Create User Token
Rate limit: 60 requests per 60 seconds. This is the default shared quota — it is shared with every other endpoint that has no dedicated limit, so requests across those endpoints all draw from the same budget.
[DEPRECATED — use POST /api/v2/agent-portfolios//user-tokens (scope names) instead] Creates a new user token for the specified agent-portfolio.
Authorizations
eToro OAuth2. Each operation lists the scopes that grant access as separate security requirements (OpenAPI OR semantics): the caller's token only needs ONE of them — you do NOT need all of them. The same scopes back the x-api-key/x-user-key credential pair.
Headers
A unique request identifier.
"9a7ffb4e-4989-455b-a00e-2c13a1dd5432"
API key for authentication.
"lhgfaslk21490FAScVPkdsb53F9dNkfHG4faZSG5vfjndfcfgdssdgsdHF4663"
User-specific authentication key.
"eyJlYW4iOiJVbnJlZ2lzdGVyZWRBcHBsaWNhdGlvbiIsImVrIjoiOE5sZ2cwcW5EUVdROUFNWGpXT2lmOWktZnpidG5KcUlqWGJ3WHJZZkpZcldrbG90ZEhvLVBjSWhQaU8xU1ZtMW84aU1WZGZqN2xWNzFjLXFxLmcybXE1dnh4Q1hUT25xaWRUaTFlcEhmVk1fIn0_"
Path Parameters
The unique identifier of the agent-portfolio.
Body
A human-readable name to identify the user token.
"my-trading-token"
[DEPRECATED — use scopeNames instead] The set of permission scope identifiers to grant to this token. Available scopes: 200 = etoro-public:real:read, 201 = etoro-public:demo:read, 202 = etoro-public:real:write, 203 = etoro-public:demo:write.
The set of permission scope names (preferred; replaces the deprecated scopeIds). Provide either scopeNames or scopeIds. Available scopes: etoro-public:real:read, etoro-public:demo:read, etoro-public:real:write, etoro-public:demo:write.
An optional set of IPv4 addresses allowed to use this token.
An optional expiration date and time for the token in UTC.
"2026-12-31T23:59:59Z"
Response
User token created successfully
The unique identifier of the newly created user token.
"f9e8d7c6-b5a4-3210-fedc-ba9876543210"
The generated user token secret. Only available at creation time.
"sk_live_a1b2c3d4e5f6..."
The display name of the user token.
"my-trading-token"
The client identifier of the application the token is associated with.
"3fa85f64-5717-4562-b3fc-2c963f66afa6"
The IPv4 addresses from which the token is allowed to be used. Null or empty when unrestricted.
The authorized scope names granted to the token.
The UTC expiration date of the token. Null when the token does not expire.
"2026-12-31T23:59:59Z"
The UTC timestamp at which the token was created.
"2026-03-06T12:00:00Z"