> ## Documentation Index
> Fetch the complete documentation index at: https://api-portal.etoro.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Register OAuth application

> **Rate limit:** 60 requests per 60 seconds. This is the **default shared quota** — it is shared with every other endpoint that has no dedicated limit, so requests across those endpoints all draw from the same budget.

---

Creates a new OAuth application. The authenticated user automatically becomes the application admin. Both `clientId` and `clientSecret` are auto-generated server-side. The `clientSecret` is returned **only in this response** (one-time reveal) - subsequent reads will never expose it again, so callers must store it securely. Auto-populated defaults (audience, applicationType, supported flows, token expirations) come from service configuration. Validation is aligned with the upstream sts-metadata-api: `applicationName` max 100 chars, `applicationIconUrl` max 500 chars, each `redirectUri` max 500 chars and unique, each `scopeId` positive and recognized in the cached scope catalog.



## OpenAPI

````yaml /api-reference/openapi.json post /api/v1/sso/applications
openapi: 3.0.1
info:
  title: eToro Api
  version: v1.314.0
  description: >-
    eToro’s public API provides access to real-time financial data, trading
    insights, and account management features, allowing developers to integrate
    eToro’s services into their applications. With access to market prices,
    historical data, and social trading information, the API empowers users to
    enhance their trading strategies. Designed for security and scalability, the
    eToro API ensures smooth and reliable integration for a variety of financial
    applications.


    For more details on integrating with eToro's public WebSocket service,
    please refer to the dedicated [WebSocket
    documentation](./websocket/websocket-doc.html).
servers:
  - url: https://public-api.etoro.com
    description: eToro Public API
security: []
tags:
  - name: Agent Portfolios
  - name: Social Feeds
  - name: Balances
  - name: Clubs
  - name: Watchlists
  - name: Top Assets
  - name: Market Data
  - name: Identity
  - name: Cash Accounts
  - name: Transfer
  - name: Notifications
  - name: PI Data
  - name: PortfolioSearch
  - name: Price Alerts
  - name: SSO - Applications
  - name: SSO - Scopes
  - name: Sub-Accounts - eToro Trading
  - name: Sub-Accounts
  - name: Trading - Demo
  - name: Trading - Real
  - name: Users Info
  - name: Rankings
  - name: User Stats
  - name: Deprecated
paths:
  /api/v1/sso/applications:
    post:
      tags:
        - SSO - Applications
      summary: Register OAuth application
      description: >-
        **Rate limit:** 60 requests per 60 seconds. This is the **default shared
        quota** — it is shared with every other endpoint that has no dedicated
        limit, so requests across those endpoints all draw from the same budget.


        ---


        Creates a new OAuth application. The authenticated user automatically
        becomes the application admin. Both `clientId` and `clientSecret` are
        auto-generated server-side. The `clientSecret` is returned **only in
        this response** (one-time reveal) - subsequent reads will never expose
        it again, so callers must store it securely. Auto-populated defaults
        (audience, applicationType, supported flows, token expirations) come
        from service configuration. Validation is aligned with the upstream
        sts-metadata-api: `applicationName` max 100 chars, `applicationIconUrl`
        max 500 chars, each `redirectUri` max 500 chars and unique, each
        `scopeId` positive and recognized in the cached scope catalog.
      operationId: createApplications
      parameters:
        - name: x-request-id
          in: header
          required: true
          schema:
            type: string
            format: uuid
            example: ae0da95b-9c26-467f-ac70-7678ae407172
          description: A unique request identifier.
        - name: x-api-key
          in: header
          required: true
          schema:
            type: string
            format: password
            example: lhgfaslk21490FAScVPkdsb53F9dNkfHG4faZSG5vfjndfcfgdssdgsdHF4663
          description: API key for authentication.
        - name: x-user-key
          in: header
          required: true
          schema:
            type: string
            format: password
            example: >-
              eyJlYW4iOiJVbnJlZ2lzdGVyZWRBcHBsaWNhdGlvbiIsImVrIjoiOE5sZ2cwcW5EUVdROUFNWGpXT2lmOWktZnpidG5KcUlqWGJ3WHJZZkpZcldrbG90ZEhvLVBjSWhQaU8xU1ZtMW84aU1WZGZqN2xWNzFjLXFxLmcybXE1dnh4Q1hUT25xaWRUaTFlcEhmVk1fIn0_
          description: User-specific authentication key.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateApplicationBody'
            example:
              applicationName: My Trading App
              applicationIconUrl: https://cdn.etoro.com/icons/my-app.png
              scopes:
                - scopeId: 224
                  isMandatory: true
                - scopeId: 226
                  isMandatory: false
              redirectUris:
                - https://myapp.com/oauth/callback
      responses:
        '201':
          description: >-
            Application created successfully. The `clientSecret` is included
            once and only once.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreateApplicationResponse'
          headers:
            RateLimit-Limit:
              description: >-
                Maximum number of requests allowed per window. This is the
                default shared pool used by every endpoint without a dedicated
                limit, so it is NOT per-endpoint — requests across those
                endpoints all draw from this one budget.
              schema:
                type: integer
              example: 60
            RateLimit-Remaining:
              description: Requests remaining in the current window for this quota.
              schema:
                type: integer
            RateLimit-Reset:
              description: Seconds until the current window resets.
              schema:
                type: integer
            RateLimit-Policy:
              description: Quota policy in the form `<limit>;w=<window-seconds>`.
              schema:
                type: string
              example: 60;w=60
        '400':
          description: >-
            Validation error - missing required field, malformed URL, duplicate
            redirect URI, unknown scope id, or duplicate scope ids.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StsMetadataFrontApi_ErrorResponse'
        '401':
          description: Missing or invalid STS access token.
        '429':
          description: >-
            Too Many Requests — the shared rate limit (60 requests / 60s) was
            exceeded.
          headers:
            RateLimit-Limit:
              description: >-
                Maximum number of requests allowed per window. This is the
                default shared pool used by every endpoint without a dedicated
                limit, so it is NOT per-endpoint — requests across those
                endpoints all draw from this one budget.
              schema:
                type: integer
              example: 60
            RateLimit-Remaining:
              description: Requests remaining in the current window for this quota.
              schema:
                type: integer
            RateLimit-Reset:
              description: Seconds until the current window resets.
              schema:
                type: integer
            RateLimit-Policy:
              description: Quota policy in the form `<limit>;w=<window-seconds>`.
              schema:
                type: string
              example: 60;w=60
            Retry-After:
              description: Seconds to wait before retrying.
              schema:
                type: integer
              example: 60
        '500':
          description: Backend sts-metadata-api unavailable.
      security:
        - oauth2:
            - etoro-public:sso-applications:write
components:
  schemas:
    CreateApplicationBody:
      type: object
      required:
        - applicationName
        - applicationIconUrl
        - scopes
        - redirectUris
      properties:
        applicationName:
          type: string
          maxLength: 100
          description: Display name shown to end users in the OAuth consent screen.
          example: My Trading App
        applicationIconUrl:
          type: string
          format: uri
          maxLength: 500
          description: >-
            Publicly reachable URL of the application icon. Format-validated
            only - the URL is not fetched by the service.
          example: https://cdn.etoro.com/icons/my-app.png
        scopes:
          type: array
          minItems: 1
          description: >-
            Scopes that the application will request from end users. Each
            `scopeId` must be positive and present in the cached scope catalog.
            Duplicates are rejected.
          items:
            $ref: '#/components/schemas/ScopeItem'
        redirectUris:
          type: array
          uniqueItems: true
          minItems: 1
          description: >-
            OAuth redirect URIs registered for the application. Must be unique.
            Each URI is capped at 500 characters.
          items:
            type: string
            format: uri
            maxLength: 500
          example:
            - https://myapp.com/oauth/callback
    CreateApplicationResponse:
      type: object
      properties:
        application:
          $ref: '#/components/schemas/ApplicationItem'
        clientSecret:
          type: string
          format: uuid
          description: >-
            OAuth client secret. Returned exactly once at creation time and
            never again - store it securely.
    StsMetadataFrontApi_ErrorResponse:
      type: object
      properties:
        errorCode:
          type: string
          description: >-
            Machine-readable error code (e.g. `ScopeIdInvalid`,
            `ScopeIdsDuplicateItems`).
        errorMessage:
          type: string
          description: Human-readable error description.
    ScopeItem:
      type: object
      required:
        - scopeId
        - isMandatory
      properties:
        scopeId:
          type: integer
          minimum: 1
          description: >-
            Scope identifier. Must be a known scope from `GET
            /api/v1/sso/scopes`.
        isMandatory:
          type: boolean
          description: >-
            When true, the user cannot deselect this scope on the consent
            screen.
    ApplicationItem:
      type: object
      description: Full application record. The `clientSecret` is intentionally excluded.
      properties:
        applicationId:
          type: integer
          format: int64
          description: Internal numeric identifier of the application.
        applicationName:
          type: string
          description: Display name of the application.
        applicationIconUrl:
          type: string
          format: uri
          description: URL of the application icon.
        clientId:
          type: string
          format: uuid
          description: >-
            OAuth client identifier. Stable across the lifetime of the
            application.
        audience:
          type: string
          description: OAuth audience claim issued for tokens minted for this application.
        applicationType:
          type: string
          description: OAuth application type (e.g. `public`, `confidential`).
        scopes:
          type: array
          description: >-
            Scopes assigned to the application, including which are mandatory at
            consent time.
          items:
            $ref: '#/components/schemas/ApplicationScopeItem'
        redirectUris:
          type: array
          description: Registered OAuth redirect URIs.
          items:
            type: string
        supportedFlows:
          type: array
          description: >-
            OAuth flows supported by the application (e.g. `authorization_code`,
            `refresh_token`).
          items:
            type: string
        supportedCodeChallengeMethods:
          type: array
          description: >-
            PKCE code-challenge methods supported by the application (e.g.
            `S256`).
          items:
            type: string
        ssoIdTokenExpirationInMinutes:
          type: integer
          description: Lifetime of issued SSO id tokens, in minutes.
        ssoRefreshTokenExpirationInMinutes:
          type: integer
          description: Lifetime of issued SSO refresh tokens, in minutes.
        ssoAccessTokenExpirationInMinutes:
          type: integer
          description: Lifetime of issued SSO access tokens, in minutes.
        adminGcids:
          type: array
          description: GCIDs of users who can administer this application.
          items:
            type: integer
            format: int64
    ApplicationScopeItem:
      type: object
      description: Scope entry as returned in application reads.
      properties:
        scopeId:
          type: integer
          description: Scope identifier.
        isMandatory:
          type: boolean
          description: >-
            When true, the user cannot deselect this scope on the consent
            screen.
  securitySchemes:
    oauth2:
      type: oauth2
      description: >-
        eToro OAuth2. Each operation lists the scopes that grant access as
        separate `security` requirements (OpenAPI OR semantics): the caller's
        token only needs ONE of them — you do NOT need all of them. The same
        scopes back the x-api-key/x-user-key credential pair.
      flows:
        authorizationCode:
          authorizationUrl: ''
          tokenUrl: ''
          scopes:
            etoro-public:agent-portfolio:read: Grants access to the 'etoro-public:agent-portfolio:read' scope.
            etoro-public:agent-portfolio:write: Grants access to the 'etoro-public:agent-portfolio:write' scope.
            etoro-public:club:read: Grants access to the 'etoro-public:club:read' scope.
            etoro-public:demo:read: Grants access to the 'etoro-public:demo:read' scope.
            etoro-public:demo:write: Grants access to the 'etoro-public:demo:write' scope.
            etoro-public:feed:read: Grants access to the 'etoro-public:feed:read' scope.
            etoro-public:feed:write: Grants access to the 'etoro-public:feed:write' scope.
            etoro-public:market-data:read: Grants access to the 'etoro-public:market-data:read' scope.
            etoro-public:money.balance:read: Grants access to the 'etoro-public:money.balance:read' scope.
            etoro-public:money.cash-transactions:read: >-
              Grants access to the 'etoro-public:money.cash-transactions:read'
              scope.
            etoro-public:money.transfer:read: Grants access to the 'etoro-public:money.transfer:read' scope.
            etoro-public:money.transfer:write: Grants access to the 'etoro-public:money.transfer:write' scope.
            etoro-public:money:transfer: Grants access to the 'etoro-public:money:transfer' scope.
            etoro-public:notifications:read: Grants access to the 'etoro-public:notifications:read' scope.
            etoro-public:notifications:write: Grants access to the 'etoro-public:notifications:write' scope.
            etoro-public:pi-data:read: Grants access to the 'etoro-public:pi-data:read' scope.
            etoro-public:price-alerts:read: Grants access to the 'etoro-public:price-alerts:read' scope.
            etoro-public:price-alerts:write: Grants access to the 'etoro-public:price-alerts:write' scope.
            etoro-public:real:read: Grants access to the 'etoro-public:real:read' scope.
            etoro-public:real:write: Grants access to the 'etoro-public:real:write' scope.
            etoro-public:sso-applications:read: Grants access to the 'etoro-public:sso-applications:read' scope.
            etoro-public:sso-applications:write: Grants access to the 'etoro-public:sso-applications:write' scope.
            etoro-public:sso-scopes:read: Grants access to the 'etoro-public:sso-scopes:read' scope.
            etoro-public:sso-scopes:write: Grants access to the 'etoro-public:sso-scopes:write' scope.
            etoro-public:sub-accounts:read: Grants access to the 'etoro-public:sub-accounts:read' scope.
            etoro-public:sub-accounts:write: Grants access to the 'etoro-public:sub-accounts:write' scope.
            etoro-public:trade.demo:read: Grants access to the 'etoro-public:trade.demo:read' scope.
            etoro-public:trade.demo:write: Grants access to the 'etoro-public:trade.demo:write' scope.
            etoro-public:trade.real:read: Grants access to the 'etoro-public:trade.real:read' scope.
            etoro-public:trade.real:write: Grants access to the 'etoro-public:trade.real:write' scope.
            etoro-public:user-info:read: Grants access to the 'etoro-public:user-info:read' scope.
            etoro-public:watchlist:read: Grants access to the 'etoro-public:watchlist:read' scope.
            etoro-public:watchlist:write: Grants access to the 'etoro-public:watchlist:write' scope.

````