NRUNO Trading Automation Wiki · Question 95

Should trading webhook payloads be signed with HMAC?

Webhook SecurityLast reviewed: 25 Aug 2026
Short answer

HMAC is useful when the sender can sign the exact payload with a shared secret. It adds integrity/authenticity checks but does not replace TLS, authorization or replay protection.

What this means in practice

HMAC is useful when the sender can sign the exact payload with a shared secret. It adds integrity/authenticity checks but does not replace TLS, authorization or replay protection. This page is specifically about “Should trading webhook payloads be signed with HMAC?”, so each scenario below is explained by its own mechanism instead of sharing one generic diagnosis.

Real-world scenarios

Scenario A — Valid signature

Verify HMAC over the exact raw payload using a server-held secret and constant-time comparison. Then check freshness separately because a correctly signed old message can still be replayed. For Scenario A — Valid signature on question 95, use that evidence specifically to answer “Should trading webhook payloads be signed with HMAC?”; keep it separate from the evidence for the other scenarios on this page.

Scenario B — Tampered body

Verify HMAC over the exact raw payload using a server-held secret and constant-time comparison. Then check freshness separately because a correctly signed old message can still be replayed. For Scenario B — Tampered body on question 95, use that evidence specifically to answer “Should trading webhook payloads be signed with HMAC?”; keep it separate from the evidence for the other scenarios on this page.

Scenario C — Signed replay

A replay reuses a once-valid command. Combine unique signal ID with timestamp or nonce, expiry and a processed-command store so an old BUY cannot become a second live order. For Scenario C — Signed replay on question 95, use that evidence specifically to answer “Should trading webhook payloads be signed with HMAC?”; keep it separate from the evidence for the other scenarios on this page.

What to check

  • TradingView alert log and exact send time
  • HTTP status and receiver timestamp
  • validated payload plus signal ID
  • cTrader result only after transport is proven

Practical rule

For “Should trading webhook payloads be signed with HMAC?”, change only the first layer whose evidence no longer matches the intended action. Preserve signal identity, timestamps and final cTrader state, and reproduce execution-affecting changes on demo before live use.

Decision summary

Direct answer: HMAC is useful when the sender can sign the exact payload with a shared secret. It adds integrity/authenticity checks but does not replace TLS, authorization or replay protection.

Next action: Match the observed evidence to one scenario above, test that mechanism independently on demo and keep the result traceable with one signal ID.

Primary sources

Need a TradingView → cTrader execution route?

NRUNO routes your TradingView instructions to cTrader. Your strategy and signal logic remain yours.