Security
Your broker password stays on your PC.
Hookmode servers receive, validate, and route the signal. Your paired Windows device stores the broker password and uses its local MetaTrader 5 terminal to place the trade.
Where your data lives
Stays on your PC
- broker password (DPAPI)
- device token
- MetaTrader 5 session
- local trade mirror (SQLite)
Shared with the web app
- account nickname, server, login
- balance / equity snapshots
- open positions and open P&L (every 60 s)
- trades and realized P&L
- signal payloads and trace events
How the connection is protected
Password on your PC only
You type it on your machine. Windows encrypts it (DPAPI), and the desktop app uses it locally to connect the MetaTrader 5 terminal. Our servers keep the nickname, server and login. Never the password. Protect your Windows sign-in and lock the PC when you leave it.
Outbound only
The desktop app opens a TLS connection to Hookmode. It communicates with the MetaTrader 5 terminal over localhost on the same PC. No port forwarding is needed.
Pair with a code, revoke in a click
A 6-digit code is valid for 10 minutes and can be used once. Every device gets its own token. Unpair it from the web app to revoke its access.
A key per strategy
Every strategy has its own 32-character key, sent in the signature field of the message. A request without a valid key is rejected before an order is sent. Rotate the key at any time. TradingView cannot add custom headers to its requests, so the key sits in the message body, protected in transit by TLS.
Terminal stays local
Hookmode manages one MetaTrader 5 terminal per account. Each terminal uses a per-session token and is reached only by the desktop app on your PC.
Your machine, your IP
Orders are submitted by your own PC and your own MetaTrader 5 terminal. Broker and prop-firm rules differ, so check yours before automating.
The architecture in detail
This page explains where your data lives and how the connections work. If anything is unclear, contact us - we are happy to help.
How the password reaches the terminal
The app hands the password to the MetaTrader 5 terminal through a local connection on the same machine (127.0.0.1), protected by a one-time token per session. It never leaves the machine.
The device channel
The desktop app connects out to us over a TLS WebSocket with a bearer token. Our servers store only a SHA-256 hash of that token. A database leak does not expose a usable credential. Unpair the device from the web and the token is dead at once.
The strategy key
Each strategy has its own secret. It travels in the request body over TLS and is compared in constant time on the server. Rotate it any time. A strategy accepts 60 requests per minute, and a duplicate alert inside 60 seconds is ignored.
Your Hookmode sign-in
Sign-in to the web app is handled by Clerk. The web account can unpair devices, change rules and fire manual trades. Protect it like you protect your broker account.
Updates
The desktop app downloads updates over HTTPS from our storage and verifies a checksum before installing. The installer is not yet signed with a publisher certificate, so Windows SmartScreen warns on the first run.
Who is behind this
Hookmode is an independent product. No broker, prop firm, or signal provider owns it. For architecture questions, write to hello@hookmode.com.
Got questions?
Contact us at hello@hookmode.com.