StopWarden

StopWarden is not open yet. Nothing here can be downloaded or bought today; these pages describe how StopWarden is planned to work when it opens. Get one email when it opens.

Quick start: your first Sim101 day

StopWarden is not open yet, so there is nothing to install today. This guide is the setup plan for when it opens. Do your first days on Sim101. Move to a real or prop account only after a clean Sim101 day (checklist at the end).

Commands in grey boxes go into PowerShell. Where it matters, each step says whether you need an Administrator window or a normal one.


Free: Scan + Watch

The free tier needs no key, and the scan needs no settings file. It is the same installer as the paid tiers.

  1. Run the installer (Step 3 below) and compile the AddOn once with F5 (Step 4).
  2. In NinjaTrader, open New > StopWarden, go to the Scan tab and press Scan now. The scan reads NinjaTrader's own log for the last 30 days, read-only, and never touches an order. Press Open report to read it. Hide account and strategy names is ticked by default, so the tab and the report show PropEval001, Strategy A and so on instead of your real account ids (safe on a screen share; Sim101-style names stay). Untick it and press Scan now again to see your own names. Without the window, the same scan runs from a normal PowerShell window: autopilot scan --open.
  3. The report lists every position with no stop order seen in NinjaTrader's log for longer than the wait, orphan orders, connection drops and restarts with a position open, and the stop timing of each strategy. It ends with the Unknowns: what it could not see. The fields are described in SCAN.
  4. Watch (alerts to your phone when a position has no working stop; it does not act) needs only the Telegram link: autopilot link-telegram (paste your bot token, then press Start in Telegram).

Everything below sets up the paid tiers (Protect: flatten, orphan cancel, relaunch and re-enable, end-of-day rules).


Step 1. Prerequisites

ItemHow to check or get it
NinjaTrader 8 Desktop, 8.1.xNinjaTrader: Help > About
Python 3.10 or newerThe installer checks this. If Python is missing, it prints the exact install command (winget install -e --id Python.Python.3.12). Tick "Add python.exe to PATH" if you use the python.org installer.
A live data connectionProtect will not enable your strategy while a configured connection is Simulated or Playback, even for Sim101 testing, and autopilot doctor reports it as a failure. Watch and the Safety Scan only read NinjaTrader's logs. Use your normal connection (for example My NinjaTrader) and trade the Sim101 account on it.
The Windows user that runs NinjaTraderDo everything below as that user. StopWarden runs in that user's desktop session.

Set the Windows clock to your exchange's timezone

All schedule times in StopWarden use this PC's clock. The simplest setup is to set Windows to the exchange's timezone (for CME futures, that is US Central Time): Settings > Time & language > Date & time > Time zone. If you keep a different timezone, convert every time in the config yourself.

Keep the desktop awake and unlocked

StopWarden clicks NinjaTrader's windows, and that only works on a signed-in, unlocked desktop.

  • Power settings: never sleep while plugged in.
  • Don't let the screen lock during trading hours.
  • On a VPS, a disconnected Remote Desktop session counts as "not interactive". Sign-in and enable clicks pause until you reconnect. See FAQ.

NinjaTrader settings (both are required)

  1. Tools > Options > Strategies > NinjaScript: tick Cancel entry orders when a strategy is disabled and Cancel exit orders when a strategy is disabled. Click OK. StopWarden will not enable anything without these two settings (HYGIENE_OFF).
  2. Tools > Options > Automated trading interface: tick AT Interface. Click OK. This lets StopWarden attempt to close a position through NinjaTrader's order-instruction files. Without it, StopWarden falls back to slower screen clicks.

Step 2. Add your strategy on Sim101 and save the workspace

In Protect, StopWarden enables and disables one existing row in the Control Center Strategies tab. It never creates or edits strategies.

  1. Control Center > Strategies tab > right-click > New Strategy...
  2. Pick your strategy. Set Account = Sim101, the instrument, and your parameters. Click OK. Leave it disabled for now. In Watch mode, which is where you start, StopWarden never enables or disables your strategy: you switch it on in NinjaTrader yourself. Protect, once it is on, enables the row at your enable time.
  3. Save the workspace (Control Center > Workspaces > Save Workspace) so the row is still there after a restart.
  4. Write down the strategy name exactly as the row shows it (the part before any /) and the account (Sim101). You need both in Step 5.

There must be exactly one row with that strategy name on that account. Two matching rows give AMBIGUOUS, and StopWarden won't click either.


Step 3. Run the installer (Administrator)

  1. Check the installer first. This software can close positions and types your NinjaTrader password, so make sure the files are exactly the ones we published. When StopWarden opens, each release will be published with a checksum that must match the file you got, character for character. If it doesn't, do not install: delete the file and contact support.
  2. Put the release files in a folder, for example C:\StopWarden. (First unblock the file you got in its Properties so Windows does not flag every file inside.)
  3. Right-click Windows PowerShell > Run as administrator. Go to that folder and run:
    
    powershell -NoProfile -ExecutionPolicy Bypass -File .\install\install.ps1
    
  4. When it asks "Copy the AddOn into NinjaTrader now? [y/N]", type y.

What the installer does:

  • Copies the program to C:\Program Files\StopWarden and adds that folder to the machine PATH.
  • Creates C:\ProgramData\StopWarden\ with autopilot.json (from the example), orderkill.json and a state\ folder. It lets your normal user write there.
  • Copies the orphan-order AddOn to <Documents>\NinjaTrader 8\bin\Custom\AddOns\StopWardenOrderGuard.cs.

Re-running the installer (to upgrade) keeps your autopilot.json, orderkill.json and state.

OptionUse
-DryRunShow every action and change nothing.
-YesDon't ask before copying the AddOn.
-SkipAddOnDon't touch the NinjaTrader folder.
-InstallDir <path>Install somewhere other than C:\Program Files\StopWarden.
-Nt8UserDir <path>Your NinjaTrader 8 folder, if it isn't <Documents>\NinjaTrader 8.
-RunAsUser DOMAIN\userThe Windows account that runs NinjaTrader, if it isn't the one signed in at the screen. Only this account (plus Administrators) can change StopWarden's settings; other users on the PC get read-only access.

If the installer stops, the exit code tells you why: 2 Python 3.10+ not found, 3 not run as Administrator, 4 not Windows, 1 other error (the message says which). See TROUBLESHOOTING.


Step 4. Compile the AddOn (once)

In NinjaTrader: New > NinjaScript Editor, then press F5. Wait for the compile to finish without errors.

You don't need to change orderkill.json. When StopWarden starts, it points the AddOn at exactly your configured account. It switches the AddOn on only when Protect can act (Protect mode, a paid licence and an accepted Learn report); in Watch mode (the default) it stays off.

The same F5 compiles the StopWarden window (New > StopWarden), which Steps 5 to 8 use.


Step 5. Open the StopWarden window and fill in Setup

In NinjaTrader's Control Center: New > StopWarden. The window has five tabs: Setup, Status, Activity, Controls and Scan. It never places, changes or cancels an order and never edits your settings file directly: every change goes through StopWarden's engine, which checks the whole file before it saves anything. If an orange banner says the engine is not installed, re-run the installer (Step 3).

On the Setup tab:

  1. Account: pick Sim101 from the list. It shows only the accounts NinjaTrader has connected right now (plus the one already saved), never accounts from earlier sessions. Empty list? Connect in NinjaTrader first, then press Reload.
  2. Connection: pick your live data connection (for example My NinjaTrader), exactly as in NinjaTrader's Connections menu.
  3. Strategy: pick the strategy you added in Step 2, or type its name exactly as the Strategies tab shows it.
  4. Enable at / End of day at: your times, 24-hour, on this PC's clock, on the same day (end of day must be later than the enable time). Any enable time works, including before 08:30: StopWarden opens and signs in to NinjaTrader shortly before it (the launch_at setting), and the line under the times says when, for example StopWarden starts NinjaTrader and signs in at 08:30, 15 minutes before the enable time. Leave At end of day, cancel working orders and close the position ticked.
  5. Press Save settings. You should see Saved. (if StopWarden is already running, it also tells you to press Pause, then Start on the Controls tab, to apply the change). If you see Not saved. Fix these first with a list, fix those and save again; nothing was written.
  6. Press Verify strategy row. You want Found the row. It is disabled right now. NOTFOUND or AMBIGUOUS means Step 2 needs fixing (add the row, or remove the duplicate), then save the workspace and press Verify again.
  7. Mode: leave it on Watch (alerts only). Use Protect stays greyed out, with the reason under it, until Protect can act for your setup (a paid licence and an accepted Learn report; see How do I turn Protect on?). Steps 9 and 10 describe Protect.

The window shows the settings it does not edit (cancel scope, the protection section) read-only. Sign-in method, trading days and holidays are set in the settings file: see Configuration.

Without the window (or if it does not open), edit the file in a normal (not Administrator) PowerShell window, opened after the installer finished so the new PATH is loaded:


notepad "C:\ProgramData\StopWarden\autopilot.json"

For a first Sim101 day, change at least these:


"connections": ["My NinjaTrader"],
"targets": [ { "strategy": "MyStrategy", "account": "Sim101", "instrument": "" } ],
"schedule": { "days": ["Mon","Tue","Wed","Thu","Fri"], "launch_at": "08:30", "enable_at": "08:45",
              "disable_at": "16:05", "flatten_on_disable": true, "holidays": [] },
"alerts": { "telegram": true, "discord": false, "heartbeat_hours": 0 }

Leave "mode": "watch" (the default). login.method is credential (default), google, or none; see FAQ.


Step 6. Phone alerts, licence and NinjaTrader login

Still on the Setup tab:

  1. Phone alerts (your own Telegram bot): paste the bot token you got from @BotFather and press Link phone. A https://t.me/... link appears; press Open the link and press Start in Telegram within 2 minutes. The window says Linked. A test message was sent to your phone. and the message arrives. The token goes to Windows Credential Manager, never into a file.
  2. Licence (paid plans only; leave it empty for the free Watch tier): paste the key from your receipt and press Activate. You should see Key accepted.

The window does not take your NinjaTrader password. Protect signs in to NinjaTrader for you only if you store it once, in a normal PowerShell window (skip this if login.method is google or none):


autopilot store-secret nt8         # asks for your NinjaTrader username, then the password twice

Without the window: autopilot link-telegram (paste the token, then press Start in Telegram), or autopilot store-secret telegram / autopilot store-secret discord for a chat id and token or a webhook, then autopilot test-alert. Licence: autopilot license activate.


Step 7. Run the doctor until there is no FAIL

On the Controls tab press Run doctor. It shows one row per check (PASS, WARN or FAIL) and a summary. Fix every FAIL and run it again. Each FAIL row says how to fix it, and TROUBLESHOOTING explains each one.

These WARNs are normal on a first run:

CheckWhy it warns nowGoes away when
Order-guard configorderkill.json is still switched offProtect can act (Step 8 onwards, after the Learn report is accepted). In Watch mode (the default) this WARN is expected and stays.
Scheduled task (two lines)The tasks aren't registered yetYou press Start (Step 8). If Windows refused the sign-in task, the Supervisor line passes with sign-in entry (HKCU Run) instead; the Keepalive line may stay WARN
NT8 newest logNinjaTrader hasn't run in the last hourNinjaTrader is running
Learn reportNo report yet, or not completeYour strategy has traded enough in Watch (20 round trips over 5 sessions by default)

Protect gate reads Watch: alerts only, never flattens (mode=watch): that is the default, and correct. Read the Clock / timezone row yourself. It always says PASS, but it shows the time and timezone StopWarden will use.

Without the window: autopilot doctor, and with NinjaTrader open and signed in, autopilot doctor --ui (its Strategy row check must say ON or OFF).


Step 8. Start StopWarden

On the Controls tab press Start. It does not need administrator rights. It starts the engine first, then registers two tasks for your Windows user only, running in your desktop session without elevation:

  • StopWarden Supervisor: starts StopWarden when you sign in to Windows.
  • StopWarden Keepalive: every 5 minutes, starts it again if it isn't running.

The message says, in plain words, that StopWarden is running and how it will start at the next sign-in:

  • It starts again at every Windows sign-in (a scheduled task for your Windows user). The normal case.
  • ... (a sign-in entry for your Windows user ...): Windows refused the scheduled task for your account, so StopWarden added itself to your own sign-in list (HKCU\Software\Microsoft\Windows\CurrentVersion\Run, value StopWarden). It still starts at sign-in and still respects Pause.
  • It will NOT start by itself at the next Windows sign-in ...: both were refused (the reason is quoted). StopWarden is running now; press Start after each sign-in and send a diagnostics zip to support.
  • The last line says whether the 5-minute restart check exists. If not, press Start again if the Status tab ever shows Engine NOT running.

Within a minute the Status tab shows its four lights (watchdog, order guard, connection, strategy), text starting Engine running, and NinjaTrader's own position for the account (Account Sim101: flat). In Watch mode the order guard light stays grey (compiled, not switched on). The Activity tab lists what StopWarden saw and did, newest first.

Pause on the Controls tab stops StopWarden (the watchdog too) until you press Start again; the Status tab shows Engine paused (Pause was pressed). The watchdog is OFF until you press Start. within a couple of seconds. KILL SWITCH asks first, then disables the strategy (see Safety); Resume clears it.

Without the window, in the normal PowerShell window, as the user who runs NinjaTrader:


autopilot install-tasks
autopilot ensure-running
autopilot status

status should show a supervisor_pid, a watchdog_pid and a small watchdog_heartbeat_age_s (a few seconds). install-tasks ends with AUTOSTART=task|registry|none, KEEPALIVE=task|none and RESULT=OK|NONE; install-tasks --print-only shows the exact Task Scheduler XML without registering anything. Run the doctor once more. The Scheduled task rows should now say PASS.


Step 9. What a normal day looks like

This table is Protect mode, once Protect can act (see How do I turn Protect on?). In Watch mode (the default) you get the alerts, but StopWarden doesn't launch, enable, disable, cancel or flatten; its alerts say what Protect would have done.

Times are the defaults. Every alert starts with [StopWarden <your PC name>] <LEVEL>. Identical alerts are sent at most once per 10 minutes.

TimeWhat happensAlert you get
Windows sign-inSupervisor and watchdog start. The order guard is pointed at your account.INFO Autopilot supervisor started.
08:30 launch_atNinjaTrader starts, signs in, connects.None, unless something fails
When NinjaTrader loads the AddOnOrder guard reports in.INFO Order guard: Orphan-order guard loaded -- enabled=True account_regex='^Sim101$' ...
08:45 enable_atChecks: flat, no kill switch, watchdog running, cancel-on-disable on. Then it clicks enable and waits 75 s to confirm from the log.INFO MyStrategy ENABLED on Sim101 (ENABLED).
During the sessionEvery 5 min it re-checks the strategy row. Every 10 min it closes known harmless pop-ups (rollover notice, order-reject boxes). The watchdog checks the log every second.Only when something happens (see below)
Every N hours (if heartbeat_hours > 0)Status pingINFO alive: phase TRADE, MyStrategy ON, Sim101 position +0.
16:05 disable_atDisables the strategy, closes any position on your account, cancels the working orders it has seen on your account, checks flat from the log.INFO End of day: MyStrategy DISABLED ... All configured accounts flat. Attempts today: 0.
OvernightNinjaTrader stays open. The watchdog and order guard keep watching the account.None, unless something happens

Alerts that mean "look at this":

AlertMeaning
WARN ... failed (...) -- retrying (n/6 today).A recovery step failed. It will retry.
WARN NT8 is DEAD during the session: relaunching / signing in.NinjaTrader died or logged out mid-session.
WARN MyStrategy dropped to OFF during the session: re-enabling.The strategy was disabled mid-session.
WARN Windows desktop is LOCKED ...Clicks are paused until you unlock.
CRITICAL Naked position flattened via OIF. ...The watchdog closed an unprotected position.
CRITICAL Order guard: ...The AddOn cancelled orphan orders (or couldn't).
CRITICAL BLOCKED for today ... / CRITICAL Recovery CAP hit ...StopWarden stopped trying for today. It tells you what to fix.
CRITICAL END OF DAY PROBLEM: ... / CRITICAL END OF DAY: NT8 is NOT running ...Check your broker now for open positions and working orders.

What each one means and what to do: Troubleshooting.


Step 10. Test the watchdog safely on Sim101

Do this only on Sim101, in Protect mode with its Learn report accepted (in Watch mode, or before acceptance, the watchdog only alerts: you get the alert and nothing is closed), during your trading window, with StopWarden running and the strategy enabled on Sim101. (While the strategy is enabled, the order guard treats the account as managed and leaves your manual orders alone.)

  1. Run autopilot status and check that watchdog_heartbeat_age_s is a few seconds.
  2. Wait until the strategy is in a Sim101 position with its stop working. Or place a manual 1-contract Sim101 order with a stop, on the same instrument.
  3. In NinjaTrader's Orders tab, cancel the stop order by hand.
  4. Don't touch anything. After the wait, plus the time NinjaTrader takes to close the position, you should see:
  • the Sim101 position go flat in the Positions tab;
  • an alert like CRITICAL Naked position flattened via OIF. Sim101: position +1 <instrument>, stop coverage 0, naked for >= the wait. If the strategy puts a new stop in place first, the watchdog correctly does nothing. That is the strategy's own protection working.
  1. OIF means it closed through the Automated Trading Interface. UIA means it had to use the screen-click fallback: check that AT Interface is on (Step 1).

You can also test the kill switch on Sim101:


autopilot stop --reason "sim test"
autopilot resume

stop disables the strategy. In Protect mode with flatten_on_disable: true it also closes the Sim101 position and cancels the working orders it has seen on Sim101. In Watch mode it only disables; autopilot stop --flatten asks for the close and cancel too. If a position is open and the stop would not close it, stop refuses and changes nothing (disabling would cancel the strategy's stop): add --flatten, or --leave-open to manage it by hand. With the default cancel_scope: "account", other accounts in NinjaTrader are not touched. Check the Orders tab afterwards: an order StopWarden never saw in the log is not cancelled by this path. See Safety.


Step 11. Moving to a real or prop account

Change accounts only after at least one clean Sim101 day: enabled on time, no unexplained alerts, EOD said "All configured accounts flat".

Checklist:

  • [ ] Your prop firm allows automated strategies, third-party tools and (if you use one) a VPS. Read its current rules.
  • [ ] Your strategy has its own stop loss on every entry. The watchdog is a backstop, not your stop.
  • [ ] You have set broker-side or firm-side daily loss limits where available (Safety).
  • [ ] The strategy row exists on the real account in the Strategies tab, and the workspace is saved.
  • [ ] You won't trade this account by hand while StopWarden runs in Protect mode. The watchdog attempts to flatten unprotected positions and the order guard cancels orders when no strategy is running, at any time of day.
  • [ ] cancel_scope left at "account" (the default) if other accounts in this NinjaTrader have working orders you want to keep. "global" sends NinjaTrader's cancel-all, which hits every account (Safety).
  • [ ] You chose the mode on purpose: "watch" (the default: alerts only) or "protect" (acts on the account, needs an active licence and a Learn report accepted for this account: an acceptance for Sim101 does not carry over). Watch at least one real session before you switch Protect on.
  • [ ] targets[0].account changed from Sim101 to your account, for example "YOUR-PROP-ACCOUNT", typed exactly as NinjaTrader shows it.
  • [ ] schedule times checked against the PC clock. Market holidays added to holidays.
  • [ ] Optional: balance_floor set a little above your firm's liquidation level.
  • [ ] autopilot doctor and autopilot doctor --ui: no FAIL.
  • [ ] autopilot resume if you stopped anything while testing. doctor shows Kill switch: not set.
  • [ ] Watch the first live enable and the first end of day yourself.

StopWarden rewrites the order-guard config (orderkill.json) for the new account the next time it starts. To restart it after changing accounts: autopilot shutdown, then autopilot start.