STACK

Architecture

Public product is a signal bus. Maximus stays on the box. Subscribers keep Tradovate credentials.

Runtime

Desk brain
Maximus. It scores the rail and sends one signal.
This app
TanStack Start, Postgres, Better Auth (Google / X). Neon when deployed.
Ingest
POST /api/v1/ingest with Bearer ing_… from Maximus. One JSON fire.
Fanout
HTTPS POST to each subscriber webhook, or they poll GET /api/v1/signals.
Fill
Their script / CrossTrade / Tradovate API. isAutomated: true. Not us.

What we will not build here

Storing subscriber OAuth refresh tokens and calling Tradovate placeorder from these servers. That is copy-trading. Different legal box. This license stops at the JSON.

Maximus curl (box)

curl -sS -X POST "$FUND_URL/api/v1/ingest" \
  -H "Authorization: Bearer $INGEST_KEY" \
  -H "Content-Type: application/json" \
  -d '{"side":"Sell","symbol":"MNQZ6","qty":5,"stop":20,"tp":40,"be":20,"poi":"H4H@29680"}'

Subscriber receiver

# webhook: POST body is maximus_signal
# then YOUR place_struct40 / Tradovate session
# we never see that key