OneTrust Verification Methods API

APIs used to create, update, and retrieve methods for verifying a data subject's identity.

Operations 4

GET /api/datasubject/v2/requestqueues/{requestQueueRefId}/verificationmethods Get List of Verification Methods #
PUT /api/datasubject/v2/requestqueues/{requestQueueRefId}/verificationmethods Update Verification Method #
POST /api/datasubject/v2/requestqueues/{requestQueueRefId}/verificationmethods Create Verification Method #
GET /api/datasubject/v2/requestqueues/{requestQueueRefId}/{methodId} Get Verification Method #

Documentation

📖
Documentation
https://developer.onetrust.com/onetrust/reference/attribute-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/activity-log
📖
Documentation
https://developer.onetrust.com/onetrust/reference/preferences-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/banner
📖
Documentation
https://developer.onetrust.com/onetrust/reference/consent-receipts
📖
Documentation
https://developer.onetrust.com/onetrust/reference/applications
📖
Documentation
https://developer.onetrust.com/onetrust/reference/categorizations
📖
Documentation
https://developer.onetrust.com/onetrust/reference/domain-data
📖
Documentation
https://developer.onetrust.com/onetrust/reference/preferences
📖
Documentation
https://developer.onetrust.com/onetrust/reference/mobile-app-data
📖
Documentation
https://developer.onetrust.com/onetrust/reference/privacy-notice-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/collection-points
📖
Documentation
https://developer.onetrust.com/onetrust/reference/catalog-search-v1
📖
Documentation
https://developer.onetrust.com/onetrust/reference/classification
📖
Documentation
https://developer.onetrust.com/onetrust/reference/custom-scan
📖
Documentation
https://developer.onetrust.com/onetrust/reference/carbon-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/audit-records
📖
Documentation
https://developer.onetrust.com/onetrust/reference/bulk-export
📖
Documentation
https://developer.onetrust.com/onetrust/reference/attachments
📖
Documentation
https://developer.onetrust.com/onetrust/reference/system-credentials
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory-relationships-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/model-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/tasks
📖
Documentation
https://developer.onetrust.com/onetrust/reference/groups-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/assessment-actions
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory-1
📖
Documentation
https://developer.onetrust.com/onetrust/reference/drop-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/incidents
📖
Documentation
https://developer.onetrust.com/onetrust/reference/document-controller
📖
Documentation
https://developer.onetrust.com/onetrust/reference/audits
📖
Documentation
https://developer.onetrust.com/onetrust/reference/initiatives
📖
Documentation
https://developer.onetrust.com/onetrust/reference/document-attachments
📖
Documentation
https://developer.onetrust.com/onetrust/reference/issues
📖
Documentation
https://developer.onetrust.com/onetrust/reference/control-implementations
📖
Documentation
https://developer.onetrust.com/onetrust/reference/training
📖
Documentation
https://developer.onetrust.com/onetrust/reference/contracts

Specifications

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/onetrust-verification-methods-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

onetrust-verification-methods-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Privacy Automation - Data Subject Request (DSR) Automation…
  version: '1.0'
  contact:
    name: OneTrust Support
    url: https://my.onetrust.com/s/contactsupport
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  description: The Privacy Rights Automation are used to manage, process, and fulfill data subject access requests (DSARs), including request creation, subtask management, resolution codes, verification methods, and audit history.
servers:
- url: https://{hostname}
  variables:
    hostname:
      default: hostname
      description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com.
tags:
- name: Verification Methods
  description: APIs used to create, update, and retrieve methods for verifying a data subject's identity.
  externalDocs:
    description: OpenAPI 3.1.0 - Download Definition
    url: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json
  x-displayName: Verification Methods
paths:
  /api/datasubject/v2/requestqueues/{requestQueueRefId}/verificationmethods:
    get:
      operationId: getAllV2VerificationMethodsUsingGET
      summary: Get List of Verification Methods
      description: Use this API to retrieve a list of all verification methods for the specified request. The response will include details for each verification method along with the corresponding ID, description, and created date.
      tags:
      - Verification Methods
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json
      parameters:
      - name: requestQueueRefId
        in: path
        required: true
        schema:
          description: The unique reference ID of the privacy request for which to retrieve verification methods.
          type: string
        example: ZASHMHK2K7
      - name: includeComments
        in: query
        required: true
        schema:
          description: Set to true to include comments and attachments in the response. If false, only basic verification method information will be returned.
          type: boolean
          default: false
        example: true
      - name: page
        in: query
        schema:
          description: Results page you want to retrieve. Page number starts with 0 (0..N)
          type: integer
          format: int32
          default: 0
          minimum: 0
        example: 0
      - name: size
        in: query
        schema:
          description: Number of records per page. Maximum page size allowed is 500
          type: integer
          format: int32
          default: 20
          maximum: 500
          minimum: 1
        example: 20
      - name: sort
        in: query
        schema:
          description: 'Sorting criteria in the format: property(,asc|desc). Default sort order is ascending.'
          type: string
          enum:
          - createdDate,asc
          - createdDate,desc
          - lastModifiedDate,asc
          - lastModifiedDate,desc
        example: createdDate,desc
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_VerificationMethodV2DTO'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2:
        - DSAR
        - DSAR_READ
        - DSAR_WRITE
    put:
      operationId: updateV2VerificationMethodUsingPUT
      summary: Update Verification Method
      description: Use this API to update an existing verification method for a request.
      tags:
      - Verification Methods
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json
      parameters:
      - name: requestQueueRefId
        in: path
        required: true
        schema:
          description: request queue reference id
          type: string
        example: ZASHMHK2K7
      - name: language
        in: query
        required: false
        schema:
          description: Language code
          type: string
        example: en-us
      - name: translate
        in: query
        required: false
        schema:
          description: Whether to translate the content
          type: boolean
          default: false
        example: false
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_VerificationMethodV2DTO'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_VerificationMethodV2DTO'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2:
        - DSAR
        - DSAR_WRITE
    post:
      operationId: createV2VerificationMethodUsingPOST
      summary: Create Verification Method
      description: Use this API to create a new verification method for the specified request.
      tags:
      - Verification Methods
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json
      parameters:
      - name: requestQueueRefId
        in: path
        required: true
        schema:
          description: request queue reference id
          type: string
        example: ZASHMHK2K7
      - name: language
        in: query
        required: false
        schema:
          description: Language code
          type: string
        example: en-us
      - name: translate
        in: query
        required: false
        schema:
          description: Whether to translate the content
          type: boolean
          default: false
        example: false
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_VerificationMethodV2DTO'
      responses:
        '201':
          description: Created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_VerificationMethodV2DTO'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2:
        - DSAR
        - DSAR_WRITE
  /api/datasubject/v2/requestqueues/{requestQueueRefId}/{methodId}:
    get:
      operationId: getAllV2VerificationMethodsByIdUsingGET
      summary: Get Verification Method
      description: Use this API to retrieve a single verification method by its unique identifier for the specified request.
      tags:
      - Verification Methods
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-data-subject-request-dsr-automation.json
      parameters:
      - name: requestQueueRefId
        in: path
        required: true
        schema:
          description: The unique reference ID of the privacy request for which to retrieve the verification method.
          type: string
        example: ZASHMHK2K7
      - name: methodId
        in: path
        required: true
        schema:
          description: The unique identifier of the verification method to retrieve.
          type: string
          format: uuid
        example: e2d0f59e-3df0-4b1f-965d-d57547ed44ad
      - name: includeComments
        in: query
        required: true
        schema:
          description: Set to true to include comments and attachments in the response. If false, only basic verification method information will be returned.
          type: boolean
        example: true
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_VerificationMethodV2DTO'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2:
        - DSAR
        - DSAR_READ
        - DSAR_WRITE
components:
  schemas:
    PrivacyAutomation-DataSubjectRequestDSRAutomation_AttachmentV2Dto:
      type: object
      properties:
        fileName:
          description: Attached file name
          type: string
          example: sample.txt
          maxLength: 200
          minLength: 1
        fileId:
          description: ID of attached file
          type: string
          format: uuid
          example: 3b47744c-eebf-44bb-bf4c-680966a448dc
        statusId:
          description: Status ID of the attachment
          type: integer
          format: int64
          example: 10
        resourcePath:
          description: Resource path of the attachment
          type: string
          example: /storage/attachments/sample.txt
          maxLength: 1000
      required:
      - fileId
      - fileName
    PrivacyAutomation-DataSubjectRequestDSRAutomation_VerificationMethodV2CommentsDto:
      type: object
      properties:
        id:
          description: The unique identifier for this comment.
          type: string
          format: uuid
          example: 3b47744c-eebf-44bb-bf4c-680966a448dc
        verificationMethodId:
          description: The identifier of the verification method this comment belongs to.
          type: string
          format: uuid
          example: 3b47744c-eebf-44bb-bf4c-680966a448dc
        comment:
          description: The text content of the comment providing details about the verification process.
          type: string
          example: Passport verified with photo matching the requester's profile picture.
        lastModifiedDate:
          description: The timestamp when this comment was last modified.
          type: string
          format: date-time
          example: '2020-01-08T11:49:48.657Z'
        type:
          description: The type of comment, represented as an integer code.
          type: integer
          format: int32
          example: 1
        attachments:
          description: A list of attachments associated with this comment, such as scanned documents or screenshots used in the verification process.
          type: array
          items:
            $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_AttachmentV2Dto'
      required:
      - comment
      - id
      - verificationMethodId
    PrivacyAutomation-DataSubjectRequestDSRAutomation_VerificationMethodV2DTO:
      type: object
      properties:
        id:
          description: The unique identifier for this verification method.
          type: string
          format: uuid
          example: 7a275364-d6e2-4581-b95b-843237cb232a
        verificationMethodName:
          description: The name of the verification method used to verify the data subject's identity.
          type: string
          example: Government ID
          maxLength: 100
          minLength: 1
        description:
          description: A detailed description of how the verification method was applied.
          type: string
          example: Verified government-issued photo ID matched with requester information.
          maxLength: 500
        verificationStatus:
          description: The current status of the verification process.
          type: string
          example: VERIFIED
          enum:
          - UNVERIFIED
          - VERIFIED
          - REJECTED
        verificationComments:
          description: A list of comments and attachments associated with this verification method. This field is only populated when includeComments is set to true in the request.
          type: array
          items:
            $ref: '#/components/schemas/PrivacyAutomation-DataSubjectRequestDSRAutomation_VerificationMethodV2CommentsDto'
        verificationType:
          description: The type of verification process used.
          type: string
          example: MANUAL
          enum:
          - DEFAULT
          - MANUAL
          - KNOWLEDGE
          - DOCUMENT
          - EMAIL
          - PHONE
        createdDate:
          description: The timestamp when this verification method was created.
          type: string
          format: date-time
          example: '2020-01-03T12:41:13.820Z'
        lastModifiedDate:
          description: The timestamp when this verification method was last modified.
          type: string
          format: date-time
          example: '2020-01-03T12:41:13.820Z'
  securitySchemes:
    PrivacyAutomation-DataSubjectRequestDSRAutomation_OAUTH2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://{hostname}/api/access/v1/oauth/token
          scopes:
            DSAR_READ: Read-only access to DSAR objects scope for external systems
            DSAR_WRITE: Access to DSAR objects scope for external systems
            DSAR: Access to DSAR objects scope for external systems
    PrivacyAutomation-DROPManagement_OAUTH2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://{hostname}/api/access/v1/oauth/token
          scopes:
            DSAR_WRITE: Access to DROP objects scope for external systems
x-readme:
  explorer-enabled: false
  proxy-enabled: false
  metrics-enabled: false
x-onetrust:
  spec-label: OpenAPI 3.1.0