Use the Cursor plugin / MCP flow. Do not follow the Grok.com “search etoro in Connectors” steps — that is a different product. Guide pages on mcp.etoro.app are docs only — not the MCP endpoint.
Put this in ~/.cursor/mcp.json or project .cursor/mcp.json. Static public client etoro-mcp-cursor-grok-bot (PKCE S256, no secret). Open DCR stays off — no /register.
Finish etoro login in the browser (complete 2FA if asked).
Approve the connection on the consent screen.
If Grok Bot shows Waiting for authorization, use Reopen so the browser tab comes back.
Confirm the server appears under Installed / connected MCP servers.
4
Confirm it’s live
Check that tools are visible (tools count > 0).
Run the safe first checks below.
If auth is stuck: disconnect/remove the server, clear any half-finished OAuth session, then Connect again.
After connect
Safe first checks
1 · Discover
List etoro MCP tools
Ask for account / profile summary
Read-only: execute-read on /api/v1/me
2 · Stay careful
Start with read-only questions
Confirm before any action that can move money
Prefer demo when trying something new
Important
Confirm before any write. Actions that can move real money need your approval. Prefer demo first. Never paste passwords, API keys, or tokens into chat.
Good to know
What to expect
Do this
Treat Grok Bot as Cursor plugins / MCP
Use https://mcp.etoro.app for Connect
Sign in with etoro SSO + 2FA
Start with read-only prompts
Skip this
Don’t use the Grok.com Connectors catalog steps
Don’t paste guide page URLs as the MCP endpoint
Don’t paste API keys into chat
Don’t approve money-moving actions without reviewing them
Auth note
Open Dynamic Client Registration is off on mcp.etoro.app by design (security). Grok Bot / Cursor uses the closed static public client etoro-mcp-cursor-grok-bot with a fixed redirect allowlist — not open registration. No client secret. Nested eToro SSO still uses the existing STS app callback on this host only. Plugin marketplace install is optional; manual mcp.json works for smoke tests.
CIMD: our AS advertises client_id_metadata_document_supported with a deny-by-default host allowlist (MCP_CIMD_ALLOWED_HOSTS). Until Cursor ships a metadata URL on an allowlisted host, use the static client above. Open DCR stays off.
Share this page
Ready to connect Grok Bot?
Share https://mcp.etoro.app/GrokBot — title, description, and preview image are set for WhatsApp, X, Slack, and LinkedIn.