100-Day Trade Challenge: trade on our AI predictions, up to 2 trade ideas a day. Free · educational · unregulated & risky Create free account
Cryptos: 21,748 Exchanges: 1,506 Market Cap: $2.87T 2.73% 24h Vol: $100.49B Dominance: BTC: 58.3% ETH: 11.4% Fear & Greed: 74/100 USD/INR: ₹95.83
Trading

What Is a Webhook in Crypto Trading? TradingView Guide

A webhook is an automatic HTTP POST that carries a TradingView alert to your bot. See the setup, payload fields, IP list and key security rules.

What Is a Webhook in Crypto Trading? TradingView Guide
Photo: Leon Brooks, public domain, via Wikimedia Commons

A webhook in crypto trading is an automatic message that one app sends to a web address the moment something happens, most often a TradingView alert that fires when your strategy's condition is met. Technically it is an HTTP POST request that carries your alert text to a webhook URL. The webhook cannot trade by itself: a receiver (your own bot, a paid service or an exchange's built-in webhook bot) reads the message and places the order through the exchange's API with your API key.

Key takeaways

  • An API call is your program asking an exchange for something. A webhook is another app pushing a message to you without being asked.
  • TradingView webhooks need a paid plan (Essential or higher) and two-factor authentication, accept only ports 80 and 443, and time out after three seconds.
  • You still need an exchange API key with trading permission. It stays on the receiver and never goes inside the alert message.
  • Protect the receiver with HTTPS, a secret passphrase in the payload and an allow-list of TradingView's four sending IP addresses.
  • Webhooks can be missed, duplicated or delayed, and a signal is only as good as the strategy behind it. Most retail strategies lose money after fees.

Webhook vs API: what is the difference?

Both use the same web technology, but the direction is opposite. With an API call, your program decides when to ask: "what is the BTC price?" or "place this order". With a webhook, you give another service a URL in advance and it calls you when an event happens. Traders usually use both in one chain: TradingView calls your receiver with a webhook, and your receiver calls the exchange's API.

QuestionAPI callWebhook
Who starts it?Your programThe other service, such as TradingView
When does it happen?Whenever your code asks, for example every few secondsOnly when an event happens, such as an alert firing
What it needsAn API key and secret, and signed requestsA public HTTPS address that is always online
Typical useReading balances, placing and cancelling ordersDelivering a buy or sell signal
Can it place a trade on its own?Yes, if the key has trading permissionNo, something must turn it into an API order

The full order pipeline, from price data to a stop-loss sitting on the exchange, is explained in our guide on how crypto trading bots place trades.

How a TradingView alert becomes an exchange order

StepWhat happensWhat can go wrong
1Your strategy or indicator condition is met on the chartThe signal comes from a repainting indicator and later disappears
2TradingView fires the alert and sends an HTTP POST with your message to the webhook URLYour receiver is offline, or delivery fails
3The receiver checks the passphrase, the sender's IP address and the fieldsWithout checks, anyone who finds the URL can send fake orders
4The receiver runs risk checks: allowed symbol, maximum size, open positions, daily loss limitWith no cap, one bad alert opens a huge position
5The receiver signs an order request with your API key and secret and sends it to the exchange APIWrong IP binding, deleted key, clock drift or missing permission
6The exchange accepts or rejects the order and returns an order IDPartial fill, or rejection for minimum size or margin
7The receiver places or confirms the stop-loss on the exchange and logs everythingThe stop is never placed, so a crash leaves the trade unprotected

Speed matters. TradingView cancels the request if the receiving server takes longer than three seconds, so well-built receivers reply at once and do the exchange work in the background.

TradingView webhook rules at a glance

These rules come from TradingView's own help pages. Plans and features change, so check the alert settings in your account.

RuleDetail
PlanWebhook notifications are not in the free Basic plan. Essential is the lowest plan with them; Plus, Premium and Ultimate also include them.
SecurityWebhook alerts work only when two-factor authentication is on for your TradingView account.
MethodAn HTTP POST with your alert message as the body.
PortsOnly 80 and 443. A URL with any other port is rejected.
IPv6Not supported for webhooks.
TimeoutIf your server takes more than three seconds, the request is cancelled.
FormatIf the message is valid JSON it is sent as application/json; otherwise as text/plain.
Sending IP addresses52.89.214.238, 34.212.75.30, 54.218.53.128 and 52.32.178.7, for your allow-list.
Alert limitAn alert that triggers more than 15 times in 3 minutes is stopped.
DeliveryWebhooks may occasionally fail. The alert log has a webhook status column showing whether each one got through.
CredentialsTradingView says not to put login credentials or passwords in the webhook body.

What goes in the alert message

The message is text you type into the alert. When the alert fires, TradingView swaps placeholders in double curly brackets for live values, so one alert can describe any trade. These are some of the placeholders TradingView documents:

PlaceholderWhat it inserts
{{ticker}}The symbol, such as BTCUSDT
{{exchange}}The exchange of the chart's symbol
{{interval}}The chart timeframe
{{close}}The closing price of the bar that triggered the alert
{{timenow}}The time the alert fired
{{strategy.order.action}}"buy" or "sell" for a strategy order
{{strategy.order.contracts}}The quantity of that strategy order
{{strategy.order.id}}The name of the strategy order
{{strategy.market_position}}"long", "flat" or "short" after the order
{{plot_0}}The value of your script's first plot (up to {{plot_19}})

Your receiver decides which field names it expects. A typical JSON payload for your own bot, set out as a table, looks like this:

FieldExample valueWhat it does
passphraseA long random string you made upProves the alert came from you. It is not your exchange API secret.
symbol{{ticker}}Tells the receiver which market to trade
side{{strategy.order.action}}Buy or sell
qty{{strategy.order.contracts}}Size, in the units your strategy uses
price{{close}}Reference price, used to reject signals far from the market
sent_at{{timenow}}Lets the receiver ignore alerts that arrive late
order_id{{strategy.order.id}}Helps the receiver spot and drop duplicates

Write the message as valid JSON, with double quotes around names and text values, so it is sent as application/json. One missing comma turns it into plain text, and most receivers will then reject it.

Why you still need an exchange API key

TradingView only sends a message. It has no access to your exchange account, so something else must act on the exchange for you. That is the job of an API key with trading permission, and it lives on the receiver, never in the alert. You have three broad choices:

  • Your own bot on a server. You run code, for example in Python, on a cloud server or VPS that stays online all day. You control everything and are responsible for everything, including security and uptime.
  • A third-party automation service. You paste your exchange API key into their platform and point the TradingView webhook at their URL. It is convenient, but you are trusting another company with a key that can trade your money, so first read whether it is safe to give an API key to a trading bot.
  • An exchange's own webhook bot. Delta Exchange India has one built in, covered below, so no separate key or server is needed.

Whichever route you choose, follow the basic key rules. Give the key trading permission only and never withdrawal permission. Bind it to fixed IP addresses where the exchange allows it. Store the secret like a password, delete keys you no longer use, and never paste a secret into Telegram, WhatsApp, a Google Form or any website you do not trust. Anyone who promises guaranteed returns from a bot in exchange for your API key is showing a classic scam sign. Our guide to API keys on Indian exchanges compares what each platform offers.

Delta Exchange India's built-in TradingView webhook

Delta Exchange India, operated by Excelium Technologies Pvt Ltd, which states it is registered with FIU-IND, runs a webhook receiver of its own. TradingView alerts can then place orders on your Delta account without your own server. Based on Delta's tutorial, the steps are:

  1. Turn on two-factor authentication on your Delta account; the feature does not work without it.
  2. Open the "Algo" menu and choose "Trading Bot".
  3. Enter a "Webhook Name", choose the "Account Name" to trade on, tick the risk acknowledgement and click "Create Webhook".
  4. Confirm with the email OTP and your 2FA code.
  5. Copy the webhook URL and the TradingView message from the pop-up. Delta says the URL is not available again after you leave the page and should not be shared with anyone.
  6. In TradingView, add your strategy to the chart, create an alert on it, paste the message into the message box and the URL into the webhook field under notifications.

Menu names can differ slightly in your app version. Delta's message uses four fields:

FieldValue in the messageWhat it does
symbol{{ticker}}The contract to trade
side{{strategy.order.action}}Buy or sell
qty{{strategy.order.contracts}}Number of contracts
trigger_time{{timenow}}When the alert fired

Delta says you can use the Trading Bot at no additional cost; normal trading fees still apply to each order. It also advises opening the first position by hand, because TradingView strategy alerts reverse an existing position. Without one, a sell alert can open a fresh short instead of closing your long. If you would rather build your own receiver, you need a normal API key, and on Delta IP whitelisting is mandatory for trading keys; see how to create a Delta Exchange India API key. Our Delta Exchange review covers its fees and products.

How to secure your webhook receiver

TradingView does not document any signature on its webhook requests. Some services sign each webhook with a shared secret, an HMAC code sent in a header, so the receiver can prove who sent it. With TradingView you build that trust yourself:

  • Use HTTPS on port 443, so the payload, including your passphrase, is encrypted in transit.
  • Put a secret passphrase in the payload and reject any request without the exact value. Make it long and random, and change it if it may have leaked.
  • Allow-list TradingView's four IP addresses in your firewall or code, and reject everything else.
  • Never put your exchange API secret in the alert message. Alert text is stored in your TradingView account, shows up in the alert log and notifications, and easily ends up in screenshots. A leaked passphrase can be changed in a minute; a leaked API secret can trade your account.
  • Treat the webhook URL as a secret. Anyone who has it can try to send orders.
  • Validate every field. Allow only the symbols you trade, cap the quantity, and ignore alerts whose {{timenow}} is more than a few seconds old.
  • Make orders safe to repeat. Keep a record of processed alerts and use a client order ID where the exchange supports one, so a repeated alert cannot open a second position.

What can go wrong with webhook trading

ProblemWhat it looks likeHow to reduce it
Missed alertThe server was down, took over three seconds, or delivery failedReply instantly, monitor uptime, check the webhook status column, and keep a stop-loss on the exchange so an open trade is protected even if the exit alert never arrives
Duplicate alertTwo identical messages, or an alert firing on every price tick, opens two positionsTrigger once per bar close, store processed IDs, check the current position before ordering
DelaySeconds pass between the signal and the fill in a fast marketUse a maximum-slippage check or limit orders; see what slippage is
Repainting indicatorA signal shows on past bars but changes or vanishes in real time, so live alerts never match the chartAlert on bar close, be wary of scripts that use higher-timeframe or future data, and forward test first
Alert stoppedThe alert triggered more than 15 times in 3 minutes and TradingView switched it offFix the logic so it fires once per signal
Position mismatchThe strategy thinks you are flat while the exchange shows an open tradeCompare the receiver's view with the exchange's positions on every alert

Repainting deserves special care. Many free scripts look brilliant on historical bars because they quietly use information that was not available at the time. That is one reason backtests overstate results; our guide on how to backtest a crypto trading strategy explains how to catch it.

Costs, tax and a reality check

  • Tools: a paid TradingView plan for webhooks, plus a server if you run your own receiver.
  • Trading costs: exchange fees on every order with 18% GST added on the fees, plus funding on perpetual futures and slippage.
  • TDS: on Indian exchanges, 1% TDS is deducted on each qualifying sale of crypto on the spot market, so a busy spot bot ties up a lot of cash in TDS until you claim it back. Read how 1% TDS on crypto works.
  • Tax: crypto gains are taxed at a flat 30% plus 4% cess, and losses cannot be set off against other income or carried forward. Futures tax is not settled; see our crypto futures legal and tax guide.

Automation does not create an edge. It carries out your rules faster and without emotion, but it also repeats your mistakes faster. Most retail strategies and bots lose money once fees, slippage and funding are counted, and backtests nearly always look better than live results. Trade only on exchanges registered with FIU-IND (see our list of FIU-registered exchanges), start with tiny sizes, and read our beginner's guide to crypto algo trading in India for the full roadmap.

FAQ

What is a webhook URL in trading?

It is the web address that receives your alert. When a TradingView alert fires, TradingView sends an HTTP POST with your alert message to that URL, and the program behind it decides whether to place an order.

Is the TradingView webhook free?

No. Webhook notifications are not part of TradingView's free Basic plan; Essential is the lowest plan that includes them, and two-factor authentication must be switched on.

Can TradingView place orders directly on an Indian exchange?

TradingView only sends the alert, and a receiver must turn it into an order through the exchange's API. Delta Exchange India has a built-in receiver; for other exchanges you need your own bot or a third-party service.

Should I put my API key in the TradingView alert message?

Never put your API secret in an alert message. Keep the key on the receiver, use a separate passphrase in the payload, and give the key trading permission only, with no withdrawals.

Why did my TradingView webhook not place a trade?

Common causes are a server that took longer than three seconds, a URL with a port other than 80 or 443, invalid JSON, a wrong passphrase, or the exchange rejecting the order over IP, permission or size. Check the webhook status column in the alert log and your receiver's logs.

Do I need coding skills to use webhooks for crypto trading?

Not always. An exchange's built-in webhook bot or a third-party service needs no code, but building your own receiver needs programming and server skills.


This article is AI-assisted, educational and general in nature. It is not financial advice and never a guarantee of profit. Every trade is at your own risk on your own exchange. See our risk disclosure and editorial policy.

Put it into practice

Run the 100-trade challenge: cap every loss, log every trade, and find out honestly whether you have an edge.