A standing alert removes the need to watch a screen. A level is crossed, and a message arrives at your server. It is tempting to treat that message as the whole story. It is the start of one. The message says something happened. What the market looks like now is a separate question, and it needs a separate read.

What arrives

When a watch fires, NoVo sends a signed POST to the webhook you registered. The signature is an HMAC-SHA256 computed over the raw body, carried in the X-NoVo-Signature header. The alert reports that a level was crossed. It never says what to do about it.

Check it before trusting it

Your webhook is an address on the public internet. Anyone who learns it can send a message there. The signature is what tells you the message came from NoVo and was not altered on the way. Compute the same HMAC over the raw body with your secret and compare. If they differ, discard the message.

Use the raw body. If your code parses the JSON and rebuilds it before checking, the bytes can change and a genuine message will fail. What the signature does and does not prove is in what the signature on a webhook proves.

A valid message can arrive more than once, or be sent again by someone who captured it. Keep track of what you have already handled and ignore repeats. The wider set of precautions is in your webhook endpoint is a door onto the internet.

The message is already old

Between the crossing and your reading of the message, time has passed. Price may have crossed back. On a fast day it may have crossed several times. The alert told you about one moment. Acting on it as if it were the present is the mistake.

Read again

So the next step is a read. If an agent handles your alerts, its instruction is simple. When an alert arrives, call the tool for that market and report where things stand now, with the reading’s age. For an equity level that is get_equity_map on a paid key. For a crypto level it is get_crypto_map. The report says the alert fired at this time, and here is the map now.

Keep the two times side by side. The time the watch fired and the time of the fresh reading. The gap between them is how much you missed.

What the agent does not do

It does not act. An alert followed by an automatic order is a trading system, and NoVo’s tools are not one. They only read. If a broker’s connector sits beside this one, the alert is not permission to use it. The reasoning is in why the read and the trade stay separate.

It does not guess what the crossing means for direction either. A level was crossed. The fresh read shows where spot sits against the walls. That is the report.

A quiet webhook

No message can mean no crossing. It can also mean the webhook is not registered, or your server was down. An armed alert with no webhook fires and arrives nowhere. Check with get_alerts now and then, as described in arming an alert through an agent.

Alerts over the MCP & API are deliberately small. They carry one fact, signed. The reading that gives the fact its context is one tool call away, and it comes with its own time.