Alpaca MCP server alternatives
Alpaca shipped the first official brokerage MCP server and it is still the most readable one. People look past it for one of three reasons: it wants an API key and secret in your client config, it documents no cap on an order, and custody sits in a US brokerage account.
What the Alpaca MCP server does well
The oldest brokerage server in our comparison by about two months, MIT licensed with 962 stars, and you can read the whole thing before you run it, which is true of almost nothing else that places real orders. If none of the three walls below is your problem, there is no reason to move.
The limit people run into
An API key and secret live in your client config, no per-order cap is documented, and custody is at Alpaca Securities, a US broker-dealer. The availability of the server itself is not documented anywhere we could find.
Five alternatives
1Kraken CLI
The closest like-for-like swap if you liked the shape rather than the broker: open source, MIT, a CLI with the MCP server built in, and a local paper-trading engine needing no credentials. It reaches further than Alpaca, adding futures, forex, staking and the xStocks tokenized equities. Two of your three walls remain: a key and secret on disk, and Kraken holding the funds.
Kraken MCP docs2tastytrade MCP
The answer if the missing cap was the problem. Its order tools refuse to act without a token from their own dry-run, single use, expiring in 60 seconds and bound to the arguments and the endpoint, so you cannot dry-run one share and submit a thousand. That is the only confirmation step in our comparison the server enforces rather than asks of the model. US equities and options only.
GitHub repo3Webull
The other answer to the missing cap, and the only brokerage product in our comparison documenting order size and value caps together with a symbol allow-list. Work out which Webull you are using: three share the name and the hosted cloud server cannot place an order.
Webull agentic trading4Gate MCP
The answer if the key on disk was the problem and you will move from equities to crypto. It authorises over OAuth2 with scopes, and it is the only exchange server here with a separate read-only scope, so you can grant market data and withhold trading. Still custodial, still no cap on a single order.
GitHub repo5FensoryOurs
Ours, fifth, and read this first: we are not available to US persons, and an Alpaca user is quite likely American. For everyone else, a hosted server with no key in a file, and a cap, allow-list and kill-switch enforced on the account rather than asked of the model, so an order above the cap is rejected rather than trimmed. The instrument differs too: tokenized US equities, not the shares Alpaca sells you, and a tokenized stock is not a share.
The Fensory MCP server
Side by side
| Option | Who holds the funds | What stops a bad order | What it trades | Where you can open it |
|---|---|---|---|---|
| Kraken CLI | Kraken | Service-group gating, a dangerous-operation acknowledgement the CLI enforces itself, and position limits set at the API-key level | Spot, perpetual and dated futures, xStocks tokenized equities, forex, staking | Not stated in the MCP documentation |
| tastytrade MCP | tastytrade, in your brokerage account | The most enforced confirmation in this comparison. The five order-submitting tools refuse to act without a token from their own dry-run; the token is single-use, expires in 60 seconds, and is bound to the arguments and the endpoint, so you cannot dry-run one share and submit a thousand. Under it sit per-leg quantity checks against the account’s own ceilings, a notional cap on buying-power impact, and a refusal to send orders into frozen or closing-only accounts | US equities and options | United States. A US brokerage account is required |
| Webull | Webull Financial | Order size and value caps, a symbol allow-list, an optional read-only mode, order preview and disconnect | Equities, options, futures, event contracts and crypto | US at launch. The self-hosted server documents nine regions including the UK, Japan and Singapore |
| Gate MCP | Gate, in your exchange account. The DEX surface is a separate wallet | The scopes are the control, and they are the only ones here shaped like ours. Five of them: market for public data, profile for read-only account access, trade before any order can be placed, account for the unified and sub-accounts, and wallet, which covers transfers, deposits and withdrawals. No cap on the size of a single order | Crypto spot, futures, options, delivery, margin, earn, plus DEX swaps across 20+ chains | Not documented on the repository |
| Fensory | You. Tokens settle to a wallet you control, perp margin sits at the venue | Kill-switch, market allow-list and a per-order cap, all enforced on the account. An order above the cap is rejected rather than trimmed | Tokenized US equities and treasuries, gold, crypto spot, perpetual futures | Not available to US persons |
Questions people ask
- Can I use the Alpaca MCP server outside the United States?
- Alpaca does not document geographic availability for the MCP server, so we cannot tell you from its documentation. What is documented is that custody sits at Alpaca Securities, a US broker-dealer, and that a brokerage account is required. Treat the absent country list as a question for Alpaca, not a yes.
- Do any of these stop an order that is too large?
- Two. Webull documents order size and value caps plus a symbol allow-list, and Fensory rejects an order above a per-order cap. tastytrade requires a dry-run confirmation token before submission, which confirms an order but does not set a dollar ceiling. Kraken and Gate rely on key-level settings; Alpaca documents no comparable size cap.
- Which of these avoid a key in a file?
- Gate authorises over OAuth2 with scopes and Fensory over OAuth. Kraken and Alpaca both want a key and secret on disk. tastytrade sits in between, with an OAuth client and refresh token plus a guard against sending them to an unrecognised host.
- Every fact in the table is pulled from our MCP server comparison by reference rather than retyped, so a cell here cannot disagree with the same cell there. Only the paragraph explaining each swap is written for this page.
- Five options, not a ranked field. Kraken is first because it is closest to what an Alpaca user was already doing; the rest by which wall each answers.
- Fensory publishes this page and is on it, fifth. We cannot serve a US reader at all, and the entry says so in its first line.