Public Isolated Experiment

Webhook Safety Lab: Valid JSON Is Only The First Check

A payload can be perfectly valid JSON, satisfy every required field and still describe an action that should not be executed. This lab separates those questions instead of hiding them behind one green checkmark.

Nothing submitted here reaches a trading account, broker, exchange or live execution route. The lab has no access to live trading state and cannot execute a trade.
Try It

Send one payload through three different questions

The same input is checked first as JSON, then as a contract, and finally as an instruction whose meaning may depend on state outside the payload itself.

Webhook payload Edit the example or paste your own JSON.
Execution permanently disabled

Syntax

Waiting

Can the request body actually be parsed as JSON?

  • No payload checked yet.

Schema

Waiting

Does the parsed object satisfy the contract expected by this demonstration?

  • No payload checked yet.

Semantic

Waiting

Can the payload alone prove that the requested action makes sense against current state?

  • No payload checked yet.

            
Three Different Questions

Why one word - “valid” - is not enough

Validation becomes ambiguous as soon as a message is allowed to change external state.

1

Syntax asks whether we can read it

Missing braces, broken quotes and malformed separators belong here. If parsing fails, there is no object to reason about yet. This is the easiest failure to detect and the one traditional JSON validators handle well.

2

Schema asks whether we recognize it

A request may be valid JSON while still missing required fields, carrying an unsupported action or using the wrong value type. Passing syntax therefore says almost nothing about whether the message satisfies an API contract.

3

Semantics asks whether it makes sense now

Some actions depend on facts the JSON cannot contain reliably: whether an object still exists, what state it is currently in, whether an identifier still points to the intended object and whether the requested operation has already happened.

Isolation By Design

The endpoint can reject a command. It cannot execute one.

This is deliberately not a trading simulator.

The public endpoint behind this page receives a payload and exposes the result of several validation layers. It does not look up a live account, query an open position, inspect an exchange order or pass the request into AlgoWay's execution layer.

That limitation is the point of the experiment. A semantic warning demonstrates where static validation runs out of information. In a real state-changing system, the next step would have to consult authoritative current state before deciding whether an action is still legitimate.

The lab therefore does not answer “is this trade safe?” It answers a narrower and more useful engineering question: “what can this payload prove by itself, and where must the system stop pretending that the payload knows everything?”