WMS DIGITAL | ONBOARDING + SIGNAL WORKFLOWS
The Future, Faster. | Workshop edition, 2 October 2026

WHAT YOU ARE COPYING
Four n8n workflows and the orchestration service they call. These are source
templates, not an account hosted for every workshop participant. Use your own
bot, private spreadsheet, Cloudflare account, Exness partner account and keys.
Never share the operator's private exports, reports or credentials.

1. Telegram onboarding: consent -> profile -> partner identity approval ->
   Exness attribution -> private status/activity -> community join request.
2. Private Exness connector: authenticated, allowlisted read operations.
3. Google Form/CRM sync: capture once, refresh private CRM every two minutes.
4. Live market demo: public Kraken candles -> completed-candle checks -> WMS
   formatting -> duplicate check -> Telegram community publication.

The AI is a background action selector. It interprets a question and proposes
one supported action; application code checks permissions and executes it.
Account reports and Exness credentials are never included in the AI prompt.
Commands remain available without a model key. This is not an unrestricted
agent that can create accounts, fund accounts, place trades or withdraw money.

REQUIREMENTS
Node.js 22.22+ (tests use node:sqlite), npm, Wrangler, Cloudflare Workers + D1,
n8n with Telegram Trigger 1.2, HTTP Request 4.2, Code 2, Google Sheets 4.6,
Schedule Trigger 1.2, and Webhook 2.1 nodes. Tested on n8n 2.41.5.
Telegram community: bot administrator with Invite Users and permission to post.
Google service account: access only to your private response spreadsheet.
Exness: an authorised partner login; a six-hour JWT is obtained for each read.

DEPLOY THE SERVICE
1. From this folder run npm install and npm test.
2. Copy wrangler.example.json to wrangler.json. Choose a unique Worker name.
3. Run npx wrangler login, then npx wrangler d1 create YOUR_DATABASE_NAME.
   Set database_name and the returned database_id in wrangler.json.
4. Run npx wrangler d1 migrations apply YOUR_DATABASE_NAME --remote.
5. Run npx wrangler deploy. Keep the returned HTTPS Worker URL.
6. Set each secret with npx wrangler secret put NAME. Paste values privately:
   TELEGRAM_TOKEN: BotFather token for your own bot.
   OPERATOR_ID: your numeric private Telegram user ID, verified using your bot.
   COMMUNITY_ID: numeric group/channel ID, verified through getChat.
   SERVICE_TOKEN: a new cryptographically random 32-byte-or-longer secret.
   CHALLENGE_SECRET: another independent random secret.
   EXNESS_PROXY_URL: your private n8n production webhook URL (below).
   Do not put these values in a workflow export or commit them to a repository.

PRIVATE EXNESS CONNECTOR
1. Import workflows/gateway.json into n8n.
2. Create an HTTP Header Auth credential: name Authorization, value
   Bearer followed by a space and your SERVICE_TOKEN. Select it on the webhook.
3. Create a Custom Auth credential for the Authenticate Exness node with JSON:
   {"body":{"login":"YOUR_PARTNER_EMAIL","password":"YOUR_PARTNER_PASSWORD"}}
   Enter real values only inside the private credential editor.
4. Publish/activate the workflow. Copy its production webhook URL into the
   service's EXNESS_PROXY_URL secret. Header authentication must remain on.
5. Execution-data saving is disabled in the supplied workflows. Keep it off
   for successful, failed and manual runs; authentication responses hold JWTs.

AI CONNECTION (OPTIONAL FOR COMMANDS, REQUIRED FOR NATURAL LANGUAGE)
Direct Meta (selected for WMS): set META_API_KEY as a Worker secret and set
AI_PROVIDER=meta, AI_MODEL=muse-spark-1.3-contributor in wrangler.json.
The adapter calls https://api.meta.ai/v1/chat/completions and requires a
complete JSON result matching the action schema. It never changes providers
silently when a key is absent or a request fails.
Contributor permits Meta to use prompts and completions for model improvement.
Clients receive a separate notice and must use /aiagree before ordinary text
is sent to this tier. /aistop withdraws that opt-in; commands keep working.
Emails, phone numbers and links are redacted, but this is not a guarantee of
anonymity. Exness reports and credentials are not included in model prompts.
The operator selected this model explicitly; /aistop also stops their AI route.

OpenRouter alternative: set OPENROUTER_API_KEY, AI_PROVIDER=openrouter and
AI_MODEL=meta/muse-spark-1.3-contributor. This adapter has mocked tests only;
the WMS deployment uses the direct Meta adapter.

Gemini: set GEMINI_API_KEY and vars AI_PROVIDER=gemini,
AI_MODEL=gemini-3.5-flash-lite in wrangler.json; redeploy.
GLM: use standard Z.ai API access with API credit; set ZAI_API_KEY,
AI_PROVIDER=zai and AI_MODEL=glm-5.3; redeploy.
The standard Z.ai endpoint is api.z.ai/api/paas/v4/chat/completions.
GLM Coding Plan quota does not cover calls from your own workflow/service
without a separate written agreement. Provider availability can change.
See the included model-rehearsal.json for the direct Meta live-routing checks.
Gemini and OpenRouter adapters have not been live-tested in this release.
After adding a key, test status, community, support, partner summary, an
unrecognised request, and a client trying to claim partner permissions.

TELEGRAM WORKFLOW
1. Import workflows/bot.json. Select your Telegram credential on its trigger.
2. Replace YOUR_ONBOARDING_WORKER.workers.dev with your deployed Worker URL.
3. Select the same Header Auth credential on the HTTP Request node.
4. Activate only ONE trigger workflow per bot token. Telegram has one webhook.
   Use the supplied Telegram Trigger, which validates Telegram's secret header.
5. Privately send /onboard, then I agree and the six requested answers.
   /start form looks up a synced form record by email; it never treats the
   claimed email as proof of ownership or reveals the captured details first.
6. Operator receives an identity review. Verify email ownership through your
   trusted client contact process. Then use /approve ID and /confirm ID.
   Do not approve fictional demo profiles or use an affiliation result as ID.
7. The service checks Exness attribution and shows only that client's report.
   It generates a 24-hour join-request invite. Join approval rechecks identity
   and attribution; another person cannot gain access by borrowing the link.
8. Public group usernames and other existing invitations can bypass this
   invite path. Configure the community's own admission settings if you want
   every entrant to be checked. The bot does not remove existing members.

COMMANDS
Everyone: /help /onboard /register /status /activity /community /learn
          /human /privacy /stop /cancel /demo /aiagree /aistop
Operator only: /summary /pipeline /client EMAIL /verify EMAIL /pending
               /approve REVIEW_ID /confirm REVIEW_ID
Reports are sent in private chats only. /demo is fictional. /stop stops
follow-up; it is not deletion. The operator handles deletion requests through
the stated contact process. No unsolicited marketing is enabled.

FORM AND PRIVATE CRM
1. Make your own Google Form and link it to a private response spreadsheet.
   Use these exact response headers in columns A:H of Form Responses 1:
   Timestamp; Name; WhatsApp number including country code; Email;
   Where did you hear about us?;
   What do you want to learn about trading, and why?;
   Your experience; Follow-up permission.
2. Create an Onboarding CRM tab with the headers in crm-headers.csv, row 1.
3. Import workflows/sync.json. Set YOUR_PRIVATE_RESPONSE_SHEET ID on BOTH
   Google Sheets nodes and select your Google service-account credential.
   Replace the Worker URL and select Header Auth on both service HTTP nodes.
4. Activate, then execute once. Verify a fictional form row is captured.
   The default range covers 499 submissions; expand it and batch the service
   calls (maximum 500 leads per call) before growing beyond that limit.
   CRM export is capped at the latest 500 bot profiles; extend with pagination
   before operating at larger scale. This is a bounded workshop implementation.
5. Keep the CRM private. RAW writes prevent values from becoming formulas.
6. Add https://t.me/YOUR_BOT?start=form to the form confirmation message,
   alongside the promised free guide. Allow two minutes for capture sync.
   The form itself triggers no outbound message. Telegram consent comes next.

LIVE MARKET DEMO (NO MARKET DATA KEY)
1. Import workflows/signals.json; set your Worker URL and Header Auth.
2. Execute manually. It publishes to the configured community when checks pass.
   A manual-only workflow does not need n8n activation/publication.
3. Inspect the actual Telegram post. It is labelled LIVE DATA AUTOMATION DEMO.
   It uses BTC/USD spot candles and 5/20-candle averages, not a trade order.
4. Repeating the same candle does not duplicate the post. An ambiguous send
   result is held for manual inspection rather than blindly resent.
5. No recurring demo broadcast is enabled. Add a Schedule Trigger only after
   choosing the audience and desired frequency.

REAL PROVIDER SIGNALS
Read SOURCES.txt before choosing a source. Public market data is not proof of
a trader's track record. Arrange provider access and redistribution permission.
For Telegram sources, their administrator adds your bot to the SOURCE channel;
being admin only in your destination group is not enough.
Set SIGNAL_SOURCE_ID, SIGNAL_SOURCE_NAME and SIGNAL_AUTO_PUBLISH=true as secrets.
The Telegram workflow receives channel_post and edited_channel_post updates.
The parser requires a stable source post, timestamp and explicit fields:
BUY MARKET BTC/USD
ENTRY: [source's numeric entry]
SL: [source's numeric stop]
TP1: [source's numeric target]
EXPIRES: [source's UTC ISO timestamp ending Z]
Missing fields are held, never invented. Source freshness, expiry, direction,
levels, live quote freshness, crossed targets/stops, and market drift are
checked. Price levels and source links survive formatting unchanged.
Only BTC/USD has an independent quote adapter in this edition. FX, metals,
and other symbols remain held until a suitable quote adapter is added and
tested. Kraken spot prices are not Exness execution prices. Source edits after
publication generate a review notice instead of guessed replacement levels.
Autochartist/Trading Central APIs are researched options, not implemented or
authenticated connectors in this pack. Their schema mapping and quote feed
must be implemented and rehearsed after access is obtained.

WHAT THE EXNESS REPORTS MEAN
See API-CAPABILITIES.txt. Deposit/balance/equity values in the client report
are bands, not exact amounts. Lot volume is not money spent. Partner rewards
are remuneration to the partner, not client profit. No full client withdrawal
ledger, fees or profit/loss is claimed from these endpoints.
Clients complete registration, Exness KYC, and any funding themselves at Exness.

REHEARSE BEFORE THE ROOM
Run npm test. Use fictional captures in a separate test chat. Check that an
unapproved chat cannot see a report and a group cannot run partner commands.
Test a real client path only with that client's authorisation and identity
review. Check /summary privately; keep client information off the projector.
Confirm the community invite path, source access, quote coverage and model key.
Download this pack and the canvas screenshot before hotel Wi-Fi is needed.

PRIVACY AND OPERATIONS
D1 stores profiles, verification decisions, events and duplicate markers.
The private sheet mirrors profile/status fields, not full financial reports.
Limit operator and spreadsheet access, establish retention/deletion procedures,
and monitor failures before broader use. The workshop does not include an
admin deletion UI, database backup schedule, or production-scale pagination.
Current state is refreshed on an explicit status/activity/community request
and at join approval; it does not continuously poll every client's account.

Rollback: deactivate the new Telegram workflow before restoring your previous
workflow. Restore its Telegram trigger only after the new one is inactive.
Do not run two Telegram webhook owners for one token.

CLIENT JOURNEY EXTENSION
The latest service also supports partner-only /journey demos: welcome, qualify,
onboarding, engage, return and stop. These use fictional records and fixed AI
briefs. /resolved TELEGRAM_ID clears a support hold after the partner resolves it.
The credential-protected /journey/queue, /journey/check and /journey/draft routes
prepare internal actions and drafts. They do not broadcast to customers.
Copy the five reusable workflows and setup guide at:
https://workshop.wms.africa/journey
