Alpaca for AI agents
Alpaca is a brokerage platform for commission-free stock and crypto trading, with market data and an API for building automated trading strategies. Traders and developers use it to place and manage orders. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Alpaca.
Review open positions and orders
Pull all open positions and outstanding orders on the account before deciding what to change.
Build out a watchlist
Create a new watchlist and add specific stock or crypto symbols a user wants to track.
Require approval before closing all positions
Liquidating every open position and canceling all orders is destructive, so it needs explicit approval first.
100 Alpaca actions, graded by risk.
Every Alpaca action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
84Look things up. Allowed by default.
- alpaca.get_newsGet News
- alpaca.get_clockGet Clock
- alpaca.get_accountGet Account
- alpaca.get_calendarGet Calendar
- alpaca.get_exchangesGet Exchanges
- alpaca.get_all_ordersGet All Orders
- alpaca.get_conditionsGet Stock Conditions
- alpaca.get_pdt_statusGet PDT Status
- alpaca.get_watchlistsGet Watchlists
- alpaca.get_bars_stocksGet Historical Stock Bars
- alpaca.get_option_barsGet Options Historical Bars
- alpaca.get_most_activesGet Most Active Stocks
- alpaca.get_option_chainGet Option Chain
- alpaca.get_subscriptionGet Subscription
- alpaca.get_open_positionGet Open Position
- alpaca.get_option_tradesGet Options Historical Trades
write
10Create and change things. Allow, or ask the user first.
- alpaca.create_watchlistCreate Watchlist
- alpaca.add_asset_to_watchlistAdd Asset to Watchlist
- alpaca.update_watchlist_by_idUpdate Watchlist By ID
- alpaca.update_watchlist_by_nameUpdate Watchlist By Name
- alpaca.update_watchlist_by_name2Update Watchlist By Name (v2)
- alpaca.create_watchlist_for_accountCreate Watchlist
- alpaca.update_trading_configurationsUpdate Trading Configurations
- alpaca.add_asset_to_watchlist_by_nameAdd Asset to Watchlist by Name
- alpaca.upload_account_cipUpload Account CIP Information
- alpaca.patch_account_configurationsUpdate Account Configurations
destructive
6Delete, cancel or archive. Ask first, or deny outright.
- alpaca.delete_watchlist_by_idDelete Watchlist By ID
- alpaca.delete_all_open_positionsDelete All Open Positions
- alpaca.delete_unsubscribe_accountDelete Unsubscribe Account
- alpaca.remove_asset_from_watchlistRemove Asset From Watchlist
- alpaca.remove_symbol_from_watchlistRemove Symbol From Watchlist
- alpaca.delete_all_orders_for_accountDelete All Orders for Account
Alpaca in three steps.
- 01Your users connect AlpacaThey sign in to Alpaca on Arc0 Connect, under your brand, and approve the access you ask for.
- 02You set the rulesReads run, writes like “create Watchlist” can wait for the user, and “delete Watchlist By ID” can be denied outright.
- 03Any agent can actYour agent calls Alpaca through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('alpaca', { read: 'allow', write: 'ask', // create_watchlist destructive: 'deny', // delete_watchlist_by_id }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Alpaca connects.
Users sign in to Alpaca on Arc0 Connect and approve the scopes you request. Build with Arc0’s Alpaca OAuth app, or bring your own so the Alpaca consent screen names you. Tokens refresh automatically, and you can export them whenever you want.
The same Alpaca connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key · OAuth 2.0
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Alpaca from any agent.
Alpaca and Arc0, answered.
Can I use Alpaca with Claude, ChatGPT or Cursor?
Yes. Connect Alpaca to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Alpaca actions you allow.
How do users connect Alpaca?
Users sign in to Alpaca on Arc0 Connect and approve the scopes you request. Build with Arc0’s Alpaca OAuth app, or bring your own so the Alpaca consent screen names you. Tokens refresh automatically, and you can export them whenever you want.
Which Alpaca actions can my agent take?
100 in total: 84 read, 10 write and 6 destructive, such as “create Watchlist”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Alpaca?
Yes. Actions like “delete Watchlist By ID” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Alpaca too?
Yes. The same Alpaca connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Alpaca into your agent.
Your users connect Alpaca once, under your brand. Your agent gets 100 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan