Create User Token (v2)
Rate limit: 60 requests per 60 seconds. This is the default shared quota — it is shared with every other endpoint that has no dedicated limit, so requests across those endpoints all draw from the same budget.
Creates a new user token for the specified agent-portfolio using scope names. Scopes are specified by name (scopeNames); scope ids are not supported in v2.
Authorizations
API key of the application. Only valid together with the x-user-key header — the pair is an alternative to OAuth bearer authentication, never sent alongside it. The pair is granted the same permissions the operation's OAuth scopes describe.
Demo credential for trying the API from these docs: lhgfaslk21490FAScVPkdsb53F9dNkfHG4faZSG5vfjndfcfgdssdgsdHF4663
User-specific authentication key. Only valid together with the x-api-key header — the pair is an alternative to OAuth bearer authentication, never sent alongside it.
Demo credential for trying the API from these docs: eyJlYW4iOiJVbnJlZ2lzdGVyZWRBcHBsaWNhdGlvbiIsImVrIjoiOE5sZ2cwcW5EUVdROUFNWGpXT2lmOWktZnpidG5KcUlqWGJ3WHJZZkpZcldrbG90ZEhvLVBjSWhQaU8xU1ZtMW84aU1WZGZqN2xWNzFjLXFxLmcybXE1dnh4Q1hUT25xaWRUaTFlcEhmVk1fIn0_
Headers
A unique request identifier.
"d4456b05-9f61-4e07-9f87-6fc250d9f83e"
Path Parameters
The unique identifier of the agent-portfolio.
Body
A human-readable name to identify the user token.
"my-trading-token"
The set of permission scope names to grant to this token. Available scopes: etoro-public:trade.real:read, etoro-public:trade.real:write, etoro-public:trade.demo:read, etoro-public:trade.demo:write.
An optional set of IPv4 addresses allowed to use this token.
An optional expiration date and time for the token in UTC.
"2026-12-31T23:59:59Z"
Response
User token created successfully
The unique identifier of the newly created user token.
"f9e8d7c6-b5a4-3210-fedc-ba9876543210"
The generated user token secret. Only available at creation time.
"sk_live_a1b2c3d4e5f6..."
The display name of the user token.
"my-trading-token"
The client identifier of the application the token is associated with.
"3fa85f64-5717-4562-b3fc-2c963f66afa6"
The IPv4 addresses from which the token is allowed to be used. Null or empty when unrestricted.
The authorized scope names granted to the token.
The UTC expiration date of the token. Null when the token does not expire.
"2026-12-31T23:59:59Z"
The UTC timestamp at which the token was created.
"2026-03-06T12:00:00Z"