Stealth TradeLocker Execution Automation
browser-fingerprint order routing without account flagging
Published: 2026-06-26 | Project: BayesianPivot | Discipline: Distributed Systems & High-Throughput State
Author: Nicholas Alexander MacAskill — Founder & CTO, Flocano Labs | Canonical: https://www.nicholasmacaskill.com/dossier/bp-tradelocker-automation
Headless Prop-Firm Execution
TradeLocker prop firms expose no public execution API. BayesianPivot closes the loop with a headless execution automation (tl_client.py) that replays the same backend-api routes the web terminal uses — not a third-party SDK, but a stealth HTTP session that submits real orders after the 9-gate funnel clears.
Stealth Session Fingerprinting
Prop-firm WAFs flag non-browser traffic. Every request carries the same fingerprint as a human on the web UI:
def _get_headers(self, auth=False):
headers = {
"User-Agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 ...",
"Accept": "application/json, text/plain, */*",
"Origin": self.base_url,
"Referer": f"{self.base_url}/",
}
if auth and self.access_token:
headers["Authorization"] = f"Bearer {self.access_token}"
if self.acc_num:
headers["accNum"] = str(self.acc_num) # required by Upcomers-class servers
return headersLogin hits /backend-api/auth/jwt/token, discovers accounts via all-accounts, and silently re-authenticates on 401 instead of hammering failed sessions.
Score-Gated Auto-Execution
The local scanner only fires live orders when LIVE_AUTO_EXECUTION is enabled and the setup scores ≥ 9.0. Everything below that stays Telegram-only — reducing trade frequency fingerprints and keeping human discretion on marginal setups.
if Config.LIVE_AUTO_EXECUTION and live_score >= 9.0:
trade_success = self.tl.execute_trade(
symbol=symbol, side=exec_side, qty=lots,
stop_loss=_sl, take_profit=_tp
)Orders post to /backend-api/trade/accounts/{id}/orders as IOC market fills with attached SL/TP — matching the web client's routeId and validity shape rather than a generic REST order schema.
Multi-Account Reconciliation
TradeLockerClient wraps Account A + B helpers, deduplicates seen_account_ids when aggregating equity, and normalizes Upcomers' proprietary list-format position responses alongside standard JSON objects. ordersHistory pairs BUY/SELL fills by position_id to reconstruct closed-trade PnL for the signed ledger audit loop.