Alpaca
Connect Alpaca
Sign in to connect your exchange and track your portfolio automatically
Alpaca at a Glance
Key facts about Alpaca compiled from verified market data and CoinGecko's exchange registry. These metrics help you evaluate liquidity, regulatory footprint and operational maturity before connecting a portfolio.
- Trust Score
- 0/10
- Available in
- 1 jurisdictions
- Trading incentives
- Not offered
- CCXT integration
- Supported
- alpaca
Trading access & integration
Alpaca is wired into Mantapex through the CCXT integration layer, so importing balances and trade history into a read-only portfolio requires an API key and a secret that you generate inside your own Alpaca account. Because Mantapex never custodies your funds, the keys you create should be scoped to read access only — withdrawal, transfer and trading permissions are unnecessary for portfolio tracking and should remain disabled.
Connection metadata is read directly from Mantapex's CCXT integration manifest — credential requirements reflect what Alpaca itself exposes to read-only API consumers and may evolve as the venue updates its API.
Getting Started with Alpaca
- Log in to your Alpaca Trading API account.
- Obtain API Keys: After logging in, navigate to the “Home” section to generate your API Key and Secret API Key. Note: It’s important to write down or save your Secret Key, as you will only have access to it once.
Account, custody & security on Alpaca
Alpaca operates as a custodial trading venue: when you fund an account, the deposited assets are held in wallets controlled by the exchange and credited to your balance as a book-entry until you withdraw them. That trade-off — convenience and order-book liquidity in exchange for counterparty risk — is the central design choice of every centralised exchange and is what makes platform-level security so important to evaluate. Year of incorporation is not published in our index for Alpaca, so we cannot quote an exact operational tenure here — the venue's own About page is the authoritative reference.
Almost every major centralised exchange — including Alpaca — operates under some form of KYC ("Know Your Customer") and AML ("Anti-Money-Laundering") obligations imposed by the jurisdiction it serves. Jurisdictional details for Alpaca are not surfaced in our index, so consult the exchange's own Terms of Service and Help Centre for the canonical KYC matrix. Expect to provide a government-issued ID document and a recent proof-of-address at minimum; higher verification tiers may add liveness checks, source-of-funds questionnaires and accredited-investor confirmations.
For the specific case of connecting Alpaca to Mantapex, the additional hardening layer is straightforward: generate a dedicated API key for read-only portfolio sync, label it clearly (for example "Mantapex read-only sync"), disable every permission except the minimum the exchange exposes for balance and trade-history queries, and store the secret in a password manager so you can rotate it on a schedule. If Alpaca supports IP whitelisting and you connect from a stable address, restrict the key to that address. If you ever stop using Mantapex — or any other third-party dashboard — revoke the key on the exchange side rather than just deleting it from the dashboard, because the credential continues to authenticate against Alpaca's API until Alpaca itself invalidates it.
How to connect any exchange securely
Enable two-factor authentication on the exchange account itself before generating any API keys. The strongest options are hardware security keys (FIDO2 / WebAuthn devices such as YubiKey or Solo) where supported, followed by an authenticator app on a dedicated device (Aegis, Raivo, 1Password, or Google Authenticator); SMS-based 2FA is the weakest common method because of SIM-swap risk. Keep the recovery phrase or backup codes in offline cold storage rather than the same password manager you sign in with. Where the venue offers a withdrawal-address whitelist, turn it on: it shrinks the blast radius of a stolen key or hijacked session because funds can only leave to a pre-approved address after a cool-down. Pair that with anti-phishing codes, a dedicated email account, and alerts for new logins, withdrawal requests and API-key creation — most exchange-related losses originate from compromised individual accounts, not platform-wide breaches.
Security guidance on this page is generic exchange hardening that applies to every centralised crypto venue. For Alpaca's exchange-specific policies — fund-segregation model, proof-of-reserves cadence, insurance coverage and incident-response history — the canonical references are Alpaca's own Help Centre and any audit reports or attestations the venue publishes directly.
API access details for Alpaca
Connecting Alpaca as a read-only portfolio source on Mantapex relies on the credentials defined by Alpaca's own API. The matrix below mirrors exactly what the CCXT integration layer asks for — ticked rows mean the field is required to authenticate, untouched rows mean Alpaca doesn't ask for that field at all.
In short, Alpaca requires 2 credentials to authenticate API requests: API key and API secret. All of these are generated from inside the exchange's own dashboard — Mantapex never asks you to share your account password or to set up an API key with withdrawal permissions enabled.
When you create the key on Alpaca for use with Mantapex, restrict its permissions to read-only access (sometimes labelled "view", "read", "query" or "info"). Mantapex only needs to fetch balances, trade history and open positions. Withdrawal, trade-execution and transfer scopes should remain disabled. If Alpaca offers a granular permission model, the safest combination is: enable "Read" or "View", disable "Trade" or "Spot trade", disable "Withdraw" or "Universal Transfer", and leave any margin / futures permission switched off unless you specifically want those positions visible inside your portfolio dashboard.
Some exchanges — Binance, OKX, Bybit, Bitget, KuCoin and several Asia-Pacific venues — offer an optional IP whitelist when you create the API key. Leaving the whitelist empty lets the key authenticate from any address, which is the simplest setup for use with a cloud-hosted dashboard such as Mantapex. If Alpaca forces you to enter at least one IP and you don't have a static address, you can usually use a placeholder value the exchange recognises (for example "0.0.0.0/0" or the wildcard option) — consult Alpaca's API documentation before relying on that workaround. Either way, the credentials remain in a read-only scope and cannot be used to move funds off the venue.
Credential schema sourced directly from the CCXT integration manifest used by Mantapex. Alpaca may rotate or extend its API in the future — if the exchange asks for a credential not listed here when you create the key, you can safely ignore it for the purpose of a read-only Mantapex import.
Official resources & community for Alpaca
The links below point to first-party Alpaca properties. We track them so you can verify announcements, support channels and operator-published policies directly at the source rather than from third-party copies. External destinations open in a new tab and are marked nofollow per our resource-link policy.
Related exchanges & comparisons
Top exchanges by trust score
Peer sets sourced from CoinGecko's trust-score ranking and CCXT's exchange manifest. Inclusion here is not an endorsement — it simply means Mantapex tracks the venue with current trust / volume data.
Recent Alpaca news
Latest reporting from major crypto news outlets covering Alpaca.
- The Currency Analytics
Alpaca Lands $435 Million Backed by Kraken's Parent and BMO
- Crypto Daily
Alpaca Raises $135M for Tokenized Stock Infrastructure
Alpaca's $135M raise pushes tokenized stocks into production, as DTCC confirms live trades. Total financing hits $435M with Kraken/BMO debt.
- Crypto Economy
Alpaca pulls $135M to expand exchange rails for onchain stocks
Alpaca raised $135 million in equity unding led by Peak XV to expand infrastructure for tokenized stocks and onchain brokerage services. Debt financing from Payward and BMO could…
- Crypto Briefing
Alpaca raises $135 million to build AI agent trading infrastructure across crypto and traditional markets
AI-driven trading infrastructure could revolutionize market dynamics, enhancing efficiency and accessibility across diverse financial assets. Alpaca raises $135 million to build…
- Coindesk
Crypto brokerage firm Alpaca raises $135 million for tokenized stock infrastructure
The company at one pointed cleared or custodied roughly 94% of tokenized U.S. equities, now holding over $1.5 billion in underlying stocks for its partners.
- Cointelegraph
Alpaca raises $135M to fund tokenized agent-first infrastructure
The BNP-backed brokerage infrastructure provider is expanding into tokenized markets and AI-native financial services as both DeFi and TradFi companies pursue onchain business.
- Crypto Briefing
Alpaca raises $435M to explore prime broking entry as AI trading volume surges 4x
Alpaca's expansion into prime brokerage could disrupt traditional financial institutions, leveraging AI-driven trading to reshape market dynamics. Alpaca raises $435M to explore…
- CrowdFundInsider
Alpaca Enhances Access to US Markets with Stablecoin Funding for Securities and Crypto Trading
Alpaca has indicated that stablecoins have evolved into essential infrastructure for global investors seeking efficient entry into traditional financial markets.
Data Disclaimer
Exchange data is sourced from third-party providers and may not reflect real-time conditions.
Your Exchange Portfolio — Free Forever
Connect read-only API keys to see balances, orders & trade history. Mix with wallets, Polymarket & Kalshi — one portfolio for everything.
