OneTrust Inventory Hierarchies API

APIs used to list, link, and unlink child inventories under a root inventory to model organizational or data-flow trees.

Operations 8

PUT /api/inventory/v2/inventories/{inventoryId}/set-as-parent Set Inventory as Parent #
PUT /api/inventory/v2/inventories/{inventoryId}/unset-as-parent Unset Inventory as Parent #
POST /api/inventory/v2/inventories/{parentInventoryId}/link-assets Add Asset Inventory as Child to Parent Inventory #
POST /api/inventory/v2/inventories/{parentInventoryId}/link-legal-entities Add Legal Entity Inventory as Child to Parent Inventory #
POST /api/inventory/v2/inventories/{parentInventoryId}/link-processing-activities Add Processing Activity Inventory as Child to Parent Inventory #
POST /api/inventory/v2/inventories/{parentInventoryId}/link-vendors Add Vendor Inventory as Child to Parent Inventory #
GET /api/inventory/v2/inventory-hierarchies/{rootInventoryId} Get List of Child Inventories by Root Inventory #
DELETE /api/inventory/v2/inventory-hierarchies/{rootInventoryId} Remove Child Inventory from Root Inventory #

Documentation

📖
Documentation
https://developer.onetrust.com/onetrust/reference/attribute-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/activity-log
📖
Documentation
https://developer.onetrust.com/onetrust/reference/preferences-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/banner
📖
Documentation
https://developer.onetrust.com/onetrust/reference/consent-receipts
📖
Documentation
https://developer.onetrust.com/onetrust/reference/applications
📖
Documentation
https://developer.onetrust.com/onetrust/reference/categorizations
📖
Documentation
https://developer.onetrust.com/onetrust/reference/domain-data
📖
Documentation
https://developer.onetrust.com/onetrust/reference/preferences
📖
Documentation
https://developer.onetrust.com/onetrust/reference/mobile-app-data
📖
Documentation
https://developer.onetrust.com/onetrust/reference/privacy-notice-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/collection-points
📖
Documentation
https://developer.onetrust.com/onetrust/reference/catalog-search-v1
📖
Documentation
https://developer.onetrust.com/onetrust/reference/classification
📖
Documentation
https://developer.onetrust.com/onetrust/reference/custom-scan
📖
Documentation
https://developer.onetrust.com/onetrust/reference/carbon-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/audit-records
📖
Documentation
https://developer.onetrust.com/onetrust/reference/bulk-export
📖
Documentation
https://developer.onetrust.com/onetrust/reference/attachments
📖
Documentation
https://developer.onetrust.com/onetrust/reference/system-credentials
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory-relationships-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/model-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/tasks
📖
Documentation
https://developer.onetrust.com/onetrust/reference/groups-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/assessment-actions
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory-1
📖
Documentation
https://developer.onetrust.com/onetrust/reference/drop-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/incidents
📖
Documentation
https://developer.onetrust.com/onetrust/reference/document-controller
📖
Documentation
https://developer.onetrust.com/onetrust/reference/audits
📖
Documentation
https://developer.onetrust.com/onetrust/reference/initiatives
📖
Documentation
https://developer.onetrust.com/onetrust/reference/document-attachments
📖
Documentation
https://developer.onetrust.com/onetrust/reference/issues
📖
Documentation
https://developer.onetrust.com/onetrust/reference/control-implementations
📖
Documentation
https://developer.onetrust.com/onetrust/reference/training
📖
Documentation
https://developer.onetrust.com/onetrust/reference/contracts

Specifications

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/onetrust-inventory-hierarchies-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

onetrust-inventory-hierarchies-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Privacy Automation - Data Mapping Automation Inventory…
  version: '1.0'
  contact:
    name: OneTrust Support
    url: https://my.onetrust.com/s/contactsupport
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  description: The Data Mapping Automation APIs are used to manage structured records (assets, vendors, processing activities, and legal entities), define schema attributes, traverse parent–child hierarchies, and create cross-record relationships—including links to personal data.
servers:
- url: https://{hostname}
  variables:
    hostname:
      default: hostname
      description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com.
tags:
- name: Inventory Hierarchies
  description: APIs used to list, link, and unlink child inventories under a root inventory to model organizational or data-flow trees.
  externalDocs:
    description: OpenAPI 3.1.0 - Download Definition
    url: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-mapping-automation.json
paths:
  /api/inventory/v2/inventories/{inventoryId}/set-as-parent:
    put:
      operationId: setInventoryAsParentInventoryUsingPUT
      summary: Set Inventory as Parent
      description: Use this API to set an existing inventory as a Parent inventory.
      tags:
      - Inventory Hierarchies
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-mapping-automation.json
      parameters:
      - name: inventoryId
        in: path
        description: The unique identifier of the inventory to set as parent
        required: true
        schema:
          type: string
          format: uuid
        example: c4bee781-912b-4328-8851-6f906afd7ccb
      - name: inventoryType
        in: query
        description: The type of inventory (e.g., assets, vendors, processing-activities, legal-entities)
        required: true
        schema:
          type: string
          enum:
          - processing-activities
          - vendors
          - assets
          - entities
        example: assets
      responses:
        '201':
          description: Created
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - OAUTH2:
        - INVENTORY
        - INVENTORY_WRITE
  /api/inventory/v2/inventories/{inventoryId}/unset-as-parent:
    put:
      operationId: unsetInventoryAsParentInventoryUsingPUT
      summary: Unset Inventory as Parent
      description: Use this API to unset an existing inventory from being a Parent inventory.
      tags:
      - Inventory Hierarchies
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-mapping-automation.json
      parameters:
      - name: inventoryId
        in: path
        description: The unique identifier of the inventory to unset as parent
        required: true
        schema:
          type: string
          format: uuid
        example: c4bee781-912b-4328-8851-6f906afd7ccb
      - name: inventoryType
        in: query
        description: The type of inventory (e.g., assets, vendors, processing-activities, legal-entities)
        required: true
        schema:
          type: string
          enum:
          - processing-activities
          - vendors
          - assets
          - entities
        example: assets
      responses:
        '201':
          description: Created
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - OAUTH2:
        - INVENTORY
        - INVENTORY_WRITE
  /api/inventory/v2/inventories/{parentInventoryId}/link-assets:
    post:
      operationId: linkAssetInventoryToParentAssetIdUsingPOST
      summary: Add Asset Inventory as Child to Parent Inventory
      description: Use this API to link an existing asset inventory as a child inventory to a parent asset inventory.
      tags:
      - Inventory Hierarchies
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-mapping-automation.json
      parameters:
      - name: parentInventoryId
        in: path
        description: The unique identifier of the parent asset inventory
        required: true
        schema:
          type: string
          format: uuid
        example: 96214230-ffbb-4870-b6c4-0f30c3bfec60
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: array
              items:
                type: string
                format: uuid
            examples:
              childInventoryIds:
                description: childInventoryIds
                value:
                - 96214230-ffbb-4870-b6c4-0f30c3bfec60
                - a1b2c3d4-e5f6-7890-abcd-ef1234567890
      responses:
        '201':
          description: Created
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - OAUTH2:
        - INVENTORY
        - INVENTORY_WRITE
  /api/inventory/v2/inventories/{parentInventoryId}/link-legal-entities:
    post:
      operationId: linkLegalEntityInventoryToParentLegalEntityIdUsingPOST
      summary: Add Legal Entity Inventory as Child to Parent Inventory
      description: Use this API to link an existing legal entity inventory as a child inventory to a parent legal entity inventory.
      tags:
      - Inventory Hierarchies
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-mapping-automation.json
      parameters:
      - name: parentInventoryId
        in: path
        description: The unique identifier of the parent legal entity inventory
        required: true
        schema:
          type: string
          format: uuid
        example: 96214230-ffbb-4870-b6c4-0f30c3bfec60
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: array
              items:
                type: string
                format: uuid
            examples:
              childInventoryIds:
                description: childInventoryIds
                value:
                - 96214230-ffbb-4870-b6c4-0f30c3bfec60
                - a1b2c3d4-e5f6-7890-abcd-ef1234567890
      responses:
        '201':
          description: Created
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - OAUTH2:
        - INVENTORY
        - INVENTORY_WRITE
  /api/inventory/v2/inventories/{parentInventoryId}/link-processing-activities:
    post:
      operationId: linkProcessingActivityInventoryToParentProcessingActivityIdUsingPOST
      summary: Add Processing Activity Inventory as Child to Parent Inventory
      description: Use this API to link an existing processing activity inventory as a child inventory to a parent processing activity inventory.
      tags:
      - Inventory Hierarchies
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-mapping-automation.json
      parameters:
      - name: parentInventoryId
        in: path
        description: The unique identifier of the parent processing activity inventory
        required: true
        schema:
          type: string
          format: uuid
        example: 96214230-ffbb-4870-b6c4-0f30c3bfec60
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: array
              items:
                type: string
                format: uuid
            examples:
              childInventoryIds:
                description: childInventoryIds
                value:
                - 96214230-ffbb-4870-b6c4-0f30c3bfec60
                - a1b2c3d4-e5f6-7890-abcd-ef1234567890
      responses:
        '201':
          description: Created
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - OAUTH2:
        - INVENTORY
        - INVENTORY_WRITE
  /api/inventory/v2/inventories/{parentInventoryId}/link-vendors:
    post:
      operationId: linkVendorInventoryToParentVendorIdUsingPOST
      summary: Add Vendor Inventory as Child to Parent Inventory
      description: Use this API to link an existing vendor inventory as a child inventory to a parent vendor inventory.
      tags:
      - Inventory Hierarchies
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-mapping-automation.json
      parameters:
      - name: parentInventoryId
        in: path
        description: The unique identifier of the parent vendor inventory
        required: true
        schema:
          type: string
          format: uuid
        example: 96214230-ffbb-4870-b6c4-0f30c3bfec60
      requestBody:
        required: true
        content:
          application/json:
            schema:
              description: List of child vendor inventory IDs to link to the parent
              type: array
              format: uuid
      responses:
        '201':
          description: Created
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - OAUTH2:
        - INVENTORY
        - INVENTORY_WRITE
  /api/inventory/v2/inventory-hierarchies/{rootInventoryId}:
    get:
      operationId: getHierarchyForInventoryIdUsingGET
      summary: Get List of Child Inventories by Root Inventory
      description: Use this API to provide a paginated list of Child Inventories for a given Inventory Schema Type and a Root Inventory Id.
      tags:
      - Inventory Hierarchies
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-mapping-automation.json
      parameters:
      - name: rootInventoryId
        in: path
        description: The unique identifier of the root inventory
        required: true
        schema:
          type: string
          format: uuid
        example: 96214230-ffbb-4870-b6c4-0f30c3bfec60
      - name: inventoryType
        in: query
        description: The type of inventory (e.g., assets, vendors, processing-activities, legal-entities)
        required: true
        schema:
          type: string
          enum:
          - processing-activities
          - vendors
          - assets
          - entities
        example: assets
      - name: page
        in: query
        description: Results page to be retrieved (0..N)
        schema:
          type: integer
          format: int32
          default: 0
          minimum: 0
        example: 0
      - name: size
        in: query
        description: Number of records per page (1..50)
        schema:
          type: integer
          format: int32
          default: 20
          maximum: 50
          minimum: 1
        example: 20
      - name: sort
        in: query
        description: 'Sorting criteria in the format: property(,asc|desc). Default sort order is ascending'
        schema:
          type: string
          enum:
          - name,asc
          - name,desc
          - createdDate,asc
          - createdDate,desc
        example: name,asc
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: string
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - OAUTH2:
        - INVENTORY
        - INVENTORY_READ
        - INVENTORY_WRITE
    delete:
      operationId: unlinkChildInventoryFromHierarchyUsingDELETE
      summary: Remove Child Inventory from Root Inventory
      description: Use this API to unlink a Child Inventory from a Root Inventory.
      tags:
      - Inventory Hierarchies
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-mapping-automation.json
      parameters:
      - name: rootInventoryId
        in: path
        description: The unique identifier of the root inventory
        required: true
        schema:
          type: string
          format: uuid
        example: 96214230-ffbb-4870-b6c4-0f30c3bfec60
      - name: inventoryType
        in: query
        description: The type of inventory (e.g., assets, vendors, processing-activities, legal-entities)
        required: true
        schema:
          type: string
          enum:
          - processing-activities
          - vendors
          - assets
          - entities
        example: assets
      - name: childInventoryId
        in: query
        description: The unique identifier of the child inventory to unlink
        required: true
        schema:
          type: string
          format: uuid
        example: 6ed251ca-969a-486f-a645-e5fc3c709f55
      responses:
        '204':
          description: No Content
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - OAUTH2:
        - INVENTORY
        - INVENTORY_WRITE
components:
  securitySchemes:
    OAUTH2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://{hostname}/api/access/v1/oauth/token
          scopes:
            INVENTORY: Inventory Scope gives the user access to read/write operations
            INVENTORY_READ: Inventory Read Scope gives the user read-only access
            INVENTORY_WRITE: Inventory Write Scope gives the user write access
x-onetrust:
  spec-label: OpenAPI 3.1.0
  links:
  - '{''Data Mapping Automation Knowledge Base'': ''https://my.onetrust.com/s/topic/0TO1Q000000ItRxWAK/data-mapping-automation''}'
x-readme:
  explorer-enabled: false
  proxy-enabled: false
  metrics-enabled: false