# Receive TradingView Webhooks Locally

**URL:** https://tradingqna.com/t/receive-tradingview-webhooks-locally/182847
**Category:** Algos, strategies, code
**Created:** [May 31, 2025, 10:31am UTC](https://tradingqna.com/t/receive-tradingview-webhooks-locally/182847 "2025-05-31T10:31:06Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![jugador](https://tradingqna.com/letter_avatar_proxy/v4/letter/j/cab0a1/32.png) [@jugador](https://tradingqna.com/u/jugador)
#### Post date: [May 31, 2025, 10:31am UTC](https://tradingqna.com/t/receive-tradingview-webhooks-locally/182847/1 "2025-05-31T10:31:06Z")

</div>

Use Python (Flask) to create a simple HTTP server that listens for POST requests.  
Then, use Ngrok to expose your local server to the internet through a secure tunnel.

When you run Ngrok, it will provide a public HTTPS URL like:  
[https://abc123.ngrok.io](https://abc123.ngrok.io) → [http://localhost:5000](http://localhost:5000)

Copy this URL and paste it into the Webhook URL field in TradingView. That’s it!  
And the good thing is Kite Connect Personal APIs are free for placing orders.

@Matti , is there any security risk in exposing our local server to the internet using this method?

---

<div class="post-metadata">

### Author: ![nivas\_k](https://tradingqna.com/user_avatar/tradingqna.com/nivas_k/32/76788_2.png) [@nivas\_k](https://tradingqna.com/u/nivas_k)
#### Post date: [June 2, 2025, 6:31am UTC](https://tradingqna.com/t/receive-tradingview-webhooks-locally/182847/2 "2025-06-02T06:31:31Z")

</div>

Yes, exposing your local Flask server with Ngrok is convenient for development or testing, but it does come with security risks.

**Key concerns include:**

- Direct Internet Access: Ngrok creates a public tunnel that bypasses your firewall. Anyone with the link can reach your Flask server. If the webhook endpoint lacks validation, attackers could send malicious data.

- URL Guessing & Scanning: Ngrok URLs may seem random, but attackers use bots to scan for live tunnels. If found, they could probe for vulnerabilities in your app.

- Phishing & Abuse: Ngrok has been misused to host fake login pages or malware, which could affect your tunnel’s reputation or get it flagged.

- Firewall Bypass: Because Ngrok opens an outbound tunnel, your network firewall can’t filter incoming requests like it usually would.

- Shared IP Reputation: Free Ngrok tunnels share IPs. If someone else using that IP does something malicious, your tunnel might get blocked.

---

<div class="post-metadata">

### Author: ![jugador](https://tradingqna.com/letter_avatar_proxy/v4/letter/j/cab0a1/32.png) [@jugador](https://tradingqna.com/u/jugador)
#### Post date: [June 2, 2025, 8:22am UTC](https://tradingqna.com/t/receive-tradingview-webhooks-locally/182847/3 "2025-06-02T08:22:27Z")

</div>

1. Don’t Share Your Ngrok URL Publicly
2. use HTTPS via Ngrok
3. Add a Secret Key =\> Make TradingView to send a Secret Key in the payload
4. Validate Payload Format
5. Add Basic Auth =\> ngrok http -auth=“user:pass” 5000
6. Add a Random Token to URL
7. Use a Local Reverse Proxy (eg: NGINX)

> [@nivas\_k](#):
>
> Shared IP Reputation: Free Ngrok tunnels share IPs. If someone else using that IP does something malicious, your tunnel might get blocked.

use alternative like: cloudflared

@Matti and @nivas_k it’s still not secure?

---

<div class="post-metadata">

### Author: ![nivas\_k](https://tradingqna.com/user_avatar/tradingqna.com/nivas_k/32/76788_2.png) [@nivas\_k](https://tradingqna.com/u/nivas_k)
#### Post date: [June 2, 2025, 1:13pm UTC](https://tradingqna.com/t/receive-tradingview-webhooks-locally/182847/4 "2025-06-02T13:13:31Z")

</div>

This reduces exposure, but no setup is ever 100 % foolproof.

---

<div class="post-metadata">

### Author: ![jugador](https://tradingqna.com/letter_avatar_proxy/v4/letter/j/cab0a1/32.png) [@jugador](https://tradingqna.com/u/jugador)
#### Post date: [June 2, 2025, 3:25pm UTC](https://tradingqna.com/t/receive-tradingview-webhooks-locally/182847/5 "2025-06-02T15:25:02Z")

</div>

> [@nivas\_k](#):
>
> This reduces exposure

isn’t that good.

> [@nivas\_k](#):
>
> no setup is ever 100 % foolproof.

so @nivas_k what you proposed to make it 100 % foolproof.  
Is there any other way to receive TradingView Webhooks locally?
