Alpaca MCP Server
Alpaca’s official local MCP server for market data, account context, and controlled trading workflows in an AI client.
- Skill Road
- Alpaca MCP Server
Categories
Description
The Alpaca MCP Server is Alpaca’s official Model Context Protocol server for the Trading API and Market Data API. It connects an MCP-capable AI client to an Alpaca account so the client can request account information, positions, orders, and market data through structured tools. Depending on the enabled toolsets, the server can also change watchlists, create or cancel orders, close positions, and exercise option positions. This is a tool integration, not investment advice: neither the server nor Skill Road recommends securities, crypto assets, trading strategies, or expected returns. Alpaca states that insights generated by its MCP server and connected AI agents are educational and informational only; they do not replace independent review or professional advice.
Official product, repository, and scope
Alpaca’s official documentation describes setup, environment variables, toolsets, and supported clients. The public alpacahq/alpaca-mcp-server repository contains source code, the MIT license, tests, and local installation paths. Immediately before this seeder was created on September 8, 2026, GitHub reported exactly 952 stars for that specific repository. Stars are a point-in-time popularity signal, not evidence of security, quality, or suitability for a trading decision.
Alpaca does not provide its own hosted remote MCP endpoint. The official default path is therefore a local stdio process through uvx alpaca-mcp-server; the repository also documents a local Docker container. A person who needs a remote connector must host the server themselves in an appropriately secured environment. This entry is consequently classified as local, even though self-managed remote hosting may be technically possible.
Suitable analysis and automation tasks
According to Alpaca, the server exposes tools for account and portfolio information, open orders, positions, market hours, calendars, watchlists, corporate actions, and news. For stocks, crypto, and options, it can retrieve historical and current bars, quotes, trades, snapshots, and in some cases option chains with Greeks. That supports traceable analysis flows such as: read account status, ask for a description of a defined market-data slice, check the response against an independent source, and make any decision outside the client.
The trading toolsets go further. They can place, replace, or cancel orders, close or liquidate positions, and issue options instructions. Those calls are not a simulation when live access is configured. An LLM can misunderstand parameters, lack relevant context, or be misled by content in news, webpages, or prompts. Financial, legal, and operational responsibility remains entirely with the person who supplies credentials and confirms an action.
Start with paper; enable live deliberately
According to Alpaca, a paper-trading account is sufficient to begin. ALPACA_PAPER_TRADE is enabled by default; paper access does not use real money or transact in real securities in the market. Paper results are not evidence that an idea will work under live conditions, however. Market movements, liquidity, order priority, and execution delays can change real outcomes.
Live trading is enabled only when ALPACA_PAPER_TRADE=false is set and appropriate live API keys are configured. That switch deserves an explicit check in the client configuration, not merely a casual prompt confirmation. Use separate paper and live keys, start with restricted toolsets, and require a deliberate human approval before every write action. A prompt such as “buy,” “sell,” “close,” or “liquidate” should never be the sole authorization.
Keys, permissions, and confirmations
Configuration requires ALPACA_API_KEY and ALPACA_SECRET_KEY in the MCP client’s environment block. Alpaca explicitly says never to paste keys into chat. Store them only in the intended client environment or an operating-system secret store, never in a repository, shared MCP file, screenshot, or prompt template. If a leak is suspected, revoke or rotate keys in the Alpaca dashboard and reconnect with new credentials.
All toolsets are enabled by default. For analysis without trading authority, Alpaca’s documentation supports a narrow ALPACA_TOOLSETS selection such as account,stock-data,crypto-data,options-data,news. Leave out trading until there is a verified need. Also limit who can read the local configuration. Tool results go to the connected AI client and may be forwarded to a model provider depending on that client’s architecture; review that provider’s data policy separately.
Security limits and FAQ
Is this investment advice? No. The server provides API tools and data; it makes no investment recommendations and promises no outcomes. Historical data, model analysis, and hypothetical backtests do not guarantee future results.
Can an AI cause real trades? Yes, when live keys, ALPACA_PAPER_TRADE=false, and write-enabled toolsets are active. Review every proposed order, symbol, side, quantity, order type, and the correct environment before an independent confirmation.
How should I start safely? Use a separate paper account, minimum read-focused toolsets, and one account-balance or data query. Only after the configuration is verified should a small, deliberately confirmed paper test follow.
Requirements
Python 3.10+, uv/uvx, an MCP-capable client, and Alpaca API keys; separate paper-trading keys for a safer start.
Installation instructions
Configure the local stdio server as uvx alpaca-mcp-server, set ALPACA_API_KEY and ALPACA_SECRET_KEY only in the environment block, and start with paper keys. Limit ALPACA_TOOLSETS to read-focused toolsets for analysis; never store keys in chats or configuration repositories.
uvx alpaca-mcp-server
Authentication
Alpaca API key and secret key in the MCP client environment block. Paper trading is enabled by default; live trading requires separate live keys and ALPACA_PAPER_TRADE=false.
Required access permissions
All toolsets are enabled by default. Restrict ALPACA_TOOLSETS to read-focused tools; enable the trading toolset only with a deliberate human approval process.
Transmitted or stored data
The local server processes credentials and returns account, portfolio, and market data to the connected AI client. That client may forward tool results to its model provider; review that provider’s data policy separately.
Security risks
Live keys and write-enabled tools can trigger real orders, cancellations, position closures, or options instructions. Do not share keys, keep paper and live separate, minimize toolsets, and independently review and confirm every action.
License and costs
- License
- MIT
- Cost
- free
The server is MIT licensed. Alpaca says a paper-trading account is sufficient to start; review current usage, data, and account terms in Alpaca’s official documentation. This entry contains no pricing figures.
Alternatives
Not recorded yet.
At a glance
- Provider
- Alpaca
- Status
- Official server
- Deployment
- Local
- Current version
- 2
- GitHub stars
- 994
- Last reviewed
- 08.09.2026
Repository and documentation
Categories
Supported clients
Related guides
Guides and background related to this entry.
Set up Mapbox MCP Server
Set up the Mapbox MCP Server: hosted endpoint or local token, a first test, and sensible limits.
30.09.2026
Set up the Asana plugin for Claude Code
Create your own Asana OAuth app, install the Claude Code plugin, and connect to Asana's V2 MCP server via /asana-setup.
30.09.2026
Setting up the Zernio MCP Server
Connect the Zernio MCP Server via OAuth or an API key, link social accounts, and deliberately safeguard write access to posts, inboxes, and ad campaigns.
28.09.2026
Setting up the Intercom MCP Server
Connect the Intercom MCP Server via OAuth or a bearer token, choose the correct regional endpoint, and deliberately safeguard write access to articles and notes.
23.09.2026