Skip to main content
POST
Create Sub-Account User Token

Authorizations

x-api-key
string
header
default:lhgfaslk21490FAScVPkdsb53F9dNkfHG4faZSG5vfjndfcfgdssdgsdHF4663
required

API key of the application. Only valid together with the x-user-key header — the pair is an alternative to OAuth bearer authentication, never sent alongside it. The pair is granted the same permissions the operation's OAuth scopes describe.

Demo credential for trying the API from these docs: lhgfaslk21490FAScVPkdsb53F9dNkfHG4faZSG5vfjndfcfgdssdgsdHF4663

x-user-key
string
header
default:eyJlYW4iOiJVbnJlZ2lzdGVyZWRBcHBsaWNhdGlvbiIsImVrIjoiOE5sZ2cwcW5EUVdROUFNWGpXT2lmOWktZnpidG5KcUlqWGJ3WHJZZkpZcldrbG90ZEhvLVBjSWhQaU8xU1ZtMW84aU1WZGZqN2xWNzFjLXFxLmcybXE1dnh4Q1hUT25xaWRUaTFlcEhmVk1fIn0_
required

User-specific authentication key. Only valid together with the x-api-key header — the pair is an alternative to OAuth bearer authentication, never sent alongside it.

Demo credential for trying the API from these docs: eyJlYW4iOiJVbnJlZ2lzdGVyZWRBcHBsaWNhdGlvbiIsImVrIjoiOE5sZ2cwcW5EUVdROUFNWGpXT2lmOWktZnpidG5KcUlqWGJ3WHJZZkpZcldrbG90ZEhvLVBjSWhQaU8xU1ZtMW84aU1WZGZqN2xWNzFjLXFxLmcybXE1dnh4Q1hUT25xaWRUaTFlcEhmVk1fIn0_

Headers

x-request-id
string<uuid>
required

A unique request identifier.

Example:

"72fb21f5-a7bb-4858-a9e3-a8526b695649"

x-sub-account-id
string
required

The encrypted sub-account identifier. The backend validates that it decrypts to a sub-account owned by the caller's token gcid and generates the token for the sub-account's gcid.

Body

application/json
userTokenName
string
required

A friendly display name for the user token.

Example:

"my-trading-bot"

scopeNames
string[]
required

The scope names to assign. Must be a subset of the scopes returned by GET /api/v1/sub-accounts/etoro-trading/user-tokens/scopes.

Example:
ipsWhitelist
string[]

An optional IPv4 whitelist for the token.

Example:
expiresAt
string<date-time>

An optional UTC expiration for the token.

Example:

"2026-12-31T23:59:59Z"

Response

User token created successfully

userTokenId
string<uuid>

The unique identifier of the created user token.

Example:

"3fa85f64-5717-4562-b3fc-2c963f66afa6"

userToken
string

The secret token value. Returned only once, on creation.

Example:

"ut_live_9f8c7b6a5d4e3f2a1b0c"

userTokenName
string

The friendly display name assigned to the token.

Example:

"my-trading-bot"

clientId
string<uuid>

The OAuth client id associated with the token.

Example:

"7c9e6679-7425-40de-944b-e07fc1f90ae7"

ipsWhitelist
string[]

The IPv4 addresses the token is restricted to, if any.

Example:
scopes
object[]

The scopes granted to the token.

expiresAt
string<date-time> | null

The UTC expiration of the token, if one was set.

Example:

"2026-12-31T23:59:59Z"

createdAt
string<date-time>

When this user token was created.

Example:

"2026-06-06T10:15:00Z"