OneTrust Scan Profiles API

APIs to handle scan profile lifecycle management including creation, updates, deletion, and retrieval with support for catalog and catalog-scan types across various system platforms.

Operations 5

GET /api/discovery-scan-config/v2/scan-profiles Get List of Scan Profiles #
PUT /api/discovery-scan-config/v2/scan-profiles Update Scan Profile #
POST /api/discovery-scan-config/v2/scan-profiles Create Scan Profile #
GET /api/discovery-scan-config/v2/scan-profiles/{scanProfileId} Get Scan Profile #
DELETE /api/discovery-scan-config/v2/scan-profiles/{scanProfileId} Delete Scan Profile #

Documentation

📖
Documentation
https://developer.onetrust.com/onetrust/reference/attribute-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/activity-log
📖
Documentation
https://developer.onetrust.com/onetrust/reference/preferences-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/banner
📖
Documentation
https://developer.onetrust.com/onetrust/reference/consent-receipts
📖
Documentation
https://developer.onetrust.com/onetrust/reference/applications
📖
Documentation
https://developer.onetrust.com/onetrust/reference/categorizations
📖
Documentation
https://developer.onetrust.com/onetrust/reference/domain-data
📖
Documentation
https://developer.onetrust.com/onetrust/reference/preferences
📖
Documentation
https://developer.onetrust.com/onetrust/reference/mobile-app-data
📖
Documentation
https://developer.onetrust.com/onetrust/reference/privacy-notice-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/collection-points
📖
Documentation
https://developer.onetrust.com/onetrust/reference/catalog-search-v1
📖
Documentation
https://developer.onetrust.com/onetrust/reference/classification
📖
Documentation
https://developer.onetrust.com/onetrust/reference/custom-scan
📖
Documentation
https://developer.onetrust.com/onetrust/reference/carbon-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/audit-records
📖
Documentation
https://developer.onetrust.com/onetrust/reference/bulk-export
📖
Documentation
https://developer.onetrust.com/onetrust/reference/attachments
📖
Documentation
https://developer.onetrust.com/onetrust/reference/system-credentials
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory-relationships-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/model-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/tasks
📖
Documentation
https://developer.onetrust.com/onetrust/reference/groups-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/assessment-actions
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory-1
📖
Documentation
https://developer.onetrust.com/onetrust/reference/drop-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/incidents
📖
Documentation
https://developer.onetrust.com/onetrust/reference/document-controller
📖
Documentation
https://developer.onetrust.com/onetrust/reference/audits
📖
Documentation
https://developer.onetrust.com/onetrust/reference/initiatives
📖
Documentation
https://developer.onetrust.com/onetrust/reference/document-attachments
📖
Documentation
https://developer.onetrust.com/onetrust/reference/issues
📖
Documentation
https://developer.onetrust.com/onetrust/reference/control-implementations
📖
Documentation
https://developer.onetrust.com/onetrust/reference/training
📖
Documentation
https://developer.onetrust.com/onetrust/reference/contracts

Specifications

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/onetrust-scan-profiles-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

onetrust-scan-profiles-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Data Use Governance - Data Discovery Scan Profiles API
  version: '1.0'
  contact:
    name: OneTrust Support
    url: https://my.onetrust.com/s/contactsupport
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  description: The Data Discovery API provides comprehensive REST endpoints for managing data discovery operations including data sources, scan profiles, credentials, and scan jobs with OAuth2 security and extensive filtering capabilities.
servers:
- url: https://{hostname}
  variables:
    hostname:
      default: hostname
      description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com.
tags:
- name: Scan Profiles
  description: APIs to handle scan profile lifecycle management including creation, updates, deletion, and retrieval with support for catalog and catalog-scan types across various system platforms.
  externalDocs:
    description: OpenAPI 3.1.0 - Download Definition
    url: https://developer.onetrust.com/onetrust/openapi/data-use-governance-data-discovery.json
  x-displayName: Scan Profiles
paths:
  /api/discovery-scan-config/v2/scan-profiles:
    get:
      operationId: getAllUsingGET_2
      summary: Get List of Scan Profiles
      description: Use this API to retrieve a list of all scan profiles. The response will include details for each scan profile along with the corresponding scan profile ID and its associated scan type, system, and paths.
      tags:
      - Scan Profiles
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/data-use-governance-data-discovery.json
      parameters:
      - name: search
        in: query
        description: The parameter to search for a scan profile by name.
        required: false
        schema:
          type: string
        example: MySQL Profile
      - name: systemName
        in: query
        description: A system name. Include to filter results to be limited to scan profiles with this system. Some examples are "Box", "Snowflake", and "MongoDB".
        required: false
        schema:
          type: string
          enum:
          - Azure Cosmos
          - Box
          - Cassandra
          - Azure Databricks
          - IBM DB2
          - Exchange
          - GCP
          - Google Workspace Gmail
          - Google BigQuery
          - Google BigTable
          - MongoDB
          - MySQL
          - OneDrive
          - Oracle RDBMS
          - PostgreSQL
          - Amazon S3
          - SalesForce
          - SAP HANA
          - ServiceNow
          - SharePoint
          - SMB
          - Snowflake
          - Microsoft SQL
          - Teradata
          - Workday
          - Zendesk
          - Amazon RDS for SQL Server
          - Azure SQL Server
          - Redshift
          - Google Drive
          - Amazon DynamoDB
          - Amazon Athena
          - SharePoint 2019 OnPrem
          - SFTP
          - NFS
          - GCS
          - Redis
          - Elastic Search
          - Microsoft Teams
          - Slack
          - AlibabaCloudOSS
          - Azure Files
          - Iceberg
          - Kafka
        example: MySQL
      - name: scanType
        in: query
        description: It is the scan profile type.
        required: false
        schema:
          type: string
          enum:
          - CATALOG
          - CATALOG_SCAN
          - OFFSET_REPORT
        example: CATALOG
      - name: createdFrom
        in: query
        description: Include a date (yyyy-mm-dd) to filter the results to scan profiles created on or after the specified date. For example, including the parameter createdFrom=2021-08-17 will filter results to scan profiles on or after August 17th, 2021.
        required: false
        schema:
          type: string
          format: date-time
        example: '2021-09-11T01:41:50.143+00:00'
      - name: createdTo
        in: query
        description: Include a date (yyyy-mm-dd) to filter the results to scan profiles created on or before the specified date. For example, including the parameter createdTo=2021-08-17 would filter results to scan profiles on or before August 17th, 2021.
        required: false
        schema:
          type: string
          format: date-time
        example: '2021-09-11T02:41:50.143+00:00'
      - name: page
        in: query
        description: Results page to be retrieved (0..N).
        schema:
          description: Results page to be retrieved (0..N).
          type: integer
          format: int32
          default: 0
          minimum: 0
        example: 1
      - name: size
        in: query
        description: Number of records per page (1..50). Maximum page size allowed is 50
        schema:
          description: Number of records per page (1..50). Maximum page size allowed is 50
          type: integer
          format: int32
          default: 20
          maximum: 50
          minimum: 1
        example: 20
      - name: sort
        in: query
        description: 'Sorting criteria in the format: property(,asc|desc). Default is ascending.'
        schema:
          description: 'Sorting criteria in the format: property(,asc|desc). Default is ascending.'
          type: string
          default: createdDate,desc
          enum:
          - name,asc
          - name,desc
          - systemName,asc
          - systemName,desc
          - scanType,asc
          - scanType,desc
          - createdDate,asc
          - createdDate,desc
        example: name,desc
      responses:
        '200':
          description: Successfully retrieved scan profiles
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DataUseGovernance-DataDiscovery_PageWrapperScanProfileDto'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - DataUseGovernance-DataDiscovery_OAUTH2:
        - DATA_DISCOVERY
    put:
      operationId: updateV2UsingPUT
      summary: Update Scan Profile
      description: Use this API to update an existing scan profile.
      tags:
      - Scan Profiles
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/data-use-governance-data-discovery.json
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/DataUseGovernance-DataDiscovery_ScanProfileV2Dto'
      responses:
        '200':
          description: Scan Profile updated successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DataUseGovernance-DataDiscovery_ScanProfileV2Dto'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - DataUseGovernance-DataDiscovery_OAUTH2:
        - DATA_DISCOVERY
    post:
      operationId: createV2UsingPOST
      summary: Create Scan Profile
      description: Use this API to create a new scan profile.
      tags:
      - Scan Profiles
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/data-use-governance-data-discovery.json
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/DataUseGovernance-DataDiscovery_ScanProfileRequestV2Dto'
      responses:
        '201':
          description: Scan Profile created successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DataUseGovernance-DataDiscovery_ScanProfileV2Dto'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - DataUseGovernance-DataDiscovery_OAUTH2:
        - DATA_DISCOVERY
  /api/discovery-scan-config/v2/scan-profiles/{scanProfileId}:
    get:
      operationId: getScanProfileUsingGET_1
      summary: Get Scan Profile
      description: Use this API to retrieve a single scan profile by its unique identifier along with the associated scan type, system, and paths.
      tags:
      - Scan Profiles
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/data-use-governance-data-discovery.json
      parameters:
      - name: scanProfileId
        in: path
        description: ID of a scan profile. This value can be obtained from Get All Scan Profiles API. Must be a valid UUID.
        required: true
        schema:
          type: string
          format: uuid
        example: ad390cb4-9ce9-4976-8895-66d724493c7b
      responses:
        '200':
          description: Scan Profile retrieved successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DataUseGovernance-DataDiscovery_ScanProfileV2Dto'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - DataUseGovernance-DataDiscovery_OAUTH2:
        - DATA_DISCOVERY
    delete:
      operationId: deleteScanProfileUsingDELETE_1
      summary: Delete Scan Profile
      description: Use this API to delete an existing scan profile.
      tags:
      - Scan Profiles
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/data-use-governance-data-discovery.json
      parameters:
      - name: scanProfileId
        in: path
        description: ID of a scan profile. This value can be obtained from Get All Scan Profiles API. Must be a valid UUID.
        required: true
        schema:
          type: string
          format: uuid
        example: ad390cb4-9ce9-4976-8895-66d724493c7b
      responses:
        '204':
          description: Scan Profile deleted successfully
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - DataUseGovernance-DataDiscovery_OAUTH2:
        - DATA_DISCOVERY
components:
  schemas:
    DataUseGovernance-DataDiscovery_Sort:
      type: object
      properties:
        sort:
          type: array
          items:
            type: string
    DataUseGovernance-DataDiscovery_PageWrapperScanProfileDto:
      type: object
      properties:
        content:
          description: The content of this page.
          example:
          - id: 1
            name: Item
          items:
            $ref: '#/components/schemas/DataUseGovernance-DataDiscovery_ScanProfileV2Dto'
          type: array
        number:
          description: Current page number.
          type: integer
          format: int32
          example: 0
        size:
          description: The size of the page (number of elements per page).
          type: integer
          format: int32
          example: 20
        numberOfElements:
          description: The number of elements on the current page.
          type: integer
          format: int32
          example: 15
        totalElements:
          description: The total number of elements across all pages.
          type: integer
          format: int32
          example: 150
        totalPages:
          description: The total number of pages.
          type: integer
          format: int32
          example: 8
        first:
          description: Indicates if this is the first page.
          type: boolean
          example: true
        last:
          description: Indicates if this is the last page.
          type: boolean
          example: false
        empty:
          description: Indicates if the page is empty.
          type: boolean
          example: false
        sort:
          description: Sorting information for the page.
          $ref: '#/components/schemas/DataUseGovernance-DataDiscovery_Sort'
        pageable:
          description: Pagination information for the page.
          $ref: '#/components/schemas/DataUseGovernance-DataDiscovery_Pageable'
    DataUseGovernance-DataDiscovery_Pageable:
      type: object
      properties:
        page:
          type: integer
          format: int32
          minimum: 0
        size:
          type: integer
          format: int32
          minimum: 1
        sort:
          type: array
          items:
            type: string
    DataUseGovernance-DataDiscovery_ScanProfileV2Dto:
      type: object
      properties:
        id:
          description: Unique ID for Scan Profile
          type: string
          format: uuid
          example: 4f162d7c-a563-4bf1-a7c4-b7899f6dcdef
        name:
          description: Name of Scan Profile
          type: string
          example: My SQL Scan Profile
        scanType:
          description: Scan Type of Scan Profile
          type: string
          example: CATALOG
          enum:
          - CATALOG
          - CATALOG_SCAN
        sourceType:
          description: Source of this Scan Profile
          type: string
          example: USER_DEFINED
          enum:
          - SEED
          - USER_DEFINED
        systemName:
          description: System Name of Scan Profile
          type: string
          example: MySQL
        scanProfileContext:
          description: Properties of Scan Profile Specific to System
          type: object
          example:
            type: MySQL
            includes:
            - database: OT
              table: Employee
              columns: Name
            excludes:
            - database: OT
              table: Credential
              columns: Id
            samplingScan:
              enableSampling: false
            tableLimits:
              randomize: false
              maxCount: 10
            tableTypes:
            - TABLE
            databaseLimits:
              randomize: false
              maxCount: 1
        systemType:
          description: System Type of Scan Profile
          type: string
          example: RELATIONAL_DATABASE
          enum:
          - RELATIONAL_DATABASE
          - NON_RELATIONAL_DATABASE
          - FILE
          - API
          - CUSTOM
          - UNKNOWN
          - CLOUD_PLATFORM
          - MACHINE_LEARNING_PLATFORM
        createdDate:
          description: Creation Date of Scan Profile
          type: string
          format: date-time
          example: '2021-09-11T01:41:50.143+00:00'
        displayName:
          description: Display Name for System Name of Scan Profile
          type: string
          example: Amazon Redshift
      required:
      - id
      - name
      - scanProfileContext
      - scanType
      - systemName
      - systemType
    DataUseGovernance-DataDiscovery_ScanProfileRequestV2Dto:
      type: object
      properties:
        name:
          description: Name of Scan Profile
          type: string
          example: My SQL Scan Profile
        scanType:
          description: Scan Type of Scan Profile
          type: string
          example: CATALOG
          enum:
          - CATALOG
          - CATALOG_SCAN
        systemName:
          description: System Name of Scan Profile
          type: string
          example: MySQL
        scanProfileContext:
          description: Properties of Scan Profile Specific to System
          type: object
          example:
            type: MySQL
            includes: []
            excludes: []
            dsarExtract: true
            clearingIndex: true
            databaseLimits:
              randomize: false
              maxCount: null
              maxPercentage: null
            tableLimits:
              randomize: false
              maxCount: null
              maxPercentage: null
            rowLimits:
              randomize: false
              maxCount: null
              maxPercentage: null
            customQuery: null
            tableTypes:
            - TABLE
        systemType:
          description: System Type of Scan Profile
          type: string
          example: RELATIONAL_DATABASE
          enum:
          - RELATIONAL_DATABASE
          - NON_RELATIONAL_DATABASE
          - FILE
          - API
          - CUSTOM
          - UNKNOWN
          - CLOUD_PLATFORM
          - MACHINE_LEARNING_PLATFORM
        displayName:
          description: Display Name for System Name of Scan Profile
          type: string
          example: Amazon Redshift
      required:
      - name
      - scanProfileContext
      - scanType
      - systemName
      - systemType
  securitySchemes:
    DataUseGovernance-DataDiscovery_OAUTH2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://{hostname}/api/access/v1/oauth/token
          scopes:
            DATA_DISCOVERY: DATA_DISCOVERY scope for external systems
    DataUseGovernance-DataDiscoveryCustomClassiferMana_OAUTH2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://{hostname}/api/access/v1/oauth/token
          scopes:
            DATA_DISCOVERY: DATA_DISCOVERY scope for external systems
x-readme:
  explorer-enabled: false
  proxy-enabled: false
  metrics-enabled: false
x-onetrust:
  spec-label: OpenAPI 3.1.0