OneTrust · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Onetrust Users V2 API
15 actions
15 updates
phrasing
extends
openapi/onetrust-users-v2-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for OneTrust's API. It is a proposal applied on top of the contract, not a document OneTrust publishes.
What the actions change
x-apievangelist-phrasing
Targets 15
$.info
$.paths['/api/access/v2/users'].get
$.paths['/api/access/v2/users'].post
$.paths['/api/access/v2/users/{userId}'].get
$.paths['/api/access/v2/users/{userId}'].put
$.paths['/api/access/v2/users/{userId}/access-levels'].get
$.paths['/api/access/v2/users/{userId}/access-levels'].post
$.paths['/api/access/v2/users/{userId}/access-levels'].delete
$.paths['/api/access/v2/users/{userId}/default-organization'].patch
$.paths['/api/scim/v2/Users'].get
$.paths['/api/scim/v2/Users'].post
$.paths['/api/scim/v2/Users/{id}'].get
$.paths['/api/scim/v2/Users/{id}'].put
$.paths['/api/scim/v2/Users/{id}'].delete
$.paths['/api/scim/v2/Users/{id}'].patch
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Onetrust Users V2 API
version: 1.0.0
extends: openapi/onetrust-users-v2-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-09-26'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 14
- target: $.paths['/api/access/v2/users'].get
update:
x-apievangelist-phrasing:
intent: List all users in the account
effect: read
questions:
- Who are all the users in my OneTrust account?
- Can I page through the account's user list and sort it?
instructions:
- text: List every user in my account, sorted by {sort}.
slots:
sort: query.sort
- text: Show page {page} of the account users with {size} per page.
slots:
page: query.page
size: query.size
method: generated
generated: '2026-09-26'
- target: $.paths['/api/access/v2/users'].post
update:
x-apievangelist-phrasing:
intent: Create a new user in the account
effect: write
questions:
- How do I add a new person as a user in my privacy account?
- Can I create a user without sending them a notification email?
instructions:
- text: Add a user named {firstName} {lastName} with email {email}.
slots:
firstName: requestBody.firstName
lastName: requestBody.lastName
email: requestBody.email
- text: Create user {email} ({firstName} {lastName}) whose access expires at {expirationDateTime}.
slots:
email: requestBody.email
firstName: requestBody.firstName
lastName: requestBody.lastName
expirationDateTime: requestBody.expirationDateTime
method: generated
generated: '2026-09-26'
- target: $.paths['/api/access/v2/users/{userId}'].get
update:
x-apievangelist-phrasing:
intent: Get one user's account details
effect: read
questions:
- What details are stored for a single user in my account?
- Can I look up one account user by their user ID?
instructions:
- text: Show the account details for user {userId}.
slots:
userId: path.userId
- text: Look up user {userId} and tell me their name, email and access levels.
slots:
userId: path.userId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/access/v2/users/{userId}'].put
update:
x-apievangelist-phrasing:
intent: Update a user's name and access details
effect: write
questions:
- How do I change a user's name or expiration date in the account?
- Can I mark an existing user as internal or external?
instructions:
- text: Rename user {userId} to {firstName} {lastName}.
slots:
userId: path.userId
firstName: requestBody.firstName
lastName: requestBody.lastName
- text: Set the access expiration of user {userId} ({firstName} {lastName}) to {expirationDateTime}.
slots:
userId: path.userId
firstName: requestBody.firstName
lastName: requestBody.lastName
expirationDateTime: requestBody.expirationDateTime
method: generated
generated: '2026-09-26'
- target: $.paths['/api/access/v2/users/{userId}/access-levels'].get
update:
x-apievangelist-phrasing:
intent: List the roles assigned to a user
effect: read
questions:
- Which roles does a particular user hold?
- What access levels has this user been granted across organizations?
instructions:
- text: List the roles assigned to user {userId}.
slots:
userId: path.userId
- text: Tell me which organizations and roles user {userId} has.
slots:
userId: path.userId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/access/v2/users/{userId}/access-levels'].post
update:
x-apievangelist-phrasing:
intent: Grant a role to a user in an organization
effect: write
questions:
- How do I give a user an additional role?
- Can I grant someone a role scoped to a specific organization?
instructions:
- text: Grant role {roleId} in organization {organizationId} to user {userId}.
slots:
roleId: requestBody.roleId
organizationId: requestBody.organizationId
userId: path.userId
- text: Give user {userId} the {roleId} role for organization {organizationId}.
slots:
userId: path.userId
roleId: requestBody.roleId
organizationId: requestBody.organizationId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/access/v2/users/{userId}/access-levels'].delete
update:
x-apievangelist-phrasing:
intent: Remove a role from a user
effect: destructive
questions:
- How do I take a role away from a user?
- Can I revoke a user's role in just one organization?
instructions:
- text: Remove role {roleId} in organization {organizationId} from user {userId}.
slots:
roleId: requestBody.roleId
organizationId: requestBody.organizationId
userId: path.userId
- text: Revoke user {userId}'s {roleId} role in organization {organizationId}.
slots:
userId: path.userId
roleId: requestBody.roleId
organizationId: requestBody.organizationId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/access/v2/users/{userId}/default-organization'].patch
update:
x-apievangelist-phrasing:
intent: Change a user's default organization
effect: write
questions:
- How do I change which organization a user lands in by default?
- Does the user need a role in an organization before it can be their default?
instructions:
- text: Make organization {organizationId} the default for user {userId}.
slots:
organizationId: query.organizationId
userId: path.userId
- text: Switch user {userId}'s default organization to {organizationId}.
slots:
userId: path.userId
organizationId: query.organizationId
method: generated
generated: '2026-09-26'
- target: $.paths['/api/scim/v2/Users'].get
update:
x-apievangelist-phrasing:
intent: List users through the SCIM provisioning endpoint
effect: read
questions:
- How does my identity provider list users over SCIM?
- Can a SCIM sync page through users with a start index and count?
instructions:
- text: List SCIM-provisioned users starting at index {startIndex}, {count} at a time.
slots:
startIndex: query.startIndex
count: query.count
- text: Fetch the SCIM user list with created and last modified dates.
method: generated
generated: '2026-09-26'
- target: $.paths['/api/scim/v2/Users'].post
update:
x-apievangelist-phrasing:
intent: Provision a user from an identity provider via SCIM
effect: write
questions:
- How do I provision a new user from my identity provider over SCIM?
- Can a SCIM-created user be assigned roles and groups at creation?
instructions:
- text: Provision SCIM user {userName} with emails {emails}.
slots:
userName: requestBody.userName
emails: requestBody.emails
- text: Create a SCIM user {userName} with roles {roles} and title {title}.
slots:
userName: requestBody.userName
roles: requestBody.roles
title: requestBody.title
method: generated
generated: '2026-09-26'
- target: $.paths['/api/scim/v2/Users/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get a SCIM user and their groups
effect: read
questions:
- Which SCIM groups does a provisioned user belong to?
- What does the SCIM record for one provisioned user look like?
instructions:
- text: Get the SCIM record for user {id}.
slots:
id: path.id
- text: Show which SCIM groups provisioned user {id} belongs to.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/scim/v2/Users/{id}'].put
update:
x-apievangelist-phrasing:
intent: Replace all attributes of a SCIM user
effect: write
questions:
- How do I fully overwrite a provisioned user's attributes over SCIM?
- Can a SCIM full replace change a user's userName and emails together?
instructions:
- text: Replace the full SCIM record of user {id} with userName {userName} and emails {emails}.
slots:
id: path.id
userName: requestBody.userName
emails: requestBody.emails
- text: Overwrite SCIM user {id} so that active is {active} and title is {title}.
slots:
id: path.id
active: requestBody.active
title: requestBody.title
method: generated
generated: '2026-09-26'
- target: $.paths['/api/scim/v2/Users/{id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a SCIM user (not currently available)
effect: destructive
questions:
- Can I delete a provisioned user through the SCIM endpoint?
- Is SCIM user deletion supported right now?
instructions:
- text: Delete SCIM user {id}.
slots:
id: path.id
- text: Remove provisioned user {id} through the SCIM delete endpoint.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/api/scim/v2/Users/{id}'].patch
update:
x-apievangelist-phrasing:
intent: Activate, deactivate or patch a SCIM user
effect: write
questions:
- How do I deactivate a user from my identity provider over SCIM?
- Can I partially update a SCIM user instead of replacing them?
instructions:
- text: Deactivate SCIM user {id}.
slots:
id: path.id
- text: Apply the SCIM patch operations {Operations} to user {id}.
slots:
Operations: requestBody.Operations
id: path.id
method: generated
generated: '2026-09-26'