OneTrust OAuth Token API

APIs to manage OAuth 2.0 authentication for secure API access. Generate access tokens using client credentials, retrieve token information, and manage API authentication for your applications.

Operations 1

POST /api/access/v1/oauth/token Generate Access Token #

Documentation

📖
Documentation
https://developer.onetrust.com/onetrust/reference/attribute-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/activity-log
📖
Documentation
https://developer.onetrust.com/onetrust/reference/preferences-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/banner
📖
Documentation
https://developer.onetrust.com/onetrust/reference/consent-receipts
📖
Documentation
https://developer.onetrust.com/onetrust/reference/applications
📖
Documentation
https://developer.onetrust.com/onetrust/reference/categorizations
📖
Documentation
https://developer.onetrust.com/onetrust/reference/domain-data
📖
Documentation
https://developer.onetrust.com/onetrust/reference/preferences
📖
Documentation
https://developer.onetrust.com/onetrust/reference/mobile-app-data
📖
Documentation
https://developer.onetrust.com/onetrust/reference/privacy-notice-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/collection-points
📖
Documentation
https://developer.onetrust.com/onetrust/reference/catalog-search-v1
📖
Documentation
https://developer.onetrust.com/onetrust/reference/classification
📖
Documentation
https://developer.onetrust.com/onetrust/reference/custom-scan
📖
Documentation
https://developer.onetrust.com/onetrust/reference/carbon-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/audit-records
📖
Documentation
https://developer.onetrust.com/onetrust/reference/bulk-export
📖
Documentation
https://developer.onetrust.com/onetrust/reference/attachments
📖
Documentation
https://developer.onetrust.com/onetrust/reference/system-credentials
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory-relationships-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/model-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/tasks
📖
Documentation
https://developer.onetrust.com/onetrust/reference/groups-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/assessment-actions
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory-1
📖
Documentation
https://developer.onetrust.com/onetrust/reference/drop-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/incidents
📖
Documentation
https://developer.onetrust.com/onetrust/reference/document-controller
📖
Documentation
https://developer.onetrust.com/onetrust/reference/audits
📖
Documentation
https://developer.onetrust.com/onetrust/reference/initiatives
📖
Documentation
https://developer.onetrust.com/onetrust/reference/document-attachments
📖
Documentation
https://developer.onetrust.com/onetrust/reference/issues
📖
Documentation
https://developer.onetrust.com/onetrust/reference/control-implementations
📖
Documentation
https://developer.onetrust.com/onetrust/reference/training
📖
Documentation
https://developer.onetrust.com/onetrust/reference/contracts

Specifications

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/onetrust-oauth-token-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

onetrust-oauth-token-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Platform - Access Management OAuth Token API
  version: '1.0'
  contact:
    name: OneTrust Support
    url: https://my.onetrust.com/s/contactsupport
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  description: The Access Management APIs enable you to programmatically control user access, manage organizational hierarchies, and monitor authentication activities across your OneTrust platform.
servers:
- url: https://{hostname}
  variables:
    hostname:
      default: hostname
      description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com.
tags:
- name: OAuth Token
  description: APIs to manage OAuth 2.0 authentication for secure API access. Generate access tokens using client credentials, retrieve token information, and manage API authentication for your applications.
  externalDocs:
    description: OpenAPI 3.1.0 - Download Definition
    url: https://developer.onetrust.com/onetrust/openapi/platform-access-management.json
  x-displayName: OAuth Token
paths:
  /api/access/v1/oauth/token:
    post:
      operationId: GetOAuthToken
      summary: Generate Access Token
      description: 'Use this API to generate an OAuth access token using the `client_credentials` grant type.


        > 🗒 Things to Know

        >

        > - Client credentials can be generated from within Global Settings in the OneTrust application. For more information, see Managing OAuth 2.0 Client Credentials.

        > - Use the `client_id` and `client_secret` to generate the OAuth access token using this API.

        > - A maximum of 500 OAuth 2.0 client credentials can be created per account.'
      tags:
      - OAuth Token
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/platform-access-management.json
      requestBody:
        required: true
        content:
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/Platform-AccessManagement_ClientCredentialsRequest'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Platform-AccessManagement_ClientCredentialsResponse'
              example:
                access_token: eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJyb2xlIjoiQXBpIEtleSBVc2VyIiwidXNlcl9uYW1lIjoiMGI2ZDRlMjI3ZDAxNGM5YzkwZjdkOWE1NGZjOTVjOTVAYXBpLm9uZXRydXN0LmNvbSIsImxhbmd1YWdlSWQiOjEsInNlc3Npb25JZCI6ImRlOGEzZDUxLTFiMTYtNGM5ZS1hODNhLWZkZDUwOWI4YmNiZSIsInRlbmFudEd1aWQiOiIwYjZkNGUyMi03ZDAxLTRjOWMtOTBmNy1kOWE1NGZjOTVjOTUiLCJjbGllbnRfaWQiOiIzMWJiMjBmOGUzYjU0N2YwYjc1MzY2NWVjODMxNmFkYyIsIm9yZ0dyb3VwSWQiOiJjZjQzMTljMi03MmQ1LTRlMjgtOGIwNy1kY2FhMmI3YTBkYzUiLCJvcmdHcm91cEd1aWQiOiJjZjQzMTljMi03MmQ1LTRlMjgtOGIwNy1kY2FhMmI3YTBkYzUiLCJvdC1zY29wZXMiOiJBU1NFU1NNRU5ULEFTU0VTU01FTlRfUkVBRCxDT05TRU5ULENPTlNFTlRfUkVBRCxDT05UUk9MLENPT0tJRSxDT09LSUVfUkVBRCIsInNjb3BlIjpbInJlYWQiXSwidGVuYW50SWQiOjM2LCJndWlkIjoiMGRmY2RiMjItZGNlNS00NWI5LWJlYTctNmNmZTQwMGFkZDJkIiwiZXhwIjoxNjM5MjU5Nzg4LCJqdGkiOiIwNzE1OGVkYi1mZjdkLTRkZjktYjQxYS0xZTRhMjgzZmE3N2EiLCJlbWFpbCI6IjBiNmQ0ZTIyN2QwMTRjOWM5MGY3ZDlhNTRmYzk1Yzk1QGFwaS5vbmV0cnVzdC5jb20ifQ.Hrzgo-vEE073wxkXtJDLKGRjAr2iT4G3EsyISr7x1brLLUuAojWWEGO1ue4RWfntUjEDYC9UAxpMbuP2Xv5ymqUartufj6YwamAqKdGd9gijaoGTXSNvE6ALSCqGOz8owpjh10Qu7nmBnSfzvmkSAD0dJKofJGvGd6IUC21eAU9rcX16R7hbGdmvSWtX7pzjwrZ72CcnLtwCSg7-XJhNB24dY_-iaftBu_vsw3Lr6nddMOGMfXtUl8bPN_ptmXcF4bA-7y2Vw7xEKYVKreKuQsiMAJ2a2aKiRVmHE1RFbyp2R-Z2soqkUL_DQxKZMeU9ehX8NDcmZ_JmtzemgeaoPQ
                email: 0b6d4e227d014c9c90f7d9a54fc95c95@api.onetrust.com
                expires_in: 31535999
                guid: 0dfcdb22-dce5-45b9-bea7-6cfe400add2d
                jti: U3TACUsO6qB_19J1ueRBUGqXRL0
                languageId: 1
                orgGroupGuid: cf4319c2-72d5-4e28-8b07-dcaa2b7a0dc5
                orgGroupId: cf4319c2-72d5-4e28-8b07-dcaa2b7a0dc5
                ot-scopes: ASSESSMENT,ASSESSMENT_READ,ATTACHMENT,ATTACHMENT_READ,AUDIT_MANAGEMENT,CONSENT,CONSENT_READ,CONTROL,COOKIE,COOKIE_READ,DATA_CATALOG_READ,DATA_DISCOVERY,DSAR_READ,DSAR_WRITE,INCIDENT,INCIDENT_CREATE,INCIDENT_READ,INTEGRATIONS,INVENTORY,INVENTORY_READ,INVENTORY_WRITE,ITRM,ORGANIZATION,POLICY,RISK,SCIM,USER,VRM,VRM_READ
                role: Api Key User
                scope: read
                sessionId: de8a3d51-1b16-4c9e-a83a-fdd509b8bcbe
                tenantGuid: 0b6d4e22-7d01-4c9c-90f7-d9a54fc95c95
                tenantId: 36
                token_type: bearer
                user_name: 0b6d4e227d014c9c90f7d9a54fc95c95@api.onetrust.com
        '400':
          description: 'Bad Request


            ### Possible Reasons:

            * Invalid `grant_type`

            '
        '401':
          description: 'Unauthorized


            ### Possible Reasons:

            * Invalid client credentials

            '
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
components:
  schemas:
    Platform-AccessManagement_ClientCredentialsResponse:
      type: object
      properties:
        access_token:
          description: The OAuth access token for API authentication.
          type: string
        email:
          description: The API user email in the format tenantGuid@api.onetrust.com.
          type: string
          format: email
        expires_in:
          description: The token lifetime in seconds.
          type: integer
          format: int32
        guid:
          description: A unique identifier for this token session.
          type: string
          format: uuid
        jti:
          description: The JWT identifier for this token.
          type: string
        languageId:
          description: The numeric identifier for the user's language.
          type: integer
          format: int32
        orgGroupGuid:
          description: The unique identifier of the organization where the credential was created.
          type: string
          format: uuid
        orgGroupId:
          description: The unique identifier of the organization.
          type: string
          format: uuid
        ot_scopes:
          description: The API scopes granted to this credential.
          type: string
        role:
          description: The user role associated with this token.
          type: string
        scope:
          description: The OAuth scope for this token.
          type: string
        sessionId:
          description: The unique identifier for this API session.
          type: string
          format: uuid
        tenantGuid:
          description: The unique identifier of your OneTrust tenant.
          type: string
        tenantId:
          description: The numeric identifier of your OneTrust tenant.
          type: integer
          format: int32
        token_type:
          description: The type of token. Always 'bearer'.
          type: string
        user_name:
          description: The API username in the format tenantGuid@api.onetrust.com.
          type: string
          format: email
    Platform-AccessManagement_ClientCredentialsRequest:
      type: object
      properties:
        grant_type:
          description: The OAuth grant type. Always use 'client_credentials'.
          type: string
          default: client_credentials
          enum:
          - client_credentials
        client_id:
          description: Your OneTrust client credential identifier.
          type: string
          default: 3d8efc3b94ed49628482eb2ab5e3bc8g
        client_secret:
          description: Your OneTrust client credential secret key.
          type: string
          default: Ycx7HNUbHWyPBZvT4WhjYyIvnEdQL3d4
      required:
      - client_id
      - client_secret
      - grant_type
  securitySchemes:
    Platform-AccessManagement_OAUTH2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://{hostname}/api/access/v1/oauth/token
          scopes:
            ORGANIZATION: Grants full access to manage organizations. This includes Create, Read, Update and Delete operations.
            USER: Grants full access to manage Users, User Groups and User Group membership. This includes Create, Read, Update and Delete operations.
    AuditRecords_OAUTH2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://{hostname}/api/access/v1/oauth/token
          scopes:
            USER: Grants full access to manage Users, User Groups and User Group membership. This includes Create, Read, Update and Delete operations.
x-readme:
  explorer-enabled: false
  proxy-enabled: false
  metrics-enabled: false
x-onetrust:
  spec-label: OpenAPI 3.1.0