Market-data vendors and BYOK
In plain English: AlphaSwarm pulls market prices from outside companies (vendors) like Alpaca and Interactive Brokers. Two things used to be fragile about that: vendor-specific code was scattered across the platform (so swapping or upgrading a vendor meant hunting down every copy), and vendor passwords/API keys sometimes travelled in process environment variables (visible to anything running in the same process). The August 2026 refactor fixed both — vendor code now lives in exactly one place per vendor, and keys are fetched on demand from the platform's credential vault ("bring your own key") instead of being baked into worker environments.
Vendor homes
Every Alpaca and IBKR entry point — trading feeds, Kafka ingesters,
brokerages, backtest data handlers, historical fetches — now constructs
its vendor SDK client through a shared factory under
alphaswarm/streaming/vendors/:
| Vendor home | Wraps |
|---|---|
alpaca_ws.py | alpaca-py StockDataStream (live websocket) |
alpaca_historical.py | alpaca-py StockHistoricalDataClient |
ibkr_client.py | ib_async clients (live + historical) |
A CI guard (scripts/ci/allowlists/vendor_sdk_homes.txt) forbids vendor
SDK imports anywhere outside the allowlisted homes, and the legacy
ib_insync package is banned outright. If you need a vendor client,
import the home — never the SDK.
Why it matters:
- One choke point per vendor for retry policy, rate limiting, session parameters, and credential resolution.
- Swappability: the strangler pattern used here (new homes wrap old call sites, then call sites collapse onto the homes) is the template for onboarding the next vendor.
- Paper isn't throttled like live: the paper brokerage now uses unlimited-rate paper capabilities instead of inheriting live rate-limit models.
BYOK credential resolution ("Rule 55")
Vendor and broker keys resolve through the CredentialResolver chain
(BrokerCredentialStore and friends) before any settings fallback.
In practice:
- Money-plane workers no longer need
ALPHASWARM_*_API_KEYvariables in their process environment. - Databento and Alpha Vantage keys moved to file mounts under
/var/run/secrets(seealphaswarm/data/sources/databento/_credentials.py). - IBKR Gateway session parameters support per-tenant BYOK, so each organization can bring its own brokerage credentials rather than sharing platform-level keys.
See Credentials for the full resolver chain and store priorities.
Config hydration schemes
Related hygiene work: hydrate:// config references are now dispatched
through a scheme registry (ssm, env, file, k8s-secret,
vault) instead of a string-prefix check — an unregistered scheme
raises instead of silently passing through. See
scripts/ci/_hydration.py.
See also
- Credentials — the CredentialResolver chain BYOK rides on.
- Streaming governance — how vendor data gets onto Kafka topics with schema governance.
- Connector control plane — onboarding and governing data connectors.
- Add a new provider — the operational recipe for wiring a new data source.