Agent skill

Alpaca CLI

by alpacahq in alpacahq/cli

Install, configure, and use the Alpaca CLI - a command-line tool for the Alpaca Trading API.

Apache-2.0Auto-check passedBusiness, Finance & HR

Install Alpaca CLI

skills CLI
$ npx skills add alpacahq/cli --skill alpaca-cli -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alpacahq/cli alpaca-cli --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alpacahq/cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/alpaca-cli .claude/skills/alpaca-cli && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
alpaca-cli
GitHub stars
177
Token cost
~2.6k tokens
SKILL.md length
941 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
Apache-2.0

At a glance

Install, configure, and use the Alpaca CLI - a command-line tool for the Alpaca Trading API.

  • Works in 3 steps: ALPACA_API_KEY + ALPACA_SECRET_KEY… → Profile access_token -> OAuth from… → Profile api_key + secret_key -> API keys…
  • The user asks to install the Alpaca CLI
  • SKILL.md covers Install, Authentication, Verify installation and Agent and automation usage, plus 6 more sections
  • Calls go; needs ALPACA_SECRET_KEY and ALPACA_API_KEY

What it does

Alpaca CLI is an agent skill from alpacahq/cli. Install, configure, and use the Alpaca CLI - a command-line tool for the Alpaca Trading API. Covers installation (Go), API key authentication, profile management, and agent/automation integration. Use when the user asks to install the Alpaca CLI, set up Alpaca API credentials, trade stocks or crypto from the command line, get market data via CLI, or integrate the Alpaca CLI into scripts, CI pipelines, or AI agent workflows. Keywords: alpaca, trading, stocks, crypto, market data, brokerage, command line, CLI tool…

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires Go (go install) for installation. macOS, Linux, and Windows supported.

It sits in Business, Finance & HR, covering Stock and market analysis, CI/CD and Authentication. It works with Alpaca. The licence is Apache-2.0.

When your agent uses it

  • The user asks to install the Alpaca CLI
  • Set up Alpaca API credentials
  • Crypto from the command line
  • Get market data via CLI

Example prompts

  • “/alpaca-cli”

Requirements

  • A credential in ALPACA_API_KEY
  • A credential in ALPACA_SECRET_KEY
  • Compatibility (from SKILL.md): Requires Go (go install) for installation. macOS, Linux, and Windows supported.

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. ALPACA_API_KEY + ALPACA_SECRET_KEY together -> env API keys
  2. Profile access_token -> OAuth from active profile
  3. Profile api_key + secret_key -> API keys from active profile

What it can do on your machine

Read from SKILL.md and the folder at commit 5360627. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ALPACA_SECRET_KEY
    • ALPACA_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Go (go install) for installation. macOS, Linux, and Windows supported.

    From compatibility in the SKILL.md frontmatter.

Context cost

Alpaca CLI loads about 2.6k tokens when it runs. Until then it costs about 136 tokens; SKILL.md has 941 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~136
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alpacahq/cli at commit 5360627, republished under its Apache-2.0 licence (© alpacahq). 941 words, ~2,596 tokens.

Download SKILL.mdSave it as .claude/skills/alpaca-cli/SKILL.md (or your agent's skills folder).
name
alpaca-cli
description
Install, configure, and use the Alpaca CLI - a command-line tool for the Alpaca Trading API. Covers installation (Go), API key authentication, profile management, and agent/automation integration. Use when the user asks to install the Alpaca CLI, set up Alpaca API credentials, trade stocks or crypto from the command line, get market data via CLI, or integrate the Alpaca CLI into scripts, CI pipelines, or AI agent workflows. Keywords: alpaca, trading, stocks, crypto, market data, brokerage, command line, CLI tool, API key setup.
compatibility
Requires Go (go install) for installation. macOS, Linux, and Windows supported.

Alpaca CLI

Install

Check if already installed:

bash
alpaca version

If not installed:

bash
go install github.com/alpacahq/cli/cmd/alpaca@latest

Authentication

Paper trading is the default. alpaca profile login uses OAuth and is paper-only. For live trading, use API keys: alpaca profile login --api-key --live.

Interactive login (stores credentials on disk)
bash
alpaca profile login

Credentials are stored in ~/.config/alpaca/profiles/ with 0600 permissions.

The embedded OAuth client ID and secret are public native-app identifiers, not security credentials. OAuth access is gated by browser consent plus redirect/state validation, and remains paper-only until the flow is hardened with PKCE or Device Authorization Grant.

Environment variables (for scripts, CI, agents)

No secrets touch disk. Preferred for automation:

bash
export ALPACA_API_KEY=PK...
export ALPACA_SECRET_KEY=...

Env API keys default to paper trading. For live, set ALPACA_LIVE_TRADE=true.

When env API keys are set, they are the authoritative credentials - any profile on disk is ignored. OAuth tokens cannot be set via env var; use alpaca profile login to store them in a profile.

Multiple profiles
bash
alpaca profile login --name paper              # OAuth, paper (default)
alpaca profile login --api-key --name live --live  # API keys, live trading
alpaca profile switch live                      # switch active profile
alpaca doctor                                   # show active profile + connectivity

Verify installation

bash
alpaca version
alpaca clock --quiet

If authenticated, also verify credentials work:

bash
alpaca account get --quiet

Exit code 0 = success, 2 = auth error.

Agent and automation usage

API commands are non-interactive once credentials are configured.

Auth and setup commands may still prompt or open a browser:

  • alpaca profile login opens a browser for OAuth and may prompt for scopes on a TTY.
  • alpaca profile login --api-key prompts for missing credentials unless --key and --secret are provided.
  • For unattended workflows, prefer environment variables over alpaca profile login.
Always use --quiet

JSON is the default output format. --quiet suppresses all non-data output (warnings, hints). Use it for machine-readable results:

bash
alpaca position list --quiet
alpaca data latest-trade --symbol AAPL --quiet

Or set it once via environment variable so every invocation is quiet:

bash
export ALPACA_QUIET=1
alpaca position list
Structured errors on stderr

Errors are always JSON on stderr:

json
{"error":"rate limited","code":0,"status":429,"hint":"Rate limited. Reduce request frequency or add delays between calls."}
Exit codes
CodeMeaning
0Success
1API or general error
2Authentication error (401)
Dry run

Preview an order without submitting:

bash
alpaca order submit --symbol AAPL --side buy --qty 10 --type limit --limit-price 185.00 --dry-run
Pipe JSON payloads
bash
echo '{"symbol":"AAPL","qty":"1","side":"buy","type":"market","time_in_force":"day"}' \
  | alpaca api POST /v2/orders
Idempotent order submission

Always pass --client-order-id when submitting orders. The API rejects duplicates (409), preventing double-orders on ambiguous failures:

bash
CLIENT_ORDER_ID="$(uuidgen)"
alpaca order submit --symbol AAPL --side buy --qty 10 --type market --client-order-id "$CLIENT_ORDER_ID" --quiet

On failure or timeout, check before retrying:

bash
alpaca order get-by-client-id --client-order-id "$CLIENT_ORDER_ID" --quiet

If the order is returned, it went through - do not resubmit. If 404 (exit code 1), retry is safe.

Resilience

The CLI retries on 429 and 5xx with exponential backoff (max 3 attempts). Retry-After headers are respected.

Debug API calls
bash
alpaca account get --verbose   # one-line request/response summary on stderr
alpaca account get --trace     # timing breakdown (DNS, TLS, TTFB) on stderr
alpaca account get --debug     # full headers and bodies on stderr

Credentials are always scrubbed from debug output.

Filter JSON output
bash
alpaca position list --jq '.[0].symbol'
alpaca order list --jq '[.[] | {id, symbol, side, qty}]'

--jq applies a jq expression to the JSON output without requiring an external jq install.

Environment variables

VariableDescription
ALPACA_API_KEYAPI key. Must be set together with ALPACA_SECRET_KEY.
ALPACA_SECRET_KEYSecret key. Must be set together with ALPACA_API_KEY.
ALPACA_LIVE_TRADEtrue routes to live; anything else (unset, empty, false) routes to paper
ALPACA_PROFILEProfile name to use
ALPACA_OUTPUTDefault output format (json, csv)
ALPACA_CONFIG_DIRConfig directory (default: ~/.config/alpaca)
ALPACA_QUIETSuppress non-data output - warnings, hints, color
ALPACA_VERBOSEShow HTTP request summaries on stderr
ALPACA_DEBUGShow HTTP request/response headers and bodies on stderr
ALPACA_TRACEShow HTTP timing breakdown on stderr (DNS, TLS, TTFB)
Credential precedence

Credentials resolve as an atomic bundle (no field-level mixing). First complete source wins:

  1. ALPACA_API_KEY + ALPACA_SECRET_KEY together -> env API keys
  2. Profile access_token -> OAuth from active profile
  3. Profile api_key + secret_key -> API keys from active profile

A partial env bundle (only one of the two) falls through to the profile. Env API keys always beat anything in a profile. OAuth tokens are not readable from env - use alpaca profile login.

Paper vs live resolves independently: ALPACA_LIVE_TRADE > profile live_trade > paper default. Env-sourced credentials ignore the profile's live_trade field and default to paper unless ALPACA_LIVE_TRADE=true opts into live. Agents should set ALPACA_LIVE_TRADE=true explicitly when live trading is intended; any other value (including false) keeps you on paper.

Show full SKILL.md (355 more words)Show less

Self-update

Check for updates explicitly before starting work when you need upgrade guidance:

bash
alpaca update --check --quiet

This returns structured output:

json
{"current":"0.0.1","latest":"0.0.2","update_available":true,"install_method":"goinstall","update_command":"go install github.com/alpacahq/cli/cmd/alpaca@latest"}

If update_available is true, run the update_command value to upgrade. Or invoke alpaca update --yes to run the upgrade non-interactively.

Manual commands:

bash
alpaca update              # check, prompt, then run the upgrade
alpaca update --yes        # check and upgrade without prompting
alpaca update --check      # machine-readable update check (JSON, no prompt)

Discovering commands

bash
alpaca --help-all                    # dump all commands, subcommands, and flags
alpaca order --help                  # help for a command group
alpaca order submit --help           # help for a specific command
alpaca order list --schema           # show response fields for a command
alpaca doctor                        # check config and API connectivity

Use --help-all to find the right command. Use <command> --help for flag details. Use <command> --schema to see API response fields generated from the spec. These are always current - never rely on stale documentation when the CLI is installed.

Pagination

Data commands return one page by default. Use --limit to control page size and --page-token to fetch subsequent pages:

bash
alpaca data bars --symbol AAPL --start 2025-01-01 --limit 500
alpaca data bars --symbol AAPL --start 2025-01-01 --limit 500 --page-token <token>

The response includes a next_page_token field when more data is available.

Troubleshooting

command not found: alpaca - Ensure $GOPATH/bin (usually ~/go/bin) is in your PATH.

Exit code 2 on every command - Credentials are missing or invalid. Re-run alpaca profile login or verify ALPACA_API_KEY / ALPACA_SECRET_KEY env vars.

Rate limited (429) - The CLI retries automatically, but if it persists, add delays between calls. Check Retry-After in --verbose output.

Completions not working - Run alpaca completion <shell> to generate completions, then open a new shell. For zsh, ensure compinit is loaded in .zshrc.

Anti-patterns

  • NEVER switch to live trading without explicit user intent. alpaca profile login defaults to paper trading - do not pass --live unless the user specifically asks for it.
  • NEVER pass --secret as a CLI flag - it leaks into shell history. Use alpaca profile login interactively or set ALPACA_SECRET_KEY as an env var.
  • NEVER omit --quiet in automation or agent workflows - without it, output may include hints and warnings on stderr that break parsing.
  • NEVER ignore exit code 2 - it means authentication failed. Do not retry; fix credentials first.
  • NEVER hardcode API keys in scripts or committed files - use environment variables or profile-based auth.
  • NEVER submit live orders without confirming the user's intent - use --dry-run to preview first when there is any ambiguity.
  • NEVER submit orders without --client-order-id in automation - without it, retries after ambiguous failures (timeouts, network errors) risk placing duplicate orders.
  • NEVER create locates without explicit user intent - alpaca locate create may incur locate fees. Use alpaca locate quotes or alpaca locate list for read-only checks.

© alpacahq, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/alpaca-cli of alpacahq/cli.

Open the folder on GitHubat commit 5360627

Compare with similar skills

Alpaca CLI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Alpaca CLI compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Alpaca CLI this skillalpacahq/cli177—~2.6kAutomated safety check: PassApache-2.0
Metamask Agent Walletnirholas/three.ws227—~4.5kAutomated safety check: PassMIT
Setupdaloopa/investing489—~1kAutomated safety check: NotesApache-2.0
Alpaca Broker Market Dataalpacahq/alpaca-skills154—~2.3kAutomated safety check: PassApache-2.0
Miniqmt CLIoopslink/trading-skills176—~8.2kAutomated safety check: PassMIT
Superior Trade AuthSuperior-Trade/superior-skills214—~950Automated safety check: PassMIT

Similar skills

  • Metamask Agent Wallet

    nirholas/three.ws

    A skill your agent uses when the user asks anything about blockchain wallets, transactions, signing, token transfers, supported chains, wallet balances, perpetual futures trading, prediction…

    227 GitHub stars~4.5k tokensUpdated today
    Business, Finance & HRAuto-check passed
  • Setup

    daloopa/investing

    Walk through initial setup and authentication for this Daloopa starter kit

    489 GitHub stars~1k tokensUpdated today
    Business, Finance & HRAuto-check: notes
  • Alpaca Broker Market Data

    alpacahq/alpaca-skills

    Pull and stream US stock market data from Alpaca — REST snapshots/bars/trades/quotes, historical bars with timeframes and feeds (IEX vs SIP), the assets master list, market clock & calendar, news…

    154 GitHub stars~2.3k tokensUpdated 29 days ago
    Business, Finance & HRAuto-check passed
  • Miniqmt CLI

    oopslink/trading-skills

    Operate miniQMT/xtquant via the miniqmt-cli tool -- market data queries, real-time streaming, account management, order placement with safety guards, daemon health checks, SSH tunnel management, and…

    176 GitHub stars~8.2k tokensUpdated 4 mo ago
    Business, Finance & HRAuto-check passed
  • Superior Trade Auth

    Superior-Trade/superior-skills

    A skill your agent uses when an agent needs to register a Superior Trade account, verify an email OTP, configure x-api-key authentication, or recover from missing or invalid credentials before using…

    214 GitHub stars~950 tokensUpdated 28 days ago
    Business, Finance & HRAuto-check passed
  • Birdeye API

    agiprolabs/claude-trading-skills

    Solana token market data via Birdeye — prices, OHLCV, trades, token metadata, security checks, and trader activity

    410 GitHub stars~1.8k tokensUpdated 1 mo ago
    Business, Finance & HRAuto-check passed

More from alpacahq/cli

  • Keep the CLI in sync with upstream OpenAPI specs. An agent skill from alpacahq/cli.

    177 GitHub stars~2k tokensUpdated 5 days ago
    Auto-check passed

Works with

Questions about Alpaca CLI

What does Alpaca CLI do?

Install, configure, and use the Alpaca CLI - a command-line tool for the Alpaca Trading API. Alpaca CLI is an agent skill from alpacahq/cli. Install, configure, and use the Alpaca CLI - a command-line tool for the Alpaca Trading API.

When should I use Alpaca CLI?

Alpaca CLI fits situations like: the user asks to install the Alpaca CLI; set up Alpaca API credentials; crypto from the command line; get market data via CLI.

How do I install Alpaca CLI in Claude Code?

Run `npx skills add alpacahq/cli --skill alpaca-cli -a claude-code`. Or copy the skill folder (.agents/skills/alpaca-cli in alpacahq/cli) into .claude/skills/alpaca-cli in your project. Claude Code loads it when a task matches its description.

How do I install Alpaca CLI in Codex?

Run `npx skills add alpacahq/cli --skill alpaca-cli -a codex`. Or copy the skill folder (.agents/skills/alpaca-cli in alpacahq/cli) into .agents/skills/alpaca-cli in your project. Codex loads it when a task matches its description.

Can I use Alpaca CLI in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alpacahq/cli --skill alpaca-cli -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/alpaca-cli, .gemini/skills/alpaca-cli, .github/skills/alpaca-cli and .opencode/skills/alpaca-cli in your project.

What does Alpaca CLI need to run?

Going by SKILL.md and its folder, Alpaca CLI needs the command-line tools its instructions call (go) and credentials named ALPACA_SECRET_KEY and ALPACA_API_KEY. Our summary lists: A credential in ALPACA_API_KEY; A credential in ALPACA_SECRET_KEY. Compatibility (from SKILL.md): Requires Go (go install) for installation. macOS, Linux, and Windows supported..

Does Alpaca CLI access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Alpaca CLI safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Alpaca CLI use?

Alpaca CLI is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Alpaca CLI use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Alpaca CLI?

Skills that share tags, products or a category with Alpaca CLI: Metamask Agent Wallet (nirholas/three.ws, 227 stars), Setup (daloopa/investing, 489 stars), Alpaca Broker Market Data (alpacahq/alpaca-skills, 154 stars) and Miniqmt CLI (oopslink/trading-skills, 176 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Alpaca CLI?

alpacahq (a GitHub organization) maintains it in alpacahq/cli, which has 177 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 2, 2026.

Source: alpacahq/cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.