Connect an Alpaca paper account
The guided Connect wizard step by step. The four illustrated Alpaca steps, what Test connection checks before anything trades, and what you see once the book is linked.
- Who it is for
- New to Bellwether
- Reading time
- 8 min read
- Updated
Bellwether trades your own Alpaca paper account. You keep the account; Bellwether gets an API key pair for it (or, where the operator has enabled it, a sign-in token from Alpaca) and nothing else. It all happens on one , Connect your broker, which a new book opens on its own until a connection is verified. The wizard has five stops along the top: Broker · Set up · Test · How it trades · Done.
Broker
Pick the broker. Alpaca is the one you can connect today; Interactive Brokers, Schwab and Tradier are listed greyed out with the reason each is not ready, so you can see what is coming. Under the picker, What Bellwether will and won't do with these keys opens a short list: it will read the , place that passed every risk check (and your approval, above your threshold), and cancel its own unfilled orders when their window ends; it will never touch a , move money, show the secret to anyone, or change your Alpaca login. Press Set up Alpaca.
If this book is already connected, the same step shows what is connected (masked account, API keys or Sign in with Alpaca) with a Disconnect button. Disconnecting is a protected action and trading on the book stops until a new connection is verified; it is also the only way to rotate keys or switch between keys and signing in with Alpaca, because the server refuses a second connection while one exists.
Set up: four illustrated cards
Each card has a drawing of what you are looking for (ours, not a screenshot of Alpaca), one or two sentences, a "watch out" line where it matters, and a button that opens the right Alpaca page in a new tab. Back and Done, next move between cards; the dots show where you are.

- Create an Alpaca account at alpaca.markets. Free; no card and nothing to fund. If you already have a login, sign in and move on.
- Switch the dashboard to Paper. The Live / Paper switch is at the top of the Alpaca dashboard. Paper starts with $100,000 of simulated cash and real prices. Keys made on the Live tab do not work here: the trading service detects a live account and parks the connection on purpose.
- Generate API keys. On the Paper overview, the box called Your API Keys → Generate New Keys. You get an API Key ID (paper ones start with PK) and a Secret Key. The secret is shown once: copy both before you close the box; if you lose it, generate a new pair.
- Paste them here. The last card is the form, with Alpaca's exact field names. A Key ID with a space in it, one that starts with AK (a live key) or CK (an OAuth app's client id) is flagged under the field before anything is sent. There is no Paper / Live choice to make: paper or live is detected, not chosen. The trading service asks Alpaca which environment the keys belong to (paper first, then live) and labels the connection; a live account on this paper deployment is labelled live and parked, and nothing is ever placed with it. The will-and-won't list is here again. Press Test connection.
Test connection is a protected action, so it asks for your unless you entered one in the last 30 minutes. The API checks that both values are present and contain no spaces, seals the pair, stores it as pending and empties the form. It never contacts Alpaca itself and never echoes the secret: from here on every screen shows the key masked, as PK••7Q2M.
Connect with Alpaca (sign-in instead of keys)
When the operator has registered Bellwether as an Alpaca OAuth app on this deployment, cards 2 and 3 carry a "skip to Connect" line and the last card is titled Connect with Alpaca: a button sends you to Alpaca's own sign-in, you approve Bellwether for paper trading, and you come back to the wizard on the Test step with the connection already stored as pending. There are no keys to copy, and the token is sealed exactly like a key pair. Paste API keys instead stays underneath for anyone who prefers keys. If the button is not there, this deployment has not enabled it and keys are the way in. If Alpaca sends you back with a problem (you cancelled, the ten-minute link expired, the app is not configured), the last card says so in a sentence and offers the button again.
Test
Testing the connection with Alpaca… is the real check. The , the one process allowed to talk to the broker, picks up the pending connection on its next registry refresh (within about 30 seconds), opens the seal, works out which environment the credentials belong to (the paper endpoint first, then live), and asks Alpaca for the account and the market clock, read-only. The screen follows the verdict, usually in under half a minute:

- Connection works. A Detected: PAPER account ••… line states what the trading service found, then a card shows what it can see, and all it will ever show: the masked account number, the account type (Paper, simulated cash, detected), the status (Verified, ready to trade paper), what Alpaca says about the account (Account active once the first account sync has run, about a minute), equity and cash, the masked key, how it is connected, and the connection's name. If Alpaca reports the account as anything but active (a new account is occasionally held for review), a note says so: the keys work and the connection is saved, but Alpaca will refuse orders until the account is active. There is nothing to redo here. Press Continue: how it trades.
- The test failed. You are back on the paste card with a red fix card in plain language (what happened and the one thing to do about it) and the server's exact words folded under "Error details (for whoever runs your desk)". The cases and their fixes are on when the connection test fails.
If nothing happens for two minutes the page says so and offers Continue to the console: the trading service is down or restarting, not your keys. The check finishes on its own once the service is back. Closing the tab is safe too: opening Connect your broker again while a test is pending puts you straight back on this step instead of asking for the keys a second time.
How it trades
Two dials. : Conservative, Moderate (preselected; the code defaults) or Aggressive. : Manual (preselected; every order waits for you) or Semi-automatic (small orders go through on their own). Aggressive asks you to type AGGRESSIVE, Semi-automatic asks you to type MORE AUTONOMY, and either one asks for your authenticator code. Order caps, loss halts and the apply whichever you pick. Both dials can be changed later in the Profile section of Strategy; single limits are fine-tuned on Risk › Limits. A third question, Trading, has Start trading now preselected for a paper account (Keep it paused for now is the other choice). Press Save and start trading (it asks for your authenticator code) or, if you kept it paused, Save and finish.
Done
Confirms the posture, the autonomy and the trading choice you saved: Trading is on. Pause it any time from the top bar., or Trading is paused with a Start trading now button. Go to my Overview takes you to the Overview. The PM (shown as on screen) starts planning your book at the next scheduled session.
If you kept it paused
A book you kept paused does not trade: the desk plans for it and nothing is bought or sold. The Overview says so in one line, Trading is paused. The desk is planning but nothing will be bought or sold., with Start trading for the owner or an operator (it asks for your authenticator code); the top bar reads Paused and its Resume does the same. Risk shows the state and the history. Every order after that still passes the risk checks (your first day).
What Accounts shows afterwards
Accounts is one column, in this order:

- Your connection: the broker, a PAPER pill (the same pill sits in the top bar on every screen), the masked account number, how it is connected (API keys you pasted, with the masked Key ID, or Sign in with Alpaca), the date it was verified, and what the trading service last read from Alpaca: equity, cash and buying power, day trades in the last five sessions, and when it last synced (about once a minute; the API never calls the broker itself). Replace keys… goes to Connect your broker, where Disconnect and the paste card live; if the connection stops working the card says so in red and the button becomes Reconnect.
- Funding, read only: where cash stands and where transfers happen; see funding your account.
- Environment: paper, locked, with one paragraph on what going live involves (a deliberate ceremony run by the operator, never a switch on that screen) and a link to the go-live scorecard.
- Another account? Each brokerage account is its own book; Add a book… opens the same sheet as the book menu, and the new book starts on Connect with no connection until its keys verify.
The house book
On the house book, Connect shows "Nothing to connect": it trades with credentials configured on the server, selected at deploy time by pointing the broker setting at Alpaca with the environment left at paper. Those server credentials are the house book's alone: no other book can be pointed at them (the API, the database and the Executor each refuse it), so every other book is connected from its owner's own sign-in with its owner's own keys, and a new book has no connection at all until its owner's keys verify.
The environment check is not a one-off: the Executor repeats it every time it opens the book, so keys swapped behind the same connection, or a label changed by hand in the database, are caught before anything trades and the open is refused with the same alert. If you later generate new keys in Alpaca, the old pair stops working at once, the book halts, and Connect your broker opens with the fix for it (keys and safety).