OneTrust Websites V2 API

The Websites V2 API from OneTrust — 1 operation(s) for websites v2.

Operations 2

POST /v2/websites Add Websites to Scan #
GET /v2/websites Get List of Websites #

Documentation

📖
Documentation
https://developer.onetrust.com/onetrust/reference/attribute-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/activity-log
📖
Documentation
https://developer.onetrust.com/onetrust/reference/preferences-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/banner
📖
Documentation
https://developer.onetrust.com/onetrust/reference/consent-receipts
📖
Documentation
https://developer.onetrust.com/onetrust/reference/applications
📖
Documentation
https://developer.onetrust.com/onetrust/reference/categorizations
📖
Documentation
https://developer.onetrust.com/onetrust/reference/domain-data
📖
Documentation
https://developer.onetrust.com/onetrust/reference/preferences
📖
Documentation
https://developer.onetrust.com/onetrust/reference/mobile-app-data
📖
Documentation
https://developer.onetrust.com/onetrust/reference/privacy-notice-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/collection-points
📖
Documentation
https://developer.onetrust.com/onetrust/reference/catalog-search-v1
📖
Documentation
https://developer.onetrust.com/onetrust/reference/classification
📖
Documentation
https://developer.onetrust.com/onetrust/reference/custom-scan
📖
Documentation
https://developer.onetrust.com/onetrust/reference/carbon-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/audit-records
📖
Documentation
https://developer.onetrust.com/onetrust/reference/bulk-export
📖
Documentation
https://developer.onetrust.com/onetrust/reference/attachments
📖
Documentation
https://developer.onetrust.com/onetrust/reference/system-credentials
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory-relationships-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/model-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/tasks
📖
Documentation
https://developer.onetrust.com/onetrust/reference/groups-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/assessment-actions
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory-1
📖
Documentation
https://developer.onetrust.com/onetrust/reference/drop-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/incidents
📖
Documentation
https://developer.onetrust.com/onetrust/reference/document-controller
📖
Documentation
https://developer.onetrust.com/onetrust/reference/audits
📖
Documentation
https://developer.onetrust.com/onetrust/reference/initiatives
📖
Documentation
https://developer.onetrust.com/onetrust/reference/document-attachments
📖
Documentation
https://developer.onetrust.com/onetrust/reference/issues
📖
Documentation
https://developer.onetrust.com/onetrust/reference/control-implementations
📖
Documentation
https://developer.onetrust.com/onetrust/reference/training
📖
Documentation
https://developer.onetrust.com/onetrust/reference/contracts

Specifications

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/onetrust-websites-v2-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

onetrust-websites-v2-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  version: '1.0'
  title: Consent & Preferences - Cookie Consent (Swagger) Websites…
servers:
- url: https://customer.my.onetrust.com/api/cookiemanager
security:
- oauth2: []
tags:
- name: Websites V2
paths:
  /v2/websites:
    post:
      tags:
      - Websites V2
      summary: Add Websites to Scan
      description: Use this API to add a website or multiple websites to the scanner.
      operationId: requestBulkAddDomainUsingPOST
      parameters:
      - name: externalOrgId
        in: query
        description: The value defaults to the organization from which the client credentials were generated. Enter a specific sub-org ID if the filter results are desired.
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              type: array
              items:
                $ref: '#/components/schemas/ScanWebsiteDto'
        description: List of Domains and their Details
      responses:
        '200':
          description: OK
          content:
            '*/*':
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/ServiceResponseDto'
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '429':
          description: 'Too Many Requests

            For more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview).'
          headers:
            Retry-After:
              description: The number of seconds after which requests will be allowed again.
              schema:
                type: integer
                format: int32
            ot-ratelimit-event-id:
              description: The unique identifier for the rate-limiting event.
              schema:
                type: string
                format: uuid
            ot-requests-allowed:
              description: The number of requests allowed within the specified period.
              schema:
                type: integer
                format: int32
            ot-period:
              description: The unit of time for which the rate limit applies.
              schema:
                type: string
                enum:
                - HOUR
                - MINUTE
            ot-request-made:
              description: The number of requests made within the specified period.
              schema:
                type: integer
                format: int32
      deprecated: false
      security:
      - apikey: []
      - oauth2:
        - COOKIE
    get:
      tags:
      - Websites V2
      summary: Get List of Websites
      operationId: getDomainsScannedBySortUsingGET
      parameters:
      - name: externalOrgId
        in: query
        description: The value defaults to the organization from which the client credentials were generated. Enter a specific sub-org ID if the filter results are desired.
        required: false
        schema:
          type: string
      - name: searchStr
        in: query
        description: Enter a URL to search for a specific domain.
        required: false
        schema:
          type: string
      - name: page
        in: query
        required: false
        description: This value can be used for getting a particular page of the paginated response.
        schema:
          type: integer
          format: int32
      - name: size
        in: query
        required: false
        description: Number of records per page (0....N).
        schema:
          type: integer
          format: int32
      - in: query
        name: sort
        description: The sorting criteria of the result list.
        schema:
          type: string
          enum:
          - ScanStatus,ASC
          - ScanStatus,DESC
          - Url,ASC
          - Url,DESC
          - PagesScanned,ASC
          - PagesScanned,DESC
          - TotalCookieCount,ASC
          - TotalCookieCount,DESC
          - ConsentPolicyName,ASC
          - ConsentPolicyName,DESC
          - ScheduledNextScanDate,ASC
          - ScheduledNextScanDate,DESC
          default: ScanStatus,ASC
      responses:
        '200':
          description: 'OK


            List of websites retrieved successfully.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PaginatedWebsiteResponseDTO'
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '429':
          description: 'Too Many Requests

            For more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview).'
          headers:
            Retry-After:
              description: The number of seconds after which requests will be allowed again.
              schema:
                type: integer
                format: int32
            ot-ratelimit-event-id:
              description: The unique identifier for the rate-limiting event.
              schema:
                type: string
                format: uuid
            ot-requests-allowed:
              description: The number of requests allowed within the specified period.
              schema:
                type: integer
                format: int32
            ot-period:
              description: The unit of time for which the rate limit applies.
              schema:
                type: string
                enum:
                - HOUR
                - MINUTE
            ot-request-made:
              description: The number of requests made within the specified period.
              schema:
                type: integer
                format: int32
      deprecated: false
      description: 'Use this API to retrieve a list of all websites in the scanner. The response will return websites in **Pending** and **Completed** status along with the corresponding domain ID, external organization ID, and last scanned date.

        > 🗒 Things to Know

        >

        > - It is recommended to use the `page` and `size` parameters if the number of domains is greater than 1,000.'
      security:
      - apikey: []
      - oauth2:
        - COOKIE_READ
        - COOKIE_FREE
components:
  schemas:
    TargetPagesScanEntityDto:
      title: TargetPagesScanEntityDto
      description: Target page for scan and details
      type: object
      required:
      - pageListName
      - targetType
      - urlType
      - pageUrls
      properties:
        pageListName:
          type: string
          description: Name of the page list.
          minLength: 1
        targetType:
          type: string
          description: Type of targeting for the URLs
          minLength: 1
          enum:
          - IncludeOnly
          - Exclude
          - Target
        urlType:
          type: string
          description: Specify which level of inclusion or exclusion is desired
          minLength: 1
          enum:
          - Page
          - Path
          - Subdomain
        pageUrls:
          type: string
          description: List of valid URLs, one per line. URLs should start with "https://" or "http://"
          minLength: 1
    ExposedWebsiteDetailsDto:
      type: object
      properties:
        consentPolicyName:
          type: string
          description: Name of the assigned consent policy to the website.
        domainName:
          type: string
          description: Name of the domain.
        domainId:
          type: string
          format: UUID
          description: ID of the domain.
        externalOrgId:
          type: string
          description: ID of the external organization for the website scan.
        lastScannedDate:
          type: string
          format: date-time
          description: The date and time at which the domain was last scanned.
        lastScannedTotalCookies:
          type: integer
          format: int32
          description: Total cookies found on the last scan.
        lastScannedTotalPages:
          type: integer
          format: int32
          description: Total pages scanned in the last scan.
        orgName:
          type: string
          description: Name of the organization.
        overPageLimit:
          type: boolean
          description: The flag to indicate if it is over the tenant page limit.
        scanError:
          type: string
          description: Error message if any in the scan.
        scheduledDateOfNextScan:
          type: string
          format: date-time
          description: The date and time at which the next scan is scheduled.
        status:
          type: string
          description: Status of the scan.
      title: ExposedWebsiteDetailsDto
    Sort:
      type: object
      properties:
        empty:
          type: boolean
          description: Flag to indicate if the results are empty or not.
        sorted:
          type: boolean
          description: Flag to indicate if the results are sorted or not. If set to TRUE, the results are sorted.
        unsorted:
          type: boolean
          description: Flag to indicate if the results are unsorted or not. If set to TRUE, the results are unsorted.
      title: Sort
    ServiceResponseDto:
      type: object
      properties:
        consentPolicyId:
          type: string
          description: Consent policy associated with the scan.
        domainId:
          type: string
          format: uuid
          description: ID of the domain under scan.
        message:
          type: string
          description: Scan response message.
        notificationTemplateId:
          type: string
          description: Notification template associated with the scan.
        ok:
          type: boolean
        rescan:
          type: boolean
          description: Flag to indicate if the rescan is required or not.
      title: ServiceResponseDto
    ScanWebsiteDto:
      title: ScanWebsiteDto
      description: Website details for scan
      type: object
      required:
      - domain
      - numberOfPages
      - independentPaths
      properties:
        domain:
          type: string
          description: Domain name of the website to scan.
          minLength: 1
        numberOfPages:
          type: integer
          description: Number of pages to scan. Number of pages depend on page limit set for each tenant. If a higher value is provided, then the page limit will have priority.
          default: 1000
        independentPaths:
          type: boolean
          description: Whether to scan independent paths.
          default: false
        includedQueryParams:
          type: string
          description: Query parameters to include in the scan.
        siteMapsUris:
          type: string
          description: URIs for the sitemaps.
          maxLength: 3000
        geoLocation:
          type: string
          description: Geographical location for the scan.
        uniqueUserAgent:
          type: boolean
          description: Indicates if a unique user agent should be used.
          default: true
        limitScanToSitemap:
          type: boolean
          description: Limits the scan to the sitemap.
          default: false
        googleLoginState:
          type: boolean
          description: Indicates if Google login is required.
          default: false
        targetPageInputs:
          type: array
          items:
            $ref: '#/components/schemas/TargetPagesScanEntityDto'
          description: List of target pages to scan.
    PaginatedWebsiteResponseDTO:
      type: object
      properties:
        content:
          type: array
          description: List of domains scanned or pending to be scanned
          items:
            $ref: '#/components/schemas/ExposedWebsiteDetailsDto'
        numberOfElements:
          type: integer
          format: int32
          description: Total number of elements in the result list.
        pageNumber:
          type: integer
          format: int32
          description: Page number of the results list (0….N).
        pageSize:
          type: integer
          format: int32
          description: Number of records per page (0…N).
        sort:
          $ref: '#/components/schemas/Sort'
        totalElements:
          type: integer
          format: int64
          description: Total number of websites found.
        totalPages:
          type: integer
          format: int32
          description: Total number of pages in the result.
      title: PaginatedWebsiteResponseDTO
      description: Paginated websites scanned or pending to be scanned
  securitySchemes:
    oauth2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://{$$.env.host}/api/access/v1/oauth/token
          scopes:
            COOKIE: Cookie Scope gives the user access to read/write operations inside the Cookie Consent module.
            COOKIE_READ: Cookie Read Scope gives the user read-only access to the Cookie Consent module.
            COOKIE_FREE: Cookie free Scope gives free users access to apis having free scope associated to them inside the Cookie Consent module.
x-readme:
  explorer-enabled: false
  metrics-enabled: false
  proxy-enabled: true
x-onetrust:
  spec-label: Swagger 2
  links:
    Cookie Consent Knowledge Base: https://my.onetrust.com/s/topic/0TO1Q000000ItRyWAK/cookie-compliance