v1

latestOpenAPI 3.0.12026-07-26171200932.8 KB
Sub-Accounts - eToro Trading

Update Sub-Account User Token

Rate limit: 60 requests per 60 seconds. This is the default shared quota — it is shared with every other endpoint that has no dedicated limit, so requests across those endpoints all draw from the same budget.


Updates an existing sub-account user token's scopes, IP whitelist, or expiration. At least one field must be provided.

patch/api/v1/sub-accounts/etoro-trading/user-tokens/{userTokenId}

Path parameters

userTokenIdstring uuid required

The unique identifier of the user token to update.

Headers

x-request-idstring uuid required
Example:a8927d55-9710-4595-be73-db18005119ec

A unique request identifier.

x-api-keystring password required
Example:lhgfaslk21490FAScVPkdsb53F9dNkfHG4faZSG5vfjndfcfgdssdgsdHF4663

API key for authentication.

x-user-keystring password required
Example:eyJlYW4iOiJVbnJlZ2lzdGVyZWRBcHBsaWNhdGlvbiIsImVrIjoiOE5sZ2cwcW5EUVdROUFNWGpXT2lmOWktZnpidG5KcUlqWGJ3WHJZZkpZcldrbG90ZEhvLVBjSWhQaU8xU1ZtMW84aU1WZGZqN2xWNzFjLXFxLmcybXE1dnh4Q1hUT25xaWRUaTFlcEhmVk1fIn0_

User-specific authentication key.

x-sub-account-idstring required

The encrypted sub-account identifier. The backend validates that it decrypts to a sub-account owned by the caller's token gcid.

Request body

scopeNamesstring[]

The replacement scope names. When provided, must be a subset of the scopes returned by GET /api/v1/sub-accounts/etoro-trading/user-tokens/scopes.

ipsWhiteliststring[]

The replacement IPv4 whitelist.

expiresAtstring date-time

The replacement UTC expiration.

Example request

{
  "scopeNames": [
    "etoro-public:trade.real:read"
  ],
  "ipsWhitelist": [
    "192.168.1.1"
  ],
  "expiresAt": "2026-12-31T23:59:59Z"
}

Response

User token updated successfully