OneTrust Consent Attachments API

APIs for managing Consent Attachments.

Operations 5

POST /rest/api/preferences/v1/attachments Upload Consent Attachment #
GET /rest/api/preferences/v1/attachments/{attachmentId} Download Consent Attachment #
DELETE /rest/api/preferences/v1/attachments-reference/{attachmentId} Remove Consent Attachment #
DELETE /rest/api/preferences/v1/datasubjects/{identifier}/attachment-references Remove All Consent Attachments #
GET /rest/api/preferences/v1/datasubjects/{identifier}/attachments Download All Consent Attachments #

Documentation

📖
Documentation
https://developer.onetrust.com/onetrust/reference/attribute-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/activity-log
📖
Documentation
https://developer.onetrust.com/onetrust/reference/preferences-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/banner
📖
Documentation
https://developer.onetrust.com/onetrust/reference/consent-receipts
📖
Documentation
https://developer.onetrust.com/onetrust/reference/applications
📖
Documentation
https://developer.onetrust.com/onetrust/reference/categorizations
📖
Documentation
https://developer.onetrust.com/onetrust/reference/domain-data
📖
Documentation
https://developer.onetrust.com/onetrust/reference/preferences
📖
Documentation
https://developer.onetrust.com/onetrust/reference/mobile-app-data
📖
Documentation
https://developer.onetrust.com/onetrust/reference/privacy-notice-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/collection-points
📖
Documentation
https://developer.onetrust.com/onetrust/reference/catalog-search-v1
📖
Documentation
https://developer.onetrust.com/onetrust/reference/classification
📖
Documentation
https://developer.onetrust.com/onetrust/reference/custom-scan
📖
Documentation
https://developer.onetrust.com/onetrust/reference/carbon-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/audit-records
📖
Documentation
https://developer.onetrust.com/onetrust/reference/bulk-export
📖
Documentation
https://developer.onetrust.com/onetrust/reference/attachments
📖
Documentation
https://developer.onetrust.com/onetrust/reference/system-credentials
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory-relationships-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/model-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/tasks
📖
Documentation
https://developer.onetrust.com/onetrust/reference/groups-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/assessment-actions
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory-1
📖
Documentation
https://developer.onetrust.com/onetrust/reference/drop-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/incidents
📖
Documentation
https://developer.onetrust.com/onetrust/reference/document-controller
📖
Documentation
https://developer.onetrust.com/onetrust/reference/audits
📖
Documentation
https://developer.onetrust.com/onetrust/reference/initiatives
📖
Documentation
https://developer.onetrust.com/onetrust/reference/document-attachments
📖
Documentation
https://developer.onetrust.com/onetrust/reference/issues
📖
Documentation
https://developer.onetrust.com/onetrust/reference/control-implementations
📖
Documentation
https://developer.onetrust.com/onetrust/reference/training
📖
Documentation
https://developer.onetrust.com/onetrust/reference/contracts

Specifications

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/onetrust-consent-attachments-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

onetrust-consent-attachments-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Consent & Preferences - Universal Consent & Preference…
  version: '1.0'
  contact:
    name: OneTrust Support
    url: https://my.onetrust.com/s/contactsupport
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  description: The Universal Consent & Preference Management APIs are used to integrate external systems and streamline the flow of data with Universal Consent & Preference Management in the OneTrust Platform.
servers:
- url: https://{hostname}
  variables:
    hostname:
      default: hostname
      description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com.
tags:
- name: Consent Attachments
  description: APIs for managing Consent Attachments.
  externalDocs:
    description: OpenAPI 3.1.0 - Download Definition
    url: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json
  x-displayName: Consent Attachments
paths:
  /rest/api/preferences/v1/attachments:
    post:
      operationId: uploadConsentAttachments
      summary: Upload Consent Attachment
      description: 'Use this API to upload and store files which contain written consent of data subjects'' transactions.


        > 🗒 Things to Know

        >

        > - The size of uploaded files must be less than 4MB.

        >

        > - The following file formats are allowed: .pdf, .jpeg, .jpg, and .png.

        >

        > - The `RefID` parameter returned within the response body can be used to attach file references to incoming data subject consents using the Create Consent Receipts API.

        >

        > - File references can be attached to a given data subject or data subject purpose by using the `attachments` or `PurposeAttachments` parameters in the Create Consent Receipts API respectively.'
      tags:
      - Consent Attachments
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json
      requestBody:
        required: true
        content:
          multipart/form-data:
            schema:
              type: object
              properties:
                file:
                  description: 'The file to upload. Supported formats: .pdf, .jpeg, .jpg, .png. Max size: 4MB.'
                  type: string
                  format: binary
              required:
              - file
      responses:
        '200':
          description: File uploaded successfully.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DSPreferneceCache_UploadDataDto'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - DSPreferneceCache_OAUTH2:
        - CONSENT
  /rest/api/preferences/v1/attachments/{attachmentId}:
    get:
      operationId: downloadGivenConsentAttachments
      summary: Download Consent Attachment
      description: 'Use this API to download a specific file reference attached to a given data subject. The file will be downloaded in .zip format.


        > 🗒 Things to Know

        >

        > - The `attachmentId` parameter value corresponds to the `RefId` parameter value returned after uploading a file using the Upload Consent Attachment API.'
      tags:
      - Consent Attachments
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json
      parameters:
      - name: attachmentId
        in: path
        description: Unique `refId` UUID of the file to be downloaded.
        required: true
        schema:
          type: string
          format: uuid
        example: 550e8400-e29b-41d4-a716-446655440000
      - name: identifier
        in: header
        description: The identifier of the data subject.
        required: true
        schema:
          type: string
        example: user@example.com
      responses:
        '200':
          description: ZIP file containing the requested attachment.
          content:
            application/zip:
              schema:
                description: Binary content of the ZIP file containing the requested attachment.
                type: string
                format: binary
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - DSPreferneceCache_OAUTH2:
        - CONSENT
        - CONSENT_READ
  /rest/api/preferences/v1/attachments-reference/{attachmentId}:
    delete:
      operationId: removeGivenConsentAttachmentRefs
      summary: Remove Consent Attachment
      description: 'Use this API to remove a specific file reference attached to a given data subject.


        > 🗒 Things to Know

        >

        > - The `attachmentId` parameter value corresponds to the `RefId` parameter value returned after uploading a file using the Upload Attachments API.'
      tags:
      - Consent Attachments
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json
      parameters:
      - name: attachmentId
        in: path
        description: Unique referenceId `refId` UUID of the file which has to removed from Data Subject.
        required: true
        schema:
          type: string
          format: uuid
        example: 550e8400-e29b-41d4-a716-446655440000
      - name: identifier
        in: header
        description: The identifier of the data subject.
        required: true
        schema:
          type: string
        example: user@example.com
      responses:
        '202':
          description: Attachment reference deletion request accepted for processing.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DSPreferneceCache_ConsentAttachmentReferencesResponse'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - DSPreferneceCache_OAUTH2:
        - CONSENT
  /rest/api/preferences/v1/datasubjects/{identifier}/attachment-references:
    delete:
      operationId: removeAllConsentAttachmentRefs
      summary: Remove All Consent Attachments
      description: Use this API to remove all file references attached to a given data subject.
      tags:
      - Consent Attachments
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json
      parameters:
      - name: identifier
        in: path
        description: The identifier of the data subject.
        required: true
        schema:
          type: string
        example: user@example.com
      responses:
        '202':
          description: All attachment references deletion request accepted for processing.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DSPreferneceCache_ConsentAttachmentReferencesResponse'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - DSPreferneceCache_OAUTH2:
        - CONSENT
  /rest/api/preferences/v1/datasubjects/{identifier}/attachments:
    get:
      operationId: downloadConsentAttachments
      summary: Download All Consent Attachments
      description: Use this API to retrieve all available file references attached to a given data subject. The files will be downloaded in .zip format.
      tags:
      - Consent Attachments
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json
      parameters:
      - name: identifier
        in: path
        description: The identifier of the data subject.
        required: true
        schema:
          type: string
        example: user@example.com
      responses:
        '200':
          description: ZIP file containing all attachments.
          content:
            application/zip:
              schema:
                description: Binary content of the ZIP file containing all the data subject's attachments.
                type: string
                format: binary
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - DSPreferneceCache_OAUTH2:
        - CONSENT
        - CONSENT_READ
components:
  schemas:
    DSPreferneceCache_UploadDataDto:
      type: object
      properties:
        refId:
          description: Reference ID for the uploaded file.
          type: string
          format: uuid
          example: 550e8400-e29b-41d4-a716-446655440000
        filename:
          description: Original name of the uploaded file.
          type: string
          example: consent_form.pdf
        fileSize:
          description: Size of the uploaded file in bytes.
          type: integer
          format: int64
          example: 1024
        contentType:
          description: MIME type of the uploaded file.
          type: string
          example: application/pdf
        qualifiedName:
          description: Fully qualified name/path of the uploaded file in storage.
          type: string
          example: tenant123/attachments/consent_form.pdf
    DSPreferneceCache_ConsentAttachmentReferencesResponse:
      type: object
      properties:
        identifier:
          description: Identifier of the data subject
          type: string
          example: user@example.com
        statusMessage:
          description: Status message describing the result of the operation
          type: string
          example: Attachment references deletion Request has been accepted for processing
  securitySchemes:
    ConsentPreferences-UniversalConsentPreferenceManag_OAUTH2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://{hostname}/api/access/v1/oauth/token
          scopes:
            CONSENT: Consent Scope gives the user access to read/write operations
            CONSENT_READ: Consent Read Scope gives the user read-only access
    ConsentAPI_OAUTH2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://{hostname}/api/access/v1/oauth/token
          scopes:
            CONSENT: Consent Scope gives the user access to read/write operations
            CONSENT_READ: Consent Read Scope gives the user read-only access
    DSPreferneceCache_OAUTH2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://{hostname}/api/access/v1/oauth/token
          scopes:
            CONSENT: Consent Scope gives the user access to read/write operations
            CONSENT_READ: Consent Read Scope gives the user read-only access
x-readme:
  explorer-enabled: false
  proxy-enabled: false
  metrics-enabled: false
x-onetrust:
  spec-label: OpenAPI 3.1.0