own receiver needs programming and server skills.
This article is AI-assisted, educational and general in nature. It is not financial advice and never a guarantee of profit. Every trade is at your own risk on your own exchange. See our risk disclosure and editorial policy.