> ## Documentation Index
> Fetch the complete documentation index at: https://api-portal.etoro.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get customer KYC gaps

> **Rate limit:** 60 requests per 60 seconds. This is the **default shared quota** — it is shared with every other endpoint that has no dedicated limit, so requests across those endpoints all draw from the same budget.

---

Returns the authenticated user's compliance gaps (requirements and user interactions), ordered by priority. Requirements are filtered to only include those with status Required or Expired.



## OpenAPI

````yaml /api-reference/partners-openapi.json get /api/v1/kyc/gaps
openapi: 3.0.1
info:
  title: eToro Api
  version: v1.342.0
  description: >-
    eToro’s public API provides access to real-time financial data, trading
    insights, and account management features, allowing developers to integrate
    eToro’s services into their applications. With access to market prices,
    historical data, and social trading information, the API empowers users to
    enhance their trading strategies. Designed for security and scalability, the
    eToro API ensures smooth and reliable integration for a variety of financial
    applications.


    For more details on integrating with eToro's public WebSocket service,
    please refer to the dedicated [WebSocket
    documentation](./websocket/websocket-doc.html).


    ## Authentication


    Every request must be authenticated with exactly one of two options: an
    OAuth 2.0 access token (`Authorization: Bearer <token>`), or the
    non-interactive credential pair (`x-api-key` + `x-user-key` headers). The
    two options are mutually exclusive — a request carrying both is rejected.
    Each operation lists the OAuth scopes that grant access as alternative
    security requirements: a bearer token needs only ONE of them, and the same
    permissions govern the credential pair.
servers:
  - url: https://public-api.etoro.com
    description: eToro Public API - Partners
security:
  - apiKeyAuth: []
    userKeyAuth: []
  - oauth2: []
tags:
  - name: OPS
  - name: KYC
  - name: Cash Accounts
  - name: FTD
  - name: Crypto Deposit
  - name: Crypto Withdrawals
  - name: Registration
  - name: Sub-Accounts
  - name: Email Verification
  - name: Trusted Partner
  - name: Phone Verification
  - name: Verification
paths:
  /api/v1/kyc/gaps:
    get:
      tags:
        - KYC
      summary: Get customer KYC gaps
      description: >-
        **Rate limit:** 60 requests per 60 seconds. This is the **default shared
        quota** — it is shared with every other endpoint that has no dedicated
        limit, so requests across those endpoints all draw from the same budget.


        ---


        Returns the authenticated user's compliance gaps (requirements and user
        interactions), ordered by priority. Requirements are filtered to only
        include those with status Required or Expired.
      operationId: getKycGaps
      parameters:
        - name: x-request-id
          in: header
          required: true
          schema:
            type: string
            format: uuid
            example: f11851f0-2088-4058-8fac-25d09ec31f80
          description: A unique request identifier.
      responses:
        '200':
          description: Successfully retrieved customer gaps
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicGapsResponse'
              example:
                requirements:
                  - requirement: POI
                    category: LoginPopup
                    status: Required
                    isMandatory: true
                    statusReason: LoginCheck
                    openReason: LoginCheck
                  - requirement: POA
                    category: VerificationCenter
                    status: Expired
                    isMandatory: false
                    statusReason: DocumentHasExpired
                    openReason: null
                userInteractions:
                  - userInteractionType: UpdateTnc
                    isMandatory: true
          headers:
            RateLimit-Limit:
              description: >-
                Maximum number of requests allowed per window. This is the
                default shared pool used by every endpoint without a dedicated
                limit, so it is NOT per-endpoint — requests across those
                endpoints all draw from this one budget.
              schema:
                type: integer
              example: 60
            RateLimit-Remaining:
              description: Requests remaining in the current window for this quota.
              schema:
                type: integer
            RateLimit-Reset:
              description: Seconds until the current window resets.
              schema:
                type: integer
            RateLimit-Policy:
              description: Quota policy in the form `<limit>;w=<window-seconds>`.
              schema:
                type: string
              example: 60;w=60
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ComplianceApi_PublicErrorResponse'
              example:
                errorCode: Unauthorized
                errorMessage: Unauthorized
        '403':
          description: Forbidden - Insufficient permissions
        '422':
          description: Unprocessable Entity - invalid or non-existent user
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ComplianceApi_PublicErrorResponse'
              example:
                errorCode: InvalidUser
                errorMessage: Invalid or non-existent user
        '429':
          description: Too Many Requests
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ComplianceApi_PublicErrorResponse'
              example:
                errorCode: TooManyRequests
                errorMessage: Too many requests
          headers:
            RateLimit-Limit:
              description: >-
                Maximum number of requests allowed per window. This is the
                default shared pool used by every endpoint without a dedicated
                limit, so it is NOT per-endpoint — requests across those
                endpoints all draw from this one budget.
              schema:
                type: integer
              example: 60
            RateLimit-Remaining:
              description: Requests remaining in the current window for this quota.
              schema:
                type: integer
            RateLimit-Reset:
              description: Seconds until the current window resets.
              schema:
                type: integer
            RateLimit-Policy:
              description: Quota policy in the form `<limit>;w=<window-seconds>`.
              schema:
                type: string
              example: 60;w=60
            Retry-After:
              description: Seconds to wait before retrying.
              schema:
                type: integer
              example: 60
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ComplianceApi_PublicErrorResponse'
              example:
                errorCode: GeneralError
                errorMessage: Internal server error. Please retry or contact support
      security:
        - apiKeyAuth: []
          userKeyAuth: []
        - oauth2:
            - etoro-public:kyc:read
        - oauth2:
            - etoro-public:kyc:write
components:
  schemas:
    PublicGapsResponse:
      type: object
      description: >-
        Customer gaps response containing requirements and user interactions
        ordered by priority
      required:
        - requirements
        - userInteractions
      properties:
        requirements:
          type: array
          description: >-
            Compliance requirements with status Required or Expired, ordered by
            priority
          items:
            $ref: '#/components/schemas/PublicRequirementDto'
        userInteractions:
          type: array
          description: Active user interactions ordered by priority
          items:
            $ref: '#/components/schemas/PublicUserInteractionDto'
    ComplianceApi_PublicErrorResponse:
      type: object
      description: Error response with code and message
      required:
        - errorCode
        - errorMessage
      properties:
        errorCode:
          type: string
          description: Machine-readable error code
          example: GeneralError
        errorMessage:
          type: string
          description: Human-readable error message
          example: Internal server error. Please retry or contact support
    PublicRequirementDto:
      type: object
      description: A single compliance requirement gap
      required:
        - requirement
        - category
        - status
        - isMandatory
      properties:
        requirement:
          type: string
          description: Requirement type identifier
          enum:
            - POI
            - POA
            - InvestmentPlan
            - NewQuestions
            - QuestionExpiration
            - CNMVDisclaimer
            - RegulationChange
            - LabelChange
            - MissingTnc
            - AsicSophisticated
            - HighDepositorStudent
            - SourceOfFunds
            - VideoIdentification
            - W8BEN
            - SelfieLiveliness
            - W8benTinChange
            - W8BenExpired
            - W8BenTtb
            - BankStatement
            - VideoIdentificationPromotion
            - RetroactiveVideoIdentGap
            - FinlandMissingPIN
            - UkClassification
            - SelfieMotion
            - CryptoStatus
            - SourceOfFundsSelfieLiveliness
            - AFCAMOP
            - PoiVC
            - PoaVC
          example: POI
        category:
          type: string
          description: Requirement category determining where the gap is shown
          enum:
            - LoginPopup
            - VerificationCenter
          example: LoginPopup
        status:
          type: string
          description: >-
            Requirement status (only Required and Expired are returned by this
            endpoint)
          enum:
            - Required
            - Expired
          example: Required
        isMandatory:
          type: boolean
          description: Whether the requirement is mandatory for the user
          example: true
        statusReason:
          type: string
          nullable: true
          description: Reason for the current requirement status
          enum:
            - None
            - DepositExceededTotalWorth
            - DepositExceedsPlan
            - InvestmentPlanUpdate
            - LoginCheck
            - DocumentHasExpired
            - UserConfirmation
            - ResetAnnualPlan
            - DocumentClassified
            - DocumentUploaded
            - CountryUpdate
            - Confirmation
            - QuestionReview
            - AccountLiqudation
            - QuestionEvaluation
            - DBScript
            - LoginGapNotSuitable
            - BackofficeRequest
            - Reject
            - Confirm
            - DocumentClassificationRemoved
            - Deeplink
            - RiskAlert
            - UserInteraction
            - NegativeConsent
            - VideoIdentPassed
            - VideoIdentFailed
            - UserDismissGap
            - EVTwoSource
            - Trade
            - RequreW8Ben
            - RequreTinAndW8Ben
            - RequreTIN
            - GapIsAlreadyExist
            - VerificationLevelInvalid
            - SelfieExists
            - AutoOpenGap
            - SelfieDocumentUnderReview
            - Deposit
            - Withdraw
            - Elderly
            - RegulationChange
            - RequireW8BenTtb
            - ActimizeAlert
            - RetroactiveVideoIdentGap
            - BatchAddRetroactiveVideoIdentGap
            - VideoIdentInPendingState
            - PinInserted
            - RiskClassificationChange
            - NoAvailableWireMop
            - NoAvailablePayPalMop
            - InitiatedViaMass
            - BlockedAccountReactivation
            - Screening
            - CRRHigh
            - FCMU
            - PeriodicReview
            - ExpiredPOI
            - ExpiredPOA
          example: LoginCheck
        openReason:
          type: string
          nullable: true
          description: Original reason the requirement was opened
          enum:
            - None
            - DepositExceededTotalWorth
            - DepositExceedsPlan
            - InvestmentPlanUpdate
            - LoginCheck
            - DocumentHasExpired
            - UserConfirmation
            - ResetAnnualPlan
            - DocumentClassified
            - DocumentUploaded
            - CountryUpdate
            - Confirmation
            - QuestionReview
            - AccountLiqudation
            - QuestionEvaluation
            - DBScript
            - LoginGapNotSuitable
            - BackofficeRequest
            - Reject
            - Confirm
            - DocumentClassificationRemoved
            - Deeplink
            - RiskAlert
            - UserInteraction
            - NegativeConsent
            - VideoIdentPassed
            - VideoIdentFailed
            - UserDismissGap
            - EVTwoSource
            - Trade
            - RequreW8Ben
            - RequreTinAndW8Ben
            - RequreTIN
            - GapIsAlreadyExist
            - VerificationLevelInvalid
            - SelfieExists
            - AutoOpenGap
            - SelfieDocumentUnderReview
            - Deposit
            - Withdraw
            - Elderly
            - RegulationChange
            - RequireW8BenTtb
            - ActimizeAlert
            - RetroactiveVideoIdentGap
            - BatchAddRetroactiveVideoIdentGap
            - VideoIdentInPendingState
            - PinInserted
            - RiskClassificationChange
            - NoAvailableWireMop
            - NoAvailablePayPalMop
            - InitiatedViaMass
            - BlockedAccountReactivation
            - Screening
            - CRRHigh
            - FCMU
            - PeriodicReview
            - ExpiredPOI
            - ExpiredPOA
          example: LoginCheck
    PublicUserInteractionDto:
      type: object
      description: A user interaction gap that requires user action
      required:
        - userInteractionType
        - isMandatory
      properties:
        userInteractionType:
          type: string
          description: Type of user interaction (DB-driven string, falls back to enum name)
          example: UpdateTnc
        isMandatory:
          type: boolean
          description: Whether the interaction is mandatory for the user
          example: true
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        API key of the application. Only valid together with the x-user-key
        header — the pair is an alternative to OAuth bearer authentication,
        never sent alongside it. The pair is granted the same permissions the
        operation's OAuth scopes describe.


        Demo credential for trying the API from these docs:
        `lhgfaslk21490FAScVPkdsb53F9dNkfHG4faZSG5vfjndfcfgdssdgsdHF4663`
      x-default: lhgfaslk21490FAScVPkdsb53F9dNkfHG4faZSG5vfjndfcfgdssdgsdHF4663
    userKeyAuth:
      type: apiKey
      in: header
      name: x-user-key
      description: >-
        User-specific authentication key. Only valid together with the x-api-key
        header — the pair is an alternative to OAuth bearer authentication,
        never sent alongside it.


        Demo credential for trying the API from these docs:
        `eyJlYW4iOiJVbnJlZ2lzdGVyZWRBcHBsaWNhdGlvbiIsImVrIjoiOE5sZ2cwcW5EUVdROUFNWGpXT2lmOWktZnpidG5KcUlqWGJ3WHJZZkpZcldrbG90ZEhvLVBjSWhQaU8xU1ZtMW84aU1WZGZqN2xWNzFjLXFxLmcybXE1dnh4Q1hUT25xaWRUaTFlcEhmVk1fIn0_`
      x-default: >-
        eyJlYW4iOiJVbnJlZ2lzdGVyZWRBcHBsaWNhdGlvbiIsImVrIjoiOE5sZ2cwcW5EUVdROUFNWGpXT2lmOWktZnpidG5KcUlqWGJ3WHJZZkpZcldrbG90ZEhvLVBjSWhQaU8xU1ZtMW84aU1WZGZqN2xWNzFjLXFxLmcybXE1dnh4Q1hUT25xaWRUaTFlcEhmVk1fIn0_
    oauth2:
      type: oauth2
      description: >-
        eToro OAuth2 — send the access token as `Authorization: Bearer <token>`.
        Each operation lists the scopes that grant access as separate `security`
        requirements (OpenAPI OR semantics): the caller's token only needs ONE
        of them — you do NOT need all of them. Mutually exclusive with the
        x-api-key/x-user-key credential pair: never send both.
      flows:
        authorizationCode:
          authorizationUrl: ''
          tokenUrl: ''
          scopes:
            etoro-public:demo:read: Grants access to the 'etoro-public:demo:read' scope.
            etoro-public:kyc:answers:read: Grants access to the 'etoro-public:kyc:answers:read' scope.
            etoro-public:kyc:answers:write: Grants access to the 'etoro-public:kyc:answers:write' scope.
            etoro-public:kyc:questions:read: Grants access to the 'etoro-public:kyc:questions:read' scope.
            etoro-public:kyc:read: Grants access to the 'etoro-public:kyc:read' scope.
            etoro-public:kyc:regulations:read: Grants access to the 'etoro-public:kyc:regulations:read' scope.
            etoro-public:kyc:write: Grants access to the 'etoro-public:kyc:write' scope.
            etoro-public:money.accounts:read: Grants access to the 'etoro-public:money.accounts:read' scope.
            etoro-public:money.accounts:write: Grants access to the 'etoro-public:money.accounts:write' scope.
            etoro-public:money.deposit.crypto:read: >-
              Grants access to the 'etoro-public:money.deposit.crypto:read'
              scope.
            etoro-public:money.deposit.crypto:write: >-
              Grants access to the 'etoro-public:money.deposit.crypto:write'
              scope.
            etoro-public:money.ftd:read: Grants access to the 'etoro-public:money.ftd:read' scope.
            etoro-public:money.ftd:write: Grants access to the 'etoro-public:money.ftd:write' scope.
            etoro-public:money.withdraw.crypto:read: >-
              Grants access to the 'etoro-public:money.withdraw.crypto:read'
              scope.
            etoro-public:money.withdraw.crypto:write: >-
              Grants access to the 'etoro-public:money.withdraw.crypto:write'
              scope.
            etoro-public:partner-default: Grants access to the 'etoro-public:partner-default' scope.
            etoro-public:partner:registration:read: >-
              Grants access to the 'etoro-public:partner:registration:read'
              scope.
            etoro-public:partner:registration:write: >-
              Grants access to the 'etoro-public:partner:registration:write'
              scope.
            etoro-public:real:read: Grants access to the 'etoro-public:real:read' scope.
            etoro-public:sub-accounts:delete: Grants access to the 'etoro-public:sub-accounts:delete' scope.
            etoro-public:verification.address:read: >-
              Grants access to the 'etoro-public:verification.address:read'
              scope.
            etoro-public:verification.address:write: >-
              Grants access to the 'etoro-public:verification.address:write'
              scope.
            etoro-public:verification.email:write: >-
              Grants access to the 'etoro-public:verification.email:write'
              scope.
            etoro-public:verification.personaldetails:read: >-
              Grants access to the
              'etoro-public:verification.personaldetails:read' scope.
            etoro-public:verification.personaldetails:write: >-
              Grants access to the
              'etoro-public:verification.personaldetails:write' scope.
            etoro-public:verification.phone:write: >-
              Grants access to the 'etoro-public:verification.phone:write'
              scope.
            etoro-public:verification.trusted.email:write: >-
              Grants access to the
              'etoro-public:verification.trusted.email:write' scope.
            etoro-public:verification.trusted.phone:write: >-
              Grants access to the
              'etoro-public:verification.trusted.phone:write' scope.
            etoro-public:verification:trusted:user:write: >-
              Grants access to the
              'etoro-public:verification:trusted:user:write' scope.

````