Skip to main content
POST
Create User Token (v2)

Authorizations

x-api-key
string
header
default:lhgfaslk21490FAScVPkdsb53F9dNkfHG4faZSG5vfjndfcfgdssdgsdHF4663
required

API key of the application. Only valid together with the x-user-key header — the pair is an alternative to OAuth bearer authentication, never sent alongside it. The pair is granted the same permissions the operation's OAuth scopes describe.

Demo credential for trying the API from these docs: lhgfaslk21490FAScVPkdsb53F9dNkfHG4faZSG5vfjndfcfgdssdgsdHF4663

x-user-key
string
header
default:eyJlYW4iOiJVbnJlZ2lzdGVyZWRBcHBsaWNhdGlvbiIsImVrIjoiOE5sZ2cwcW5EUVdROUFNWGpXT2lmOWktZnpidG5KcUlqWGJ3WHJZZkpZcldrbG90ZEhvLVBjSWhQaU8xU1ZtMW84aU1WZGZqN2xWNzFjLXFxLmcybXE1dnh4Q1hUT25xaWRUaTFlcEhmVk1fIn0_
required

User-specific authentication key. Only valid together with the x-api-key header — the pair is an alternative to OAuth bearer authentication, never sent alongside it.

Demo credential for trying the API from these docs: eyJlYW4iOiJVbnJlZ2lzdGVyZWRBcHBsaWNhdGlvbiIsImVrIjoiOE5sZ2cwcW5EUVdROUFNWGpXT2lmOWktZnpidG5KcUlqWGJ3WHJZZkpZcldrbG90ZEhvLVBjSWhQaU8xU1ZtMW84aU1WZGZqN2xWNzFjLXFxLmcybXE1dnh4Q1hUT25xaWRUaTFlcEhmVk1fIn0_

Headers

x-request-id
string<uuid>
required

A unique request identifier.

Example:

"d4456b05-9f61-4e07-9f87-6fc250d9f83e"

Path Parameters

agentPortfolioId
string<uuid>
required

The unique identifier of the agent-portfolio.

Body

application/json
userTokenName
string
required

A human-readable name to identify the user token.

Example:

"my-trading-token"

scopeNames
string[]
required

The set of permission scope names to grant to this token. Available scopes: etoro-public:trade.real:read, etoro-public:trade.real:write, etoro-public:trade.demo:read, etoro-public:trade.demo:write.

Example:
ipsWhitelist
string[]

An optional set of IPv4 addresses allowed to use this token.

Example:
expiresAt
string<date-time>

An optional expiration date and time for the token in UTC.

Example:

"2026-12-31T23:59:59Z"

Response

User token created successfully

userTokenId
string<uuid>

The unique identifier of the newly created user token.

Example:

"f9e8d7c6-b5a4-3210-fedc-ba9876543210"

userToken
string

The generated user token secret. Only available at creation time.

Example:

"sk_live_a1b2c3d4e5f6..."

userTokenName
string

The display name of the user token.

Example:

"my-trading-token"

clientId
string<uuid>

The client identifier of the application the token is associated with.

Example:

"3fa85f64-5717-4562-b3fc-2c963f66afa6"

ipsWhitelist
string[]

The IPv4 addresses from which the token is allowed to be used. Null or empty when unrestricted.

Example:
scopeNames
string[]

The authorized scope names granted to the token.

Example:
expiresAt
string<date-time> | null

The UTC expiration date of the token. Null when the token does not expire.

Example:

"2026-12-31T23:59:59Z"

createdAt
string<date-time>

The UTC timestamp at which the token was created.

Example:

"2026-03-06T12:00:00Z"