Authentication
Every POST to a strategy webhook needs the strategy API key. GET …/health does not.
TradingView (use this)
TradingView cannot send custom headers. Auth goes on the Webhook URL only:
https://YOUR_POD.tradepod.in/strategy/strat_xxxxx/opt?key=YOUR_API_KEY
Copy that full URL from Strategy → Config. Leave the Message as entry/exit JSON without a "key" field.
Do not put the secret in the alert body. TradingView warns against putting credentials in webhook messages.
Other tools (Postman / bots)
Those can use a header instead of ?key=:
X-Api-Key: YOUR_API_KEYAuthorization: Bearer YOUR_API_KEY
A "key" field in JSON is also accepted, but it is not needed for TradingView.
Errors
| Status | Meaning | What to do |
|---|---|---|
| 401 | Missing or wrong key | Paste the full Webhook URL with ?key= from Config |
| 403 | TradingView off, or strategy disabled | Settings → Integrations; enable the strategy |
| 404 | Strategy not found | Recreate / copy URL again |
See TradingView alerts.