Update OAuth application
Rate limit: 60 requests per 60 seconds. This is the default shared quota — it is shared with every other endpoint that has no dedicated limit, so requests across those endpoints all draw from the same budget.
Updates one or more modifiable fields of an existing OAuth application. Only the application’s admin (the caller’s GCID must be in adminGcids) can perform updates. Non-admins receive 404 Not Found (opaque authorization - the gateway does not disclose whether the application exists). At least one field must be provided in the body; omitted fields are left unchanged. Uniqueness and length constraints match the create endpoint.
Authorizations
eToro OAuth2. Each operation lists the scopes that grant access as separate security requirements (OpenAPI OR semantics): the caller's token only needs ONE of them — you do NOT need all of them. The same scopes back the x-api-key/x-user-key credential pair.
Headers
A unique request identifier.
"c2f6d728-b659-4c03-b20b-70306bf28417"
API key for authentication.
"lhgfaslk21490FAScVPkdsb53F9dNkfHG4faZSG5vfjndfcfgdssdgsdHF4663"
User-specific authentication key.
"eyJlYW4iOiJVbnJlZ2lzdGVyZWRBcHBsaWNhdGlvbiIsImVrIjoiOE5sZ2cwcW5EUVdROUFNWGpXT2lmOWktZnpidG5KcUlqWGJ3WHJZZkpZcldrbG90ZEhvLVBjSWhQaU8xU1ZtMW84aU1WZGZqN2xWNzFjLXFxLmcybXE1dnh4Q1hUT25xaWRUaTFlcEhmVk1fIn0_"
Path Parameters
The OAuth clientId of the application to update.
Body
At least one field must be provided. Omitted fields are left unchanged.
Updated display name.
100Updated icon URL.
500Replacement set of scopes. Each scopeId must be positive and present in the cached catalog; no duplicates.
Replacement set of redirect URIs.
500Response
Application updated successfully.
Full application record. The clientSecret is intentionally excluded.