> ## Documentation Index
> Fetch the complete documentation index at: https://api-portal.etoro.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update OAuth application

> **Rate limit:** 60 requests per 60 seconds. This is the **default shared quota** — it is shared with every other endpoint that has no dedicated limit, so requests across those endpoints all draw from the same budget.

---

Updates one or more modifiable fields of an existing OAuth application. Only the application's admin (the caller's GCID must be in `adminGcids`) can perform updates. Non-admins receive `404 Not Found` (opaque authorization - the gateway does not disclose whether the application exists). At least one field must be provided in the body; omitted fields are left unchanged. Uniqueness and length constraints match the create endpoint.



## OpenAPI

````yaml /api-reference/openapi.json put /api/v1/sso/applications/{clientId}
openapi: 3.0.1
info:
  title: eToro Api
  version: v1.314.0
  description: >-
    eToro’s public API provides access to real-time financial data, trading
    insights, and account management features, allowing developers to integrate
    eToro’s services into their applications. With access to market prices,
    historical data, and social trading information, the API empowers users to
    enhance their trading strategies. Designed for security and scalability, the
    eToro API ensures smooth and reliable integration for a variety of financial
    applications.


    For more details on integrating with eToro's public WebSocket service,
    please refer to the dedicated [WebSocket
    documentation](./websocket/websocket-doc.html).
servers:
  - url: https://public-api.etoro.com
    description: eToro Public API
security: []
tags:
  - name: Agent Portfolios
  - name: Social Feeds
  - name: Balances
  - name: Clubs
  - name: Watchlists
  - name: Top Assets
  - name: Market Data
  - name: Identity
  - name: Cash Accounts
  - name: Transfer
  - name: Notifications
  - name: PI Data
  - name: PortfolioSearch
  - name: Price Alerts
  - name: SSO - Applications
  - name: SSO - Scopes
  - name: Sub-Accounts - eToro Trading
  - name: Sub-Accounts
  - name: Trading - Demo
  - name: Trading - Real
  - name: Users Info
  - name: Rankings
  - name: User Stats
  - name: Deprecated
paths:
  /api/v1/sso/applications/{clientId}:
    put:
      tags:
        - SSO - Applications
      summary: Update OAuth application
      description: >-
        **Rate limit:** 60 requests per 60 seconds. This is the **default shared
        quota** — it is shared with every other endpoint that has no dedicated
        limit, so requests across those endpoints all draw from the same budget.


        ---


        Updates one or more modifiable fields of an existing OAuth application.
        Only the application's admin (the caller's GCID must be in `adminGcids`)
        can perform updates. Non-admins receive `404 Not Found` (opaque
        authorization - the gateway does not disclose whether the application
        exists). At least one field must be provided in the body; omitted fields
        are left unchanged. Uniqueness and length constraints match the create
        endpoint.
      operationId: updateApplicationsByClientId
      parameters:
        - name: x-request-id
          in: header
          required: true
          schema:
            type: string
            format: uuid
            example: c2f6d728-b659-4c03-b20b-70306bf28417
          description: A unique request identifier.
        - name: x-api-key
          in: header
          required: true
          schema:
            type: string
            format: password
            example: lhgfaslk21490FAScVPkdsb53F9dNkfHG4faZSG5vfjndfcfgdssdgsdHF4663
          description: API key for authentication.
        - name: x-user-key
          in: header
          required: true
          schema:
            type: string
            format: password
            example: >-
              eyJlYW4iOiJVbnJlZ2lzdGVyZWRBcHBsaWNhdGlvbiIsImVrIjoiOE5sZ2cwcW5EUVdROUFNWGpXT2lmOWktZnpidG5KcUlqWGJ3WHJZZkpZcldrbG90ZEhvLVBjSWhQaU8xU1ZtMW84aU1WZGZqN2xWNzFjLXFxLmcybXE1dnh4Q1hUT25xaWRUaTFlcEhmVk1fIn0_
          description: User-specific authentication key.
        - name: clientId
          in: path
          required: true
          description: The OAuth `clientId` of the application to update.
          schema:
            type: string
            format: uuid
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateApplicationBody'
            example:
              applicationName: My Renamed Trading App
              redirectUris:
                - https://myapp.com/oauth/callback
                - https://myapp.com/oauth/callback-staging
      responses:
        '200':
          description: Application updated successfully.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UpdateApplicationResponse'
          headers:
            RateLimit-Limit:
              description: >-
                Maximum number of requests allowed per window. This is the
                default shared pool used by every endpoint without a dedicated
                limit, so it is NOT per-endpoint — requests across those
                endpoints all draw from this one budget.
              schema:
                type: integer
              example: 60
            RateLimit-Remaining:
              description: Requests remaining in the current window for this quota.
              schema:
                type: integer
            RateLimit-Reset:
              description: Seconds until the current window resets.
              schema:
                type: integer
            RateLimit-Policy:
              description: Quota policy in the form `<limit>;w=<window-seconds>`.
              schema:
                type: string
              example: 60;w=60
        '400':
          description: Validation error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StsMetadataFrontApi_ErrorResponse'
        '401':
          description: Missing or invalid STS access token.
        '404':
          description: >-
            Application not found, or the caller is not an admin of the
            application.
        '429':
          description: >-
            Too Many Requests — the shared rate limit (60 requests / 60s) was
            exceeded.
          headers:
            RateLimit-Limit:
              description: >-
                Maximum number of requests allowed per window. This is the
                default shared pool used by every endpoint without a dedicated
                limit, so it is NOT per-endpoint — requests across those
                endpoints all draw from this one budget.
              schema:
                type: integer
              example: 60
            RateLimit-Remaining:
              description: Requests remaining in the current window for this quota.
              schema:
                type: integer
            RateLimit-Reset:
              description: Seconds until the current window resets.
              schema:
                type: integer
            RateLimit-Policy:
              description: Quota policy in the form `<limit>;w=<window-seconds>`.
              schema:
                type: string
              example: 60;w=60
            Retry-After:
              description: Seconds to wait before retrying.
              schema:
                type: integer
              example: 60
        '500':
          description: Backend sts-metadata-api unavailable.
      security:
        - oauth2:
            - etoro-public:sso-applications:write
components:
  schemas:
    UpdateApplicationBody:
      type: object
      description: At least one field must be provided. Omitted fields are left unchanged.
      properties:
        applicationName:
          type: string
          maxLength: 100
          description: Updated display name.
        applicationIconUrl:
          type: string
          format: uri
          maxLength: 500
          description: Updated icon URL.
        scopes:
          type: array
          description: >-
            Replacement set of scopes. Each `scopeId` must be positive and
            present in the cached catalog; no duplicates.
          items:
            $ref: '#/components/schemas/ScopeItem'
        redirectUris:
          type: array
          uniqueItems: true
          description: Replacement set of redirect URIs.
          items:
            type: string
            format: uri
            maxLength: 500
    UpdateApplicationResponse:
      type: object
      properties:
        application:
          $ref: '#/components/schemas/ApplicationItem'
    StsMetadataFrontApi_ErrorResponse:
      type: object
      properties:
        errorCode:
          type: string
          description: >-
            Machine-readable error code (e.g. `ScopeIdInvalid`,
            `ScopeIdsDuplicateItems`).
        errorMessage:
          type: string
          description: Human-readable error description.
    ScopeItem:
      type: object
      required:
        - scopeId
        - isMandatory
      properties:
        scopeId:
          type: integer
          minimum: 1
          description: >-
            Scope identifier. Must be a known scope from `GET
            /api/v1/sso/scopes`.
        isMandatory:
          type: boolean
          description: >-
            When true, the user cannot deselect this scope on the consent
            screen.
    ApplicationItem:
      type: object
      description: Full application record. The `clientSecret` is intentionally excluded.
      properties:
        applicationId:
          type: integer
          format: int64
          description: Internal numeric identifier of the application.
        applicationName:
          type: string
          description: Display name of the application.
        applicationIconUrl:
          type: string
          format: uri
          description: URL of the application icon.
        clientId:
          type: string
          format: uuid
          description: >-
            OAuth client identifier. Stable across the lifetime of the
            application.
        audience:
          type: string
          description: OAuth audience claim issued for tokens minted for this application.
        applicationType:
          type: string
          description: OAuth application type (e.g. `public`, `confidential`).
        scopes:
          type: array
          description: >-
            Scopes assigned to the application, including which are mandatory at
            consent time.
          items:
            $ref: '#/components/schemas/ApplicationScopeItem'
        redirectUris:
          type: array
          description: Registered OAuth redirect URIs.
          items:
            type: string
        supportedFlows:
          type: array
          description: >-
            OAuth flows supported by the application (e.g. `authorization_code`,
            `refresh_token`).
          items:
            type: string
        supportedCodeChallengeMethods:
          type: array
          description: >-
            PKCE code-challenge methods supported by the application (e.g.
            `S256`).
          items:
            type: string
        ssoIdTokenExpirationInMinutes:
          type: integer
          description: Lifetime of issued SSO id tokens, in minutes.
        ssoRefreshTokenExpirationInMinutes:
          type: integer
          description: Lifetime of issued SSO refresh tokens, in minutes.
        ssoAccessTokenExpirationInMinutes:
          type: integer
          description: Lifetime of issued SSO access tokens, in minutes.
        adminGcids:
          type: array
          description: GCIDs of users who can administer this application.
          items:
            type: integer
            format: int64
    ApplicationScopeItem:
      type: object
      description: Scope entry as returned in application reads.
      properties:
        scopeId:
          type: integer
          description: Scope identifier.
        isMandatory:
          type: boolean
          description: >-
            When true, the user cannot deselect this scope on the consent
            screen.
  securitySchemes:
    oauth2:
      type: oauth2
      description: >-
        eToro OAuth2. Each operation lists the scopes that grant access as
        separate `security` requirements (OpenAPI OR semantics): the caller's
        token only needs ONE of them — you do NOT need all of them. The same
        scopes back the x-api-key/x-user-key credential pair.
      flows:
        authorizationCode:
          authorizationUrl: ''
          tokenUrl: ''
          scopes:
            etoro-public:agent-portfolio:read: Grants access to the 'etoro-public:agent-portfolio:read' scope.
            etoro-public:agent-portfolio:write: Grants access to the 'etoro-public:agent-portfolio:write' scope.
            etoro-public:club:read: Grants access to the 'etoro-public:club:read' scope.
            etoro-public:demo:read: Grants access to the 'etoro-public:demo:read' scope.
            etoro-public:demo:write: Grants access to the 'etoro-public:demo:write' scope.
            etoro-public:feed:read: Grants access to the 'etoro-public:feed:read' scope.
            etoro-public:feed:write: Grants access to the 'etoro-public:feed:write' scope.
            etoro-public:market-data:read: Grants access to the 'etoro-public:market-data:read' scope.
            etoro-public:money.balance:read: Grants access to the 'etoro-public:money.balance:read' scope.
            etoro-public:money.cash-transactions:read: >-
              Grants access to the 'etoro-public:money.cash-transactions:read'
              scope.
            etoro-public:money.transfer:read: Grants access to the 'etoro-public:money.transfer:read' scope.
            etoro-public:money.transfer:write: Grants access to the 'etoro-public:money.transfer:write' scope.
            etoro-public:money:transfer: Grants access to the 'etoro-public:money:transfer' scope.
            etoro-public:notifications:read: Grants access to the 'etoro-public:notifications:read' scope.
            etoro-public:notifications:write: Grants access to the 'etoro-public:notifications:write' scope.
            etoro-public:pi-data:read: Grants access to the 'etoro-public:pi-data:read' scope.
            etoro-public:price-alerts:read: Grants access to the 'etoro-public:price-alerts:read' scope.
            etoro-public:price-alerts:write: Grants access to the 'etoro-public:price-alerts:write' scope.
            etoro-public:real:read: Grants access to the 'etoro-public:real:read' scope.
            etoro-public:real:write: Grants access to the 'etoro-public:real:write' scope.
            etoro-public:sso-applications:read: Grants access to the 'etoro-public:sso-applications:read' scope.
            etoro-public:sso-applications:write: Grants access to the 'etoro-public:sso-applications:write' scope.
            etoro-public:sso-scopes:read: Grants access to the 'etoro-public:sso-scopes:read' scope.
            etoro-public:sso-scopes:write: Grants access to the 'etoro-public:sso-scopes:write' scope.
            etoro-public:sub-accounts:read: Grants access to the 'etoro-public:sub-accounts:read' scope.
            etoro-public:sub-accounts:write: Grants access to the 'etoro-public:sub-accounts:write' scope.
            etoro-public:trade.demo:read: Grants access to the 'etoro-public:trade.demo:read' scope.
            etoro-public:trade.demo:write: Grants access to the 'etoro-public:trade.demo:write' scope.
            etoro-public:trade.real:read: Grants access to the 'etoro-public:trade.real:read' scope.
            etoro-public:trade.real:write: Grants access to the 'etoro-public:trade.real:write' scope.
            etoro-public:user-info:read: Grants access to the 'etoro-public:user-info:read' scope.
            etoro-public:watchlist:read: Grants access to the 'etoro-public:watchlist:read' scope.
            etoro-public:watchlist:write: Grants access to the 'etoro-public:watchlist:write' scope.

````