Alpaca for AI agents

Alpaca is a brokerage platform for commission-free stock and crypto trading, with market data and an API for building automated trading strategies. Traders and developers use it to place and manage orders. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

E-commerceOAuth 2.0MCP + RESTalpaca.markets
AUDIT LOG · ALPACAPOLICY: acme-support
09:41:07 · claude · u_8f2read
alpaca.get_news
Get News✓ allowed · 212ms
09:41:08 · claude · u_8f2read
alpaca.get_clock
Get Clock✓ allowed · 164ms
09:41:09 · claude · u_8f2write
alpaca.create_watchlist
Create Watchlist✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
alpaca.delete_watchlist_by_id
Delete Watchlist By ID✕ blocked · policy: deny
EVERY ALPACA CALL, ON THE RECORD
01 · USE CASES

What agents do in Alpaca.

01

Review open positions and orders

Pull all open positions and outstanding orders on the account before deciding what to change.

02

Build out a watchlist

Create a new watchlist and add specific stock or crypto symbols a user wants to track.

03

Require approval before closing all positions

Liquidating every open position and canceling all orders is destructive, so it needs explicit approval first.

02 · ACTIONS

100 Alpaca actions, graded by risk.

Every Alpaca action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

84

Look things up. Allowed by default.

  • alpaca.get_news
    Get News
  • alpaca.get_clock
    Get Clock
  • alpaca.get_account
    Get Account
  • alpaca.get_calendar
    Get Calendar
  • alpaca.get_exchanges
    Get Exchanges
  • alpaca.get_all_orders
    Get All Orders
  • alpaca.get_conditions
    Get Stock Conditions
  • alpaca.get_pdt_status
    Get PDT Status
  • alpaca.get_watchlists
    Get Watchlists
  • alpaca.get_bars_stocks
    Get Historical Stock Bars
  • alpaca.get_option_bars
    Get Options Historical Bars
  • alpaca.get_most_actives
    Get Most Active Stocks
  • alpaca.get_option_chain
    Get Option Chain
  • alpaca.get_subscription
    Get Subscription
  • alpaca.get_open_position
    Get Open Position
  • alpaca.get_option_trades
    Get Options Historical Trades
+ 68 MORE

write

10

Create and change things. Allow, or ask the user first.

  • alpaca.create_watchlist
    Create Watchlist
  • alpaca.add_asset_to_watchlist
    Add Asset to Watchlist
  • alpaca.update_watchlist_by_id
    Update Watchlist By ID
  • alpaca.update_watchlist_by_name
    Update Watchlist By Name
  • alpaca.update_watchlist_by_name2
    Update Watchlist By Name (v2)
  • alpaca.create_watchlist_for_account
    Create Watchlist
  • alpaca.update_trading_configurations
    Update Trading Configurations
  • alpaca.add_asset_to_watchlist_by_name
    Add Asset to Watchlist by Name
  • alpaca.upload_account_cip
    Upload Account CIP Information
  • alpaca.patch_account_configurations
    Update Account Configurations

destructive

6

Delete, cancel or archive. Ask first, or deny outright.

  • alpaca.delete_watchlist_by_id
    Delete Watchlist By ID
  • alpaca.delete_all_open_positions
    Delete All Open Positions
  • alpaca.delete_unsubscribe_account
    Delete Unsubscribe Account
  • alpaca.remove_asset_from_watchlist
    Remove Asset From Watchlist
  • alpaca.remove_symbol_from_watchlist
    Remove Symbol From Watchlist
  • alpaca.delete_all_orders_for_account
    Delete All Orders for Account
03 · HOW IT WORKS

Alpaca in three steps.

  1. 01Your users connect AlpacaThey sign in to Alpaca on Arc0 Connect, under your brand, and approve the access you ask for.
  2. 02You set the rulesReads run, writes like “create Watchlist” can wait for the user, and “delete Watchlist By ID” can be denied outright.
  3. 03Any agent can actYour agent calls Alpaca through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('alpaca', {
  read: 'allow',
  write: 'ask',        // create_watchlist
  destructive: 'deny',  // delete_watchlist_by_id
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Alpaca connects.

Users sign in to Alpaca on Arc0 Connect and approve the scopes you request. Build with Arc0’s Alpaca OAuth app, or bring your own so the Alpaca consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

The same Alpaca connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key · OAuth 2.0
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Alpaca from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Alpaca and Arc0, answered.

Q01

Can I use Alpaca with Claude, ChatGPT or Cursor?

Yes. Connect Alpaca to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Alpaca actions you allow.

Q02

How do users connect Alpaca?

Users sign in to Alpaca on Arc0 Connect and approve the scopes you request. Build with Arc0’s Alpaca OAuth app, or bring your own so the Alpaca consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

Q03

Which Alpaca actions can my agent take?

100 in total: 84 read, 10 write and 6 destructive, such as “create Watchlist”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Alpaca?

Yes. Actions like “delete Watchlist By ID” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Alpaca too?

Yes. The same Alpaca connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Alpaca into your agent.

Your users connect Alpaca once, under your brand. Your agent gets 100 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan