Should trading webhook payloads be signed with HMAC?
HMAC is useful when the sender can sign the exact payload with a shared secret. It adds integrity/authenticity checks but does not replace TLS, authorization or replay protection.
What this means in practice
HMAC is useful when the sender can sign the exact payload with a shared secret. It adds integrity/authenticity checks but does not replace TLS, authorization or replay protection. This page is specifically about “Should trading webhook payloads be signed with HMAC?”, so each scenario below is explained by its own mechanism instead of sharing one generic diagnosis.
Real-world scenarios
Scenario A — Valid signature
Verify HMAC over the exact raw payload using a server-held secret and constant-time comparison. Then check freshness separately because a correctly signed old message can still be replayed. For Scenario A — Valid signature on question 95, use that evidence specifically to answer “Should trading webhook payloads be signed with HMAC?”; keep it separate from the evidence for the other scenarios on this page.
Scenario B — Tampered body
Verify HMAC over the exact raw payload using a server-held secret and constant-time comparison. Then check freshness separately because a correctly signed old message can still be replayed. For Scenario B — Tampered body on question 95, use that evidence specifically to answer “Should trading webhook payloads be signed with HMAC?”; keep it separate from the evidence for the other scenarios on this page.
Scenario C — Signed replay
A replay reuses a once-valid command. Combine unique signal ID with timestamp or nonce, expiry and a processed-command store so an old BUY cannot become a second live order. For Scenario C — Signed replay on question 95, use that evidence specifically to answer “Should trading webhook payloads be signed with HMAC?”; keep it separate from the evidence for the other scenarios on this page.
What to check
- TradingView alert log and exact send time
- HTTP status and receiver timestamp
- validated payload plus signal ID
- cTrader result only after transport is proven
Practical rule
For “Should trading webhook payloads be signed with HMAC?”, change only the first layer whose evidence no longer matches the intended action. Preserve signal identity, timestamps and final cTrader state, and reproduce execution-affecting changes on demo before live use.
Decision summary
Direct answer: HMAC is useful when the sender can sign the exact payload with a shared secret. It adds integrity/authenticity checks but does not replace TLS, authorization or replay protection.
Next action: Match the observed evidence to one scenario above, test that mechanism independently on demo and keep the result traceable with one signal ID.
Primary sources
Need a TradingView → cTrader execution route?
NRUNO routes your TradingView instructions to cTrader. Your strategy and signal logic remain yours.