Agent skill

Alpaca Broker Integration

by alpacahq in alpacahq/alpaca-skills

Entry point for integrating with the Alpaca Broker API (plus Market Data and Trading APIs) in any programming language.

Apache-2.0Auto-check passedBusiness, Finance & HR

Install Alpaca Broker Integration

skills CLI
$ npx skills add alpacahq/alpaca-skills --skill alpaca-broker-integration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alpacahq/alpaca-skills alpaca-broker-integration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alpacahq/alpaca-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/broker-api/integration .claude/skills/alpaca-broker-integration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
alpaca-broker-integration
GitHub stars
154
Token cost
~3k tokens
SKILL.md length
1,369 words
Files
2
Skills in repo
14
Repo updated
First seen
Licence
Apache-2.0

At a glance

Entry point for integrating with the Alpaca Broker API (plus Market Data and Trading APIs) in any programming language.

  • Works in 8 steps: The four API families → Base URLs → Authentication → …
  • A developer wants to build on Alpaca — open brokerage accounts
  • SKILL.md covers Reference Documentation, 1. The four API families, 2. Base URLs and 3. Authentication, plus 5 more sections
  • Reaches docs.alpaca.markets and broker-api.alpaca.markets; needs API_KEY_ID and API_SECRET_KEY

What it does

Alpaca Broker Integration is an agent skill from alpacahq/alpaca-skills. Entry point for integrating with the Alpaca Broker API (plus Market Data and Trading APIs) in any programming language. Use when a developer wants to build on Alpaca — open brokerage accounts, run KYC, fund accounts, move money via journals, place orders, consume real-time event streams, or pull market data — and need to know base URLs, auth, conventions, or which focused sub-skill to use.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `reference.md`).

It sits in Business, Finance & HR, covering Stock and market analysis and Trading and backtesting. The repository describes itself as: Agent skills for Alpaca's Trading API and Broker API: drop-in SKILL.md files for AI coding assistants. The licence is Apache-2.0.

When your agent uses it

  • A developer wants to build on Alpaca — open brokerage accounts
  • Move money via journals
  • Consume real-time event streams
  • Pull market data — and need to know base URLs

Example prompts

  • “/alpaca-broker-integration”

Requirements

  • A credential in API_SECRET_KEY

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. The four API families
  2. Base URLs
  3. Authentication
  4. Three consumption styles
  5. Wire conventions (true across the platform)
  6. Sandbox-first workflow
  7. Skill map — where to go next
  8. Integration guidance (applies regardless of language)

What it can do on your machine

Read from SKILL.md and the folder at commit 39111ab. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • docs.alpaca.markets
    • broker-api.alpaca.markets
    • broker-api.sandbox.alpaca.markets
    • api.alpaca.markets
    • paper-api.alpaca.markets
    • data.alpaca.markets

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY_ID
    • API_SECRET_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Alpaca Broker Integration loads about 3k tokens when it runs. Until then it costs about 105 tokens; SKILL.md has 1,369 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~105
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alpacahq/alpaca-skills at commit 39111ab, republished under its Apache-2.0 licence (© alpacahq). 1,369 words, ~3,008 tokens.

Download SKILL.mdSave it as .claude/skills/alpaca-broker-integration/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
alpaca-broker-integration
description
Entry point for integrating with the Alpaca Broker API (plus Market Data and Trading APIs) in any programming language. Use when a developer wants to build on Alpaca — open brokerage accounts, run KYC, fund accounts, move money via journals, place orders, consume real-time event streams, or pull market data — and need to know base URLs, auth, conventions, or which focused sub-skill to use.

Alpaca Integration Assistant

You are an expert on the Alpaca APIs. Help developers integrate with Alpaca in any programming language. Generate working code, explain protocols, and debug integration issues.

This is the router / overview skill. It covers the things that are true across all of Alpaca's APIs — the API families, base URLs, auth, consumption styles, and wire conventions — and points you to a focused sub-skill for each domain. Read this first, then jump to the specific skill for the task.

Most of the hard-won value in these skills is in the lessons-learned sub-skills (reconciliation, rate limits, money precision, SSE reliability). Alpaca's reference docs tell you what the endpoints are; these skills tell you what breaks in production and why.


Reference Documentation

  • Docs home: https://docs.alpaca.markets/
  • API reference: https://docs.alpaca.markets/reference/
  • Machine-readable index: https://docs.alpaca.markets/llms.txt and https://docs.alpaca.markets/llms-full.txt
  • OpenAPI specs (4): Authentication API, Broker API, Market Data API, Trading API

Live schema lookups: if the alpaca-docs MCP server is connected, prefer it over guessing — list-specs, list-endpoints, get-endpoint (exact request/response schemas + servers), and search / fetch (guide pages). Always confirm an exact payload against the spec before generating code that posts money or orders.


1. The four API families

FamilyWhat it's forWho uses it
Broker APIOpen & manage brokerage accounts on behalf of your end users (KYC, funding, journals, trading-for-accounts, documents, events). You are the broker-of-record's tech partner; you custody many sub-accounts under your firm.Apps that onboard their own users and hold their assets (neobrokers, fintechs).
Trading APITrade a single account that belongs to the API-key holder.Individual algo traders, bots.
Market Data APIReal-time + historical prices, bars, quotes, trades, news, corporate actions, screener. REST and WebSocket.Everyone.
Authentication APIOAuth 2.0 flows for letting third parties act on an Alpaca account.OAuth integrations.

Decide first which family you're on — it changes the base URL, the auth, and the URL shape of every call. The most common confusion: Broker API places orders at /v1/trading/accounts/{account_id}/orders (the account is in the path because you act for a user), whereas the standalone Trading API places orders at /v2/orders (implicitly your own account).

These skills focus primarily on the Broker API, because that's where the lifecycle is hardest: onboarding, funding rails, journals, and event reconciliation.


2. Base URLs

FamilyProductionSandbox / Paper
Broker APIhttps://broker-api.alpaca.marketshttps://broker-api.sandbox.alpaca.markets
Trading APIhttps://api.alpaca.marketshttps://paper-api.alpaca.markets (paper)
Market Data (REST)https://data.alpaca.markets(same host; sandbox data is limited)
Market Data (WebSocket)wss://stream.data.alpaca.marketswss://stream.data.sandbox.alpaca.markets

Always start in sandbox. Switch by environment variable, never by code path — a single ENV flag that selects the base URL is the pattern that survives. Sandbox accounts can be funded with fake money and auto-approved, so you can exercise the full lifecycle without real KYC or cash.


3. Authentication

Auth differs by API family — this trips people up constantly.

Broker API → HTTP Basic
Authorization: Basic base64("<API_KEY_ID>:<API_SECRET_KEY>")

The same Basic credential authenticates Broker REST, Broker SSE event streams, and trading-on-behalf-of-accounts. Build the base64 token once at startup; don't recompute per request.

Market Data API → key/secret headers (or Basic in broker context)
APCA-API-KEY-ID: <API_KEY_ID>
APCA-API-SECRET-KEY: <API_SECRET_KEY>

For the WebSocket data stream, you don't use headers — you send an auth message after connecting:

json
{"action": "auth", "key": "<API_KEY_ID>", "secret": "<API_SECRET_KEY>"}

Broker API partners can usually authenticate market-data calls with their Broker Basic credentials too. Pick one scheme per data client and be consistent; mixing them is a frequent source of 401s.

Trading API → key/secret headers

Same APCA-API-* headers as market data.

Authentication API → OAuth 2.0 Bearer

For OAuth integrations, exchange the code for a token and send Authorization: Bearer <token>.


4. Three consumption styles

Alpaca gives you three transports. Use the right one for the job — and know that they have different auth and different reliability characteristics.

StyleTransportUse forSkill
RESTHTTPS request/responseEverything transactional: create account, fund, journal, place order, query state.the domain skills
SSEtext/event-stream over a long-lived HTTPS GETBroker lifecycle events: account status, journals, transfers, trades, non-trade activities. Replayable via cursors.alpaca-broker-sse-events
WebSocketwss://Real-time market data (trades/quotes/bars).alpaca-broker-market-data

Key distinction: Broker events come over SSE (simple HTTP, Basic auth, replayable with since/since_id). Market data comes over WebSocket (subscribe model, auth message, ping/pong). They are different endpoints with different auth — don't conflate them.


5. Wire conventions (true across the platform)

These apply everywhere and are the source of most subtle bugs:

  • Numbers are strings. Prices, quantities, notional, and money amounts come back as JSON strings ("100.50", "1.5"). Parse into a decimal type, never a binary float. See alpaca-broker-money-precision.
  • IDs: account_id, order_id, journal_id, transfer_id are UUIDs. Activity IDs and newer event IDs are ULIDs — lexicographically sortable, which matters for event ordering and replay cursors.
  • Idempotency: pass your own client_order_id on orders so retries don't double-fill. Records you create from events should be keyed on the Alpaca ID with upsert/skip-duplicate semantics. See alpaca-broker-reconciliation-idempotency.
  • Pagination: list endpoints page forward with a token. Market-data bars return next_page_token in the body; activities return a page token via the X-Next-Page-Token response header. Loop until the token is empty.
  • Rate limits: responses carry X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset (unix seconds). On HTTP 429, wait until reset before retrying. See alpaca-broker-rate-limits-resilience.
  • Timestamps: RFC3339 (e.g. 2026-01-02T15:04:05Z). SSE since/until accept RFC3339, but + in a timezone offset must be URL-encoded as %2B.
  • Status ≠ done. Almost every write (account, journal, transfer, order) is asynchronous and moves through a state machine. A 200 means "accepted," not "settled." Always reconcile on the terminal status, which arrives later via event or poll.

Show full SKILL.md (484 more words)Show less

6. Sandbox-first workflow

When helping someone start from zero, walk them through this order:

  1. Pick sandbox URLs via an ENV switch.
  2. Authenticate with Basic (Broker) — verify with GET /v1/accounts (list).
  3. Create an account with full KYC payload → alpaca-broker-account-onboarding.
  4. Wait for ACTIVE status (via SSE account-status events or polling) before any money/trade op.
  5. Fund it (sandbox lets you simulate deposits) → alpaca-broker-funding-transfers.
  6. Move cash where it's needed with journals → alpaca-broker-journals.
  7. Place an order → alpaca-broker-trading-orders.
  8. Subscribe to events to track fills/transfers in real time → alpaca-broker-sse-events.
  9. Add a reconciliation pass before going live → alpaca-broker-reconciliation-idempotency.

7. Skill map — where to go next

If the task is about…Use skill
Creating accounts, KYC, CIP, document upload, agreements, account status, W-8BENalpaca-broker-account-onboarding
ACH / wire / funding-wallet rails, deposits, withdrawals, transfer status, the omnibus/float-account modelalpaca-broker-funding-transfers
Moving cash (JNLC) or shares (JNLS) between accounts, batch & reverse-batch, journal lifecyclealpaca-broker-journals
Placing/canceling orders, qty vs notional, fractional shares, order lifecycle, positions, recurring buysalpaca-broker-trading-orders
Snapshots, bars, quotes, assets, news, market clock/calendar, feeds (IEX/SIP), WebSocket price streamsalpaca-broker-market-data
Consuming Broker SSE event streams reliably (reconnect, heartbeats, replay cursors)alpaca-broker-sse-events
Keeping local state correct: missed-event recovery, polling rails without webhooks, idempotency, status guardsalpaca-broker-reconciliation-idempotency
Backoff, 429 handling, rate-limit headers, concurrency limits, batch sizingalpaca-broker-rate-limits-resilience
Handling money correctly: decimals vs floats, numbers-as-strings, truncation/roundingalpaca-broker-money-precision

8. Integration guidance (applies regardless of language)

  1. One base-URL switch, environment-driven. Never hardcode prod URLs in a code branch.
  2. Build auth once. Cache the Basic token / header set at client construction.
  3. Treat every write as async. Model the state machine; act on terminal states, not on the 2xx.
  4. Persist Alpaca's IDs. Store account_id, order_id, journal_id, transfer_id on your local records — they are your only correlation key for events and reconciliation.
  5. Decimals, not floats, for anything monetary. Parse the string fields into a decimal type.
  6. Reconcile, don't trust the stream. SSE can drop events; design a polling/heal pass that re-syncs from Alpaca as source of truth (alpaca-broker-reconciliation-idempotency).
  7. Respect rate limits proactively. Watch X-RateLimit-Remaining, back off before you get throttled.
  8. Use client_order_id and Alpaca-ID-keyed upserts so retries and duplicate events are safe.
Language notes (transport only — Alpaca is HTTP/SSE/WS, so any stack works)
  • Python: httpx/requests (REST), httpx/aiohttp or an SSE client for events, websockets for data, decimal.Decimal for money.
  • TypeScript/Node: fetch (REST), an EventSource implementation for SSE (pass the Authorization header), ws for WebSocket, decimal-as-string or decimal.js.
  • Go: net/http (REST + SSE via a streaming bufio.Scanner), gorilla/websocket for data; be deliberate about money types (shopspring/decimal if precision matters).
  • Any language: SSE is just a long-lived HTTP GET that yields text/event-stream; if no SSE client exists, read the response body line-by-line and parse data: frames.

Alpaca also publishes official SDKs (alpaca-py, @alpacahq/alpaca-trade-api / typescript-sdk, Go community SDKs). Offer them when the user wants speed, but these skills teach the wire protocol so the knowledge transfers to any language or a custom client.

© alpacahq, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/broker-api/integration of alpacahq/alpaca-skills.

  • SKILL.md
  • reference.md

Open the folder on GitHubat commit 39111ab

Compare with similar skills

Alpaca Broker Integration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Alpaca Broker Integration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Alpaca Broker Integration this skillalpacahq/alpaca-skills154—~3kAutomated safety check: PassApache-2.0
Miniqmt CLIoopslink/trading-skills176—~8.2kAutomated safety check: PassMIT
Metamask Agent Walletnirholas/three.ws230—~4.5kAutomated safety check: PassMIT
Tushare Datazillionare/zillionare3222 repos~2.3kAutomated safety check: PassNone
Tradingview MCPatilaahmettaner/tradingview-mcp5k—~1.3kAutomated safety check: PassMIT
Digital Oraclekomako-workshop/digital-oracle878—~5.9kAutomated safety check: PassMIT

Similar skills

  • Miniqmt CLI

    oopslink/trading-skills

    Operate miniQMT/xtquant via the miniqmt-cli tool -- market data queries, real-time streaming, account management, order placement with safety guards, daemon health checks, SSH tunnel management, and…

    176 GitHub stars~8.2k tokensUpdated 4 mo ago
    Business, Finance & HRAuto-check passed
  • Metamask Agent Wallet

    nirholas/three.ws

    A skill your agent uses when the user asks anything about blockchain wallets, transactions, signing, token transfers, supported chains, wallet balances, perpetual futures trading, prediction…

    230 GitHub stars~4.5k tokensUpdated today
    Business, Finance & HRAuto-check passed
  • Tushare Data

    zillionare/zillionare

    面向中文自然语言的 Tushare 数据研究技能。用于把“看看这只股票最近怎么样”“帮我查财报趋势”“最近哪个板块最强”“北向资金在买什么”“给我导出一份行情数据”这类请求,转成可执行的数据获取、清洗、对比、筛选、导出与简要分析流程。适用于 A 股、指数、ETF/基金、财务、估值、资金流、公告新闻、板块概念与宏观数据等研究场景。

    322 GitHub starsUsed in 2 repos~2.3k tokens
    Business, Finance & HRAuto-check passed
  • Tradingview MCP

    atilaahmettaner/tradingview-mcp

    AI Trading Intelligence — live prices, 30+ technical indicators, backtesting (6 strategies), walk-forward overfitting detection, trade logs, equity curves, licensed news sentiment (Marketaux), and…

    5k GitHub stars~1.3k tokensUpdated yesterday
    Business, Finance & HRAuto-check passed
  • Digital Oracle

    komako-workshop/digital-oracle

    Answer prediction questions using market trading data, not opinions.

    878 GitHub stars~5.9k tokensUpdated 2 mo ago
    Business, Finance & HRAuto-check passed
  • Worth Buy Stocks

    starriv/worth-buy-stocks

    Evaluate US stocks under an Alpaca trend and relative-strength framework, and prioritize defined-risk net-credit income spreads: Bull Put/Bear Call first, Iron Condor second.

    175 GitHub stars~4.5k tokensUpdated 8 days ago
    Business, Finance & HRAuto-check: notes

More from alpacahq/alpaca-skills

All 14 skills in this repo
  • Alpaca Broker Account Onboarding

    alpacahq/alpaca-skills

    Open and manage brokerage accounts via the Alpaca Broker API — account creation, KYC/CIP, identity & disclosures, agreements, document upload (incl.

    154 GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Alpaca Broker Funding Transfers

    alpacahq/alpaca-skills

    Move money between an Alpaca brokerage account and the EXTERNAL banking world via the Broker API — ACH relationships, wire recipient banks, classic transfers (deposits/withdrawals), the v1beta…

    154 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Alpaca Broker Journals

    alpacahq/alpaca-skills

    Move cash (JNLC) and securities (JNLS) BETWEEN accounts inside your own Alpaca omnibus via the Broker API — single, batch, and reverse-batch journals, the Idempotency-Key header, journal status…

    154 GitHub stars~2.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Alpaca Broker Money Precision

    alpacahq/alpaca-skills

    Handle money and numeric precision correctly with the Alpaca API — numbers-as-strings on the wire, decimals vs floats, rounding/truncation before sending amounts, fractional-share precision, and…

    154 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Make Alpaca API clients resilient — rate-limit header handling, HTTP 429 backoff, exponential retry, bounded concurrency/worker pools, pagination loops, batch sizing, and timeouts.

    154 GitHub stars~1.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Keep local state correct against the Alpaca Broker API — idempotency keys, ID-keyed upserts, event snapshotting and dedup, polling rails that have no events, nightly reconciliation/heal jobs, status…

    154 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Alpaca Broker Integration

What does Alpaca Broker Integration do?

Entry point for integrating with the Alpaca Broker API (plus Market Data and Trading APIs) in any programming language. Alpaca Broker Integration is an agent skill from alpacahq/alpaca-skills. Entry point for integrating with the Alpaca Broker API (plus Market Data and Trading APIs) in any programming language.

When should I use Alpaca Broker Integration?

Alpaca Broker Integration fits situations like: A developer wants to build on Alpaca — open brokerage accounts; move money via journals; consume real-time event streams; pull market data — and need to know base URLs.

How do I install Alpaca Broker Integration in Claude Code?

Run `npx skills add alpacahq/alpaca-skills --skill alpaca-broker-integration -a claude-code`. Or copy the skill folder (skills/broker-api/integration in alpacahq/alpaca-skills) into .claude/skills/alpaca-broker-integration in your project. Claude Code loads it when a task matches its description.

How do I install Alpaca Broker Integration in Codex?

Run `npx skills add alpacahq/alpaca-skills --skill alpaca-broker-integration -a codex`. Or copy the skill folder (skills/broker-api/integration in alpacahq/alpaca-skills) into .agents/skills/alpaca-broker-integration in your project. Codex loads it when a task matches its description.

Can I use Alpaca Broker Integration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alpacahq/alpaca-skills --skill alpaca-broker-integration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/alpaca-broker-integration, .gemini/skills/alpaca-broker-integration, .github/skills/alpaca-broker-integration and .opencode/skills/alpaca-broker-integration in your project.

What does Alpaca Broker Integration need to run?

Going by SKILL.md and its folder, Alpaca Broker Integration needs credentials named API_KEY_ID and API_SECRET_KEY. Our summary lists: A credential in API_SECRET_KEY.

Does Alpaca Broker Integration access the network?

SKILL.md names 6 domains. In commands or code: docs.alpaca.markets, broker-api.alpaca.markets, broker-api.sandbox.alpaca.markets, api.alpaca.markets, paper-api.alpaca.markets and data.alpaca.markets; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Alpaca Broker Integration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Alpaca Broker Integration use?

Alpaca Broker Integration is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Alpaca Broker Integration use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Alpaca Broker Integration?

Skills that share tags, products or a category with Alpaca Broker Integration: Miniqmt CLI (oopslink/trading-skills, 176 stars), Metamask Agent Wallet (nirholas/three.ws, 230 stars), Tushare Data (zillionare/zillionare, 322 stars) and Tradingview MCP (atilaahmettaner/tradingview-mcp, 5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Alpaca Broker Integration?

alpacahq (a GitHub organization) maintains it in alpacahq/alpaca-skills, which has 154 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on September 8, 2026.

Source: alpacahq/alpaca-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.