v1

latestOpenAPI 3.0.12026-07-26171200932.8 KB
Sub-Accounts - eToro Trading

Create Sub-Account User Token

Rate limit: 60 requests per 60 seconds. This is the default shared quota — it is shared with every other endpoint that has no dedicated limit, so requests across those endpoints all draw from the same budget.


Generates a non-interactive user token for the sub-account identified by the x-sub-account-id header. The secret token value is returned only once, in this response.

post/api/v1/sub-accounts/etoro-trading/user-tokens

Headers

x-request-idstring uuid required
Example:49f8ed4f-6d94-481e-82eb-ff308c61fdcd

A unique request identifier.

x-api-keystring password required
Example:lhgfaslk21490FAScVPkdsb53F9dNkfHG4faZSG5vfjndfcfgdssdgsdHF4663

API key for authentication.

x-user-keystring password required
Example:eyJlYW4iOiJVbnJlZ2lzdGVyZWRBcHBsaWNhdGlvbiIsImVrIjoiOE5sZ2cwcW5EUVdROUFNWGpXT2lmOWktZnpidG5KcUlqWGJ3WHJZZkpZcldrbG90ZEhvLVBjSWhQaU8xU1ZtMW84aU1WZGZqN2xWNzFjLXFxLmcybXE1dnh4Q1hUT25xaWRUaTFlcEhmVk1fIn0_

User-specific authentication key.

x-sub-account-idstring required

The encrypted sub-account identifier. The backend validates that it decrypts to a sub-account owned by the caller's token gcid and generates the token for the sub-account's gcid.

Request body

userTokenNamestring required

A friendly display name for the user token.

scopeNamesstring[] required

The scope names to assign. Must be a subset of the scopes returned by GET /api/v1/sub-accounts/etoro-trading/user-tokens/scopes.

ipsWhiteliststring[]

An optional IPv4 whitelist for the token.

expiresAtstring date-time

An optional UTC expiration for the token.

Example request

{
  "userTokenName": "my-trading-bot",
  "scopeNames": [
    "etoro-public:trade.real:read",
    "etoro-public:trade.real:write"
  ],
  "ipsWhitelist": [
    "192.168.1.1"
  ],
  "expiresAt": "2026-12-31T23:59:59Z"
}

Response

User token created successfully

userTokenIdstring uuid

The unique identifier of the created user token.

userTokenstring

The secret token value. Returned only once, on creation.

userTokenNamestring

The friendly display name assigned to the token.

clientIdstring uuid

The OAuth client id associated with the token.

ipsWhiteliststring[]

The IPv4 addresses the token is restricted to, if any.

expiresAtstring date-time nullable

The UTC expiration of the token, if one was set.

createdAtstring date-time

When this user token was created.

Example response

{
  "userTokenId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
  "userToken": "ut_live_9f8c7b6a5d4e3f2a1b0c",
  "userTokenName": "my-trading-bot",
  "clientId": "7c9e6679-7425-40de-944b-e07fc1f90ae7",
  "ipsWhitelist": [
    "192.168.1.1"
  ],
  "scopes": [
    {
      "name": "etoro-public:trade.real:read"
    }
  ],
  "expiresAt": "2026-12-31T23:59:59Z",
  "createdAt": "2026-06-06T10:15:00Z"
}