Saltar al contenido principal

Market-data vendors and BYOK

In plain English: AlphaSwarm pulls market prices from outside companies (vendors) like Alpaca and Interactive Brokers. Two things used to be fragile about that: vendor-specific code was scattered across the platform (so swapping or upgrading a vendor meant hunting down every copy), and vendor passwords/API keys sometimes travelled in process environment variables (visible to anything running in the same process). The August 2026 refactor fixed both — vendor code now lives in exactly one place per vendor, and keys are fetched on demand from the platform's credential vault ("bring your own key") instead of being baked into worker environments.

Vendor homes​

Every Alpaca and IBKR entry point — trading feeds, Kafka ingesters, brokerages, backtest data handlers, historical fetches — now constructs its vendor SDK client through a shared factory under alphaswarm/streaming/vendors/:

Vendor homeWraps
alpaca_ws.pyalpaca-py StockDataStream (live websocket)
alpaca_historical.pyalpaca-py StockHistoricalDataClient
ibkr_client.pyib_async clients (live + historical)

A CI guard (scripts/ci/allowlists/vendor_sdk_homes.txt) forbids vendor SDK imports anywhere outside the allowlisted homes, and the legacy ib_insync package is banned outright. If you need a vendor client, import the home — never the SDK.

Why it matters:

  • One choke point per vendor for retry policy, rate limiting, session parameters, and credential resolution.
  • Swappability: the strangler pattern used here (new homes wrap old call sites, then call sites collapse onto the homes) is the template for onboarding the next vendor.
  • Paper isn't throttled like live: the paper brokerage now uses unlimited-rate paper capabilities instead of inheriting live rate-limit models.

BYOK credential resolution ("Rule 55")​

Vendor and broker keys resolve through the CredentialResolver chain (BrokerCredentialStore and friends) before any settings fallback. In practice:

  • Money-plane workers no longer need ALPHASWARM_*_API_KEY variables in their process environment.
  • Databento and Alpha Vantage keys moved to file mounts under /var/run/secrets (see alphaswarm/data/sources/databento/_credentials.py).
  • IBKR Gateway session parameters support per-tenant BYOK, so each organization can bring its own brokerage credentials rather than sharing platform-level keys.

See Credentials for the full resolver chain and store priorities.

Config hydration schemes​

Related hygiene work: hydrate:// config references are now dispatched through a scheme registry (ssm, env, file, k8s-secret, vault) instead of a string-prefix check — an unregistered scheme raises instead of silently passing through. See scripts/ci/_hydration.py.

See also​