Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Entry point for integrating with the Alpaca Broker API (plus Market Data and Trading APIs) in any programming language. Use when a developer wants to build on Alpaca — open brokerage accounts, run KYC, fund accounts, move money via journals, place orders, consume real-time event streams, or pull market data — and need to know base URLs, auth, conventions, or which focused sub-skill to use.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-17 | ✗→✓ | ▲ Improved | 139% | 0% |
| case-01 | ✗→✓ | ▲ Improved | 117% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 297% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 85% | 0% |
| case-10 | ✗→✓ | ▲ Improved | 89% | 0% |
You are an expert on the Alpaca APIs. Help developers integrate with Alpaca in any programming language. Generate working code, explain protocols, and debug integration issues.
This is the router / overview skill. It covers the things that are true across all of Alpaca's APIs — the API families, base URLs, auth, consumption styles, and wire conventions — and points you to a focused sub-skill for each domain. Read this first, then jump to the specific skill for the task.
> Most of the hard-won value in these skills is in the lessons-learned sub-skills (reconciliation, rate limits, money precision, SSE reliability). Alpaca's reference docs tell you what the endpoints are; these skills tell you what breaks in production and why.
https://docs.alpaca.markets/https://docs.alpaca.markets/reference/https://docs.alpaca.markets/llms.txt and https://docs.alpaca.markets/llms-full.txtLive schema lookups: if the alpaca-docs MCP server is connected, prefer it over guessing — list-specs, list-endpoints, get-endpoint (exact request/response schemas + servers), and search / fetch (guide pages). Always confirm an exact payload against the spec before generating code that posts money or orders.
| Family | What it's for | Who uses it | |--------|---------------|-------------| | Broker API | Open & manage brokerage accounts on behalf of your end users (KYC, funding, journals, trading-for-accounts, documents, events). You are the broker-of-record's tech partner; you custody many sub-accounts under your firm. | Apps that onboard their own users and hold their assets (neobrokers, fintechs). | | Trading API | Trade a single account that belongs to the API-key holder. | Individual algo traders, bots. | | Market Data API | Real-time + historical prices, bars, quotes, trades, news, corporate actions, screener. REST and WebSocket. | Everyone. | | Authentication API | OAuth 2.0 flows for letting third parties act on an Alpaca account. | OAuth integrations. |
Decide first which family you're on — it changes the base URL, the auth, and the URL shape of every call. The most common confusion: Broker API places orders at /v1/trading/accounts/{account_id}/orders (the account is in the path because you act for a user), whereas the standalone Trading API places orders at /v2/orders (implicitly your own account).
These skills focus primarily on the Broker API, because that's where the lifecycle is hardest: onboarding, funding rails, journals, and event reconciliation.
| Family | Production | Sandbox / Paper | |--------|-----------|-----------------| | Broker API | https://broker-api.alpaca.markets | https://broker-api.sandbox.alpaca.markets | | Trading API | https://api.alpaca.markets | https://paper-api.alpaca.markets (paper) | | Market Data (REST) | https://data.alpaca.markets | (same host; sandbox data is limited) | | Market Data (WebSocket) | wss://stream.data.alpaca.markets | wss://stream.data.sandbox.alpaca.markets |
Always start in sandbox. Switch by environment variable, never by code path — a single ENV flag that selects the base URL is the pattern that survives. Sandbox accounts can be funded with fake money and auto-approved, so you can exercise the full lifecycle without real KYC or cash.
Auth differs by API family — this trips people up constantly.
Authorization: Basic base64("<API_KEY_ID>:<API_SECRET_KEY>")The same Basic credential authenticates Broker REST, Broker SSE event streams, and trading-on-behalf-of-accounts. Build the base64 token once at startup; don't recompute per request.
APCA-API-KEY-ID: <API_KEY_ID>
APCA-API-SECRET-KEY: <API_SECRET_KEY>For the WebSocket data stream, you don't use headers — you send an auth message after connecting:
json{"action": "auth", "key": "<API_KEY_ID>", "secret": "<API_SECRET_KEY>"}
> Broker API partners can usually authenticate market-data calls with their Broker Basic credentials too. Pick one scheme per data client and be consistent; mixing them is a frequent source of 401s.
Same APCA-API-* headers as market data.
For OAuth integrations, exchange the code for a token and send Authorization: Bearer <token>.
Alpaca gives you three transports. Use the right one for the job — and know that they have different auth and different reliability characteristics.
| Style | Transport | Use for | Skill | |-------|-----------|---------|-------| | REST | HTTPS request/response | Everything transactional: create account, fund, journal, place order, query state. | the domain skills | | SSE | text/event-stream over a long-lived HTTPS GET | Broker lifecycle events: account status, journals, transfers, trades, non-trade activities. Replayable via cursors. | alpaca-broker-sse-events | | WebSocket | wss:// | Real-time market data (trades/quotes/bars). | alpaca-broker-market-data |
Key distinction: Broker events come over SSE (simple HTTP, Basic auth, replayable with since/since_id). Market data comes over WebSocket (subscribe model, auth message, ping/pong). They are different endpoints with different auth — don't conflate them.
These apply everywhere and are the source of most subtle bugs:
"100.50", "1.5"). Parse into a decimal type, never a binary float. See alpaca-broker-money-precision.account_id, order_id, journal_id, transfer_id are UUIDs. Activity IDs and newer event IDs are ULIDs — lexicographically sortable, which matters for event ordering and replay cursors.client_order_id on orders so retries don't double-fill. Records you create from events should be keyed on the Alpaca ID with upsert/skip-duplicate semantics. See alpaca-broker-reconciliation-idempotency.next_page_token in the body; activities return a page token via the X-Next-Page-Token response header. Loop until the token is empty.X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset (unix seconds). On HTTP 429, wait until reset before retrying. See alpaca-broker-rate-limits-resilience.2026-01-02T15:04:05Z). SSE since/until accept RFC3339, but + in a timezone offset must be URL-encoded as %2B.200 means "accepted," not "settled." Always reconcile on the terminal status, which arrives later via event or poll.When helping someone start from zero, walk them through this order:
ENV switch.GET /v1/accounts (list).alpaca-broker-account-onboarding.ACTIVE status (via SSE account-status events or polling) before any money/trade op.alpaca-broker-funding-transfers.alpaca-broker-journals.alpaca-broker-trading-orders.alpaca-broker-sse-events.alpaca-broker-reconciliation-idempotency.| If the task is about… | Use skill | |-----------------------|-----------| | Creating accounts, KYC, CIP, document upload, agreements, account status, W-8BEN | alpaca-broker-account-onboarding | | ACH / wire / funding-wallet rails, deposits, withdrawals, transfer status, the omnibus/float-account model | alpaca-broker-funding-transfers | | Moving cash (JNLC) or shares (JNLS) between accounts, batch & reverse-batch, journal lifecycle | alpaca-broker-journals | | Placing/canceling orders, qty vs notional, fractional shares, order lifecycle, positions, recurring buys | alpaca-broker-trading-orders | | Snapshots, bars, quotes, assets, news, market clock/calendar, feeds (IEX/SIP), WebSocket price streams | alpaca-broker-market-data | | Consuming Broker SSE event streams reliably (reconnect, heartbeats, replay cursors) | alpaca-broker-sse-events | | Keeping local state correct: missed-event recovery, polling rails without webhooks, idempotency, status guards | alpaca-broker-reconciliation-idempotency | | Backoff, 429 handling, rate-limit headers, concurrency limits, batch sizing | alpaca-broker-rate-limits-resilience | | Handling money correctly: decimals vs floats, numbers-as-strings, truncation/rounding | alpaca-broker-money-precision |
2xx.account_id, order_id, journal_id, transfer_id on your local records — they are your only correlation key for events and reconciliation.alpaca-broker-reconciliation-idempotency).X-RateLimit-Remaining, back off before you get throttled.client_order_id and Alpaca-ID-keyed upserts so retries and duplicate events are safe.httpx/requests (REST), httpx/aiohttp or an SSE client for events, websockets for data, decimal.Decimal for money.fetch (REST), an EventSource implementation for SSE (pass the Authorization header), ws for WebSocket, decimal-as-string or decimal.js.net/http (REST + SSE via a streaming bufio.Scanner), gorilla/websocket for data; be deliberate about money types (shopspring/decimal if precision matters).text/event-stream; if no SSE client exists, read the response body line-by-line and parse data: frames.Alpaca also publishes official SDKs (alpaca-py, @alpacahq/alpaca-trade-api / typescript-sdk, Go community SDKs). Offer them when the user wants speed, but these skills teach the wire protocol so the knowledge transfers to any language or a custom client.
Other measured skills in the registry, with their headline benchmark lift.