Stealth TradeLocker Execution Automation

browser-fingerprint order routing without account flagging

Published: 2026-06-26  |  Project: BayesianPivot  |  Discipline: Distributed Systems & High-Throughput State

Author: Nicholas Alexander MacAskill — Founder & CTO, Flocano Labs  |  Canonical: https://www.nicholasmacaskill.com/dossier/bp-tradelocker-automation

auto_execution_threshold
9.0 / 10
Verified Invariant
supported_accounts
2 (deduped)
Verified Invariant
order_validity
IOC market
Verified Invariant
session_fingerprint
Chrome/macOS
Verified Invariant

Headless Prop-Firm Execution

TradeLocker prop firms expose no public execution API. BayesianPivot closes the loop with a headless execution automation (tl_client.py) that replays the same backend-api routes the web terminal uses — not a third-party SDK, but a stealth HTTP session that submits real orders after the 9-gate funnel clears.

Stealth Session Fingerprinting

Prop-firm WAFs flag non-browser traffic. Every request carries the same fingerprint as a human on the web UI:

PYTHONPRODUCTION RUNTIME
def _get_headers(self, auth=False):
    headers = {
        "User-Agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 ...",
        "Accept": "application/json, text/plain, */*",
        "Origin": self.base_url,
        "Referer": f"{self.base_url}/",
    }
    if auth and self.access_token:
        headers["Authorization"] = f"Bearer {self.access_token}"
    if self.acc_num:
        headers["accNum"] = str(self.acc_num)  # required by Upcomers-class servers
    return headers

Login hits /backend-api/auth/jwt/token, discovers accounts via all-accounts, and silently re-authenticates on 401 instead of hammering failed sessions.

Score-Gated Auto-Execution

The local scanner only fires live orders when LIVE_AUTO_EXECUTION is enabled and the setup scores ≥ 9.0. Everything below that stays Telegram-only — reducing trade frequency fingerprints and keeping human discretion on marginal setups.

PYTHONPRODUCTION RUNTIME
if Config.LIVE_AUTO_EXECUTION and live_score >= 9.0:
    trade_success = self.tl.execute_trade(
        symbol=symbol, side=exec_side, qty=lots,
        stop_loss=_sl, take_profit=_tp
    )

Orders post to /backend-api/trade/accounts/{id}/orders as IOC market fills with attached SL/TP — matching the web client's routeId and validity shape rather than a generic REST order schema.

Multi-Account Reconciliation

TradeLockerClient wraps Account A + B helpers, deduplicates seen_account_ids when aggregating equity, and normalizes Upcomers' proprietary list-format position responses alongside standard JSON objects. ordersHistory pairs BUY/SELL fills by position_id to reconstruct closed-trade PnL for the signed ledger audit loop.

SIGNAL_DETECTED:"system online // first dossier lesson logged"//TARGET:sovereign layer////////////////////////
Flocano Labs
ARCHITECTURELAYER
Memoirs
TASTELAYER
Nicholas Alexander MacAskill
IDENTITYLAYER
Biography
ABOUTFOUNDER