Add Hosted Key
simstudioai/sim
Add hosted API key support to a tool so Sim provides the key (metered and billed to the workspace) when a user has not brought their own.
Make Alpaca API clients resilient — rate-limit header handling, HTTP 429 backoff, exponential retry, bounded concurrency/worker pools, pagination loops, batch sizing, and timeouts.
$ npx skills add alpacahq/alpaca-skills --skill alpaca-broker-rate-limits-resilience -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install alpacahq/alpaca-skills alpaca-broker-rate-limits-resilience --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/alpacahq/alpaca-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/broker-api/rate-limits-resilience .claude/skills/alpaca-broker-rate-limits-resilience && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "alpaca-broker-rate-limits-resilience" agent skill from https://github.com/alpacahq/alpaca-skills/tree/main/skills/broker-api/rate-limits-resilience into .claude/skills/alpaca-broker-rate-limits-resilience/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alpaca-broker-rate-limits-resilience", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/alpacahq/alpaca-skills/tree/main/skills/broker-api/rate-limits-resilienceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add alpacahq/alpaca-skills --skill alpaca-broker-rate-limits-resilience -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install alpacahq/alpaca-skills alpaca-broker-rate-limits-resilience --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alpacahq/alpaca-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/broker-api/rate-limits-resilience .agents/skills/alpaca-broker-rate-limits-resilience && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "alpaca-broker-rate-limits-resilience" agent skill from https://github.com/alpacahq/alpaca-skills/tree/main/skills/broker-api/rate-limits-resilience into .agents/skills/alpaca-broker-rate-limits-resilience/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alpaca-broker-rate-limits-resilience", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add alpacahq/alpaca-skills --skill alpaca-broker-rate-limits-resilience -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install alpacahq/alpaca-skills alpaca-broker-rate-limits-resilience --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alpacahq/alpaca-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/broker-api/rate-limits-resilience .cursor/skills/alpaca-broker-rate-limits-resilience && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "alpaca-broker-rate-limits-resilience" agent skill from https://github.com/alpacahq/alpaca-skills/tree/main/skills/broker-api/rate-limits-resilience into .cursor/skills/alpaca-broker-rate-limits-resilience/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alpaca-broker-rate-limits-resilience", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/alpacahq/alpaca-skills.git --path skills/broker-api/rate-limits-resilience--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add alpacahq/alpaca-skills --skill alpaca-broker-rate-limits-resilience -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install alpacahq/alpaca-skills alpaca-broker-rate-limits-resilience --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alpacahq/alpaca-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/broker-api/rate-limits-resilience .gemini/skills/alpaca-broker-rate-limits-resilience && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "alpaca-broker-rate-limits-resilience" agent skill from https://github.com/alpacahq/alpaca-skills/tree/main/skills/broker-api/rate-limits-resilience into .gemini/skills/alpaca-broker-rate-limits-resilience/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alpaca-broker-rate-limits-resilience", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install alpacahq/alpaca-skills alpaca-broker-rate-limits-resilienceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add alpacahq/alpaca-skills --skill alpaca-broker-rate-limits-resilience -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/alpacahq/alpaca-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/broker-api/rate-limits-resilience .github/skills/alpaca-broker-rate-limits-resilience && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "alpaca-broker-rate-limits-resilience" agent skill from https://github.com/alpacahq/alpaca-skills/tree/main/skills/broker-api/rate-limits-resilience into .github/skills/alpaca-broker-rate-limits-resilience/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alpaca-broker-rate-limits-resilience", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add alpacahq/alpaca-skills --skill alpaca-broker-rate-limits-resilience -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install alpacahq/alpaca-skills alpaca-broker-rate-limits-resilience --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alpacahq/alpaca-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/broker-api/rate-limits-resilience .opencode/skills/alpaca-broker-rate-limits-resilience && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "alpaca-broker-rate-limits-resilience" agent skill from https://github.com/alpacahq/alpaca-skills/tree/main/skills/broker-api/rate-limits-resilience into .opencode/skills/alpaca-broker-rate-limits-resilience/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alpaca-broker-rate-limits-resilience", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
alpaca-broker-rate-limits-resilienceMake Alpaca API clients resilient — rate-limit header handling, HTTP 429 backoff, exponential retry, bounded concurrency/worker pools, pagination loops, batch sizing, and timeouts.
Alpaca Broker Rate Limits Resilience is an agent skill from alpacahq/alpaca-skills. Make Alpaca API clients resilient — rate-limit header handling, HTTP 429 backoff, exponential retry, bounded concurrency/worker pools, pagination loops, batch sizing, and timeouts. Use when building robust REST clients, bulk/cron jobs, or reconciliation sweeps against Alpaca in any language.
Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `reference.md`).
It sits in Backend & APIs, covering Rate limiting. It works with Alpaca. The repository describes itself as: Agent skills for Alpaca's Trading API and Broker API: drop-in SKILL.md files for AI coding assistants. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 39111ab. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Alpaca Broker Rate Limits Resilience loads about 1.4k tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 589 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from alpacahq/alpaca-skills at commit 39111ab, republished under its Apache-2.0 licence (© alpacahq). 589 words, ~1,450 tokens.
.claude/skills/alpaca-broker-rate-limits-resilience/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Alpaca's APIs are rate-limited and occasionally flaky under load. Any client that does more than a handful of calls — especially bulk jobs, backfills, and reconciliation sweeps — needs disciplined retry, backoff, and concurrency control. These patterns are transport-level and apply in any language.
Read
alpaca-broker-integrationfirst.
Alpaca returns standard headers:
| Header | Meaning |
|---|---|
X-RateLimit-Limit | requests allowed in the window |
X-RateLimit-Remaining | requests left in the current window |
X-RateLimit-Reset | unix timestamp (seconds) when the window resets |
Parse them on every response, not just on errors. Two uses:
Remaining drops below a threshold (e.g. ≤ 50), log a warning and/or slow down — you're about to get throttled.429, use Reset to wait exactly until the window opens.Limits vary by endpoint and plan; market-data limits differ from broker limits. Don't hardcode a number — react to the headers.
MAX_ATTEMPTS = 10
INITIAL_DELAY_MS = 1000
for attempt in 1..MAX_ATTEMPTS:
res = http(request) # with a sane timeout (see §5)
remaining, reset_at = parse_rate_headers(res.headers)
if remaining <= 50: log_warn("approaching rate limit", reset_at)
if res.status == 429:
# wait until the window resets, plus a small buffer
wait = (reset_at - now()) if reset_at else INITIAL_DELAY_MS * 2^(attempt-1)
sleep(max(0, wait) + 1000) # +1s buffer past reset
continue
if res.status in (500, 502, 503, 504) or network_error:
sleep(INITIAL_DELAY_MS * 2^(attempt-1)) # exponential backoff
continue
return res # success or non-retryable 4xx
raise last_errorKey points:
429, wait until X-RateLimit-Reset + a ~1s buffer — don't blindly exponential-backoff when the API told you exactly when to retry.base * 2^(attempt-1)) for network errors and 5xx. With base 1s and 10 attempts the tail is minutes — fine for background jobs, too slow for user-facing calls (use fewer attempts there).400/403/422) — those won't fix themselves; surface them.Parallelism speeds bulk jobs but is the fastest way to hit limits. Use a fixed worker pool, not unbounded fan-out.
List endpoints page forward with a token — never assume one response is complete.
/v1/accounts/activities): page via the X-Next-Page-Token response header; loop until it's empty. Use page_size (≤100) and a direction./v2/stocks/bars): page via next_page_token in the body → pass back as page_token. Remember limit counts across all symbols and results sort by symbol-then-time, so a single page may contain only the first symbol(s) — keep paging.token = null
loop:
page = fetch(url + (token ? "&page_token="+token : "")) # via retry loop
accumulate(page.items)
token = page.next_token # header or body, per endpoint
if not token: breakalpaca-broker-sse-events.)429 → wait until X-RateLimit-Reset + buffer.alpaca-broker-reconciliation-idempotency.Related skills: safe re-runs of jobs → alpaca-broker-reconciliation-idempotency; the heal/poll jobs that use these patterns → alpaca-broker-reconciliation-idempotency; market-data pagination specifics → alpaca-broker-market-data.
© alpacahq, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/broker-api/rate-limits-resilience of alpacahq/alpaca-skills.
Open the folder on GitHubat commit 39111ab
Alpaca Broker Rate Limits Resilience next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Alpaca Broker Rate Limits Resilience this skillalpacahq/alpaca-skills | 154 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Add Hosted Keysimstudioai/sim | 30k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | |
| Upstash Ratelimit TSupstash/ratelimit-js | 2k | — | ~313 | Automated safety check: Pass | MIT | |
| Repo2skillzhangyanxs/repo2skill | 246 | — | ~3.6k | Automated safety check: Pass | None | |
| Better Auth Security Best PracticesEpicenterHQ/epicenter | 4.8k | — | ~896 | Automated safety check: Pass | Custom licence | |
| Dload Fetch Toolphp-internal/dload | 105 | — | ~1.1k | Automated safety check: Pass | BSD-3-Clause |
simstudioai/sim
Add hosted API key support to a tool so Sim provides the key (metered and billed to the workspace) when a user has not brought their own.
upstash/ratelimit-js
Lightweight guidance for using the Redis Rate Limit TypeScript SDK, including setup steps, basic usage, and pointers to advanced algorithm, features, pricing, and traffic‑protection docs.
zhangyanxs/repo2skill
Convert GitHub/GitLab/Gitee repositories into comprehensive OpenCode Skills using embedded LLM calls with multiple mirrors and rate limit handling
EpicenterHQ/epicenter
Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.
php-internal/dload
Get a CLI tool — native binary or PHAR — from a GitHub release into a project folder with dload (vendor/bin/dload).
itsmostafa/aws-agent-skills
AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.
alpacahq/alpaca-skills
Open and manage brokerage accounts via the Alpaca Broker API — account creation, KYC/CIP, identity & disclosures, agreements, document upload (incl.
alpacahq/alpaca-skills
Move money between an Alpaca brokerage account and the EXTERNAL banking world via the Broker API — ACH relationships, wire recipient banks, classic transfers (deposits/withdrawals), the v1beta…
alpacahq/alpaca-skills
Entry point for integrating with the Alpaca Broker API (plus Market Data and Trading APIs) in any programming language.
alpacahq/alpaca-skills
Move cash (JNLC) and securities (JNLS) BETWEEN accounts inside your own Alpaca omnibus via the Broker API — single, batch, and reverse-batch journals, the Idempotency-Key header, journal status…
alpacahq/alpaca-skills
Handle money and numeric precision correctly with the Alpaca API — numbers-as-strings on the wire, decimals vs floats, rounding/truncation before sending amounts, fractional-share precision, and…
alpacahq/alpaca-skills
Keep local state correct against the Alpaca Broker API — idempotency keys, ID-keyed upserts, event snapshotting and dedup, polling rails that have no events, nightly reconciliation/heal jobs, status…
Works with
Categories
Make Alpaca API clients resilient — rate-limit header handling, HTTP 429 backoff, exponential retry, bounded concurrency/worker pools, pagination loops, batch sizing, and timeouts. Alpaca Broker Rate Limits Resilience is an agent skill from alpacahq/alpaca-skills. Make Alpaca API clients resilient — rate-limit header handling, HTTP 429 backoff, exponential retry, bounded concurrency/worker pools, pagination loops, batch sizing, and timeouts.
Alpaca Broker Rate Limits Resilience fits situations like: building robust REST clients; reconciliation sweeps against Alpaca in any language.
Run `npx skills add alpacahq/alpaca-skills --skill alpaca-broker-rate-limits-resilience -a claude-code`. Or copy the skill folder (skills/broker-api/rate-limits-resilience in alpacahq/alpaca-skills) into .claude/skills/alpaca-broker-rate-limits-resilience in your project. Claude Code loads it when a task matches its description.
Run `npx skills add alpacahq/alpaca-skills --skill alpaca-broker-rate-limits-resilience -a codex`. Or copy the skill folder (skills/broker-api/rate-limits-resilience in alpacahq/alpaca-skills) into .agents/skills/alpaca-broker-rate-limits-resilience in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alpacahq/alpaca-skills --skill alpaca-broker-rate-limits-resilience -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/alpaca-broker-rate-limits-resilience, .gemini/skills/alpaca-broker-rate-limits-resilience, .github/skills/alpaca-broker-rate-limits-resilience and .opencode/skills/alpaca-broker-rate-limits-resilience in your project.
SKILL.md names no scripts, command-line tools or credentials: Alpaca Broker Rate Limits Resilience is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Alpaca Broker Rate Limits Resilience is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Alpaca Broker Rate Limits Resilience: Add Hosted Key (simstudioai/sim, 30k stars), Upstash Ratelimit TS (upstash/ratelimit-js, 2k stars), Repo2skill (zhangyanxs/repo2skill, 246 stars) and Better Auth Security Best Practices (EpicenterHQ/epicenter, 4.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
alpacahq (a GitHub organization) maintains it in alpacahq/alpaca-skills, which has 154 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on September 8, 2026.
Source: alpacahq/alpaca-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.