OneTrust website screenshot

OneTrust

OneTrust is an enterprise trust, privacy, and AI-governance platform. Its developer portal publishes 37 downloadable OpenAPI definitions covering roughly 631 operations across Universal Consent & Preference Management, Cookie Consent / CMP, Consent Receipts, Data Subject Request (DSR) Automation, Assessment Automation (PIA/DPIA), Data Mapping, Data Catalog and Data Discovery, Incident Management, IT & Security Risk Management, Audit Management, Issues Management, Enterprise Policy Management, Compliance Automation, Third-Party Risk Management, ESG Program Reporting, AI Governance, and the shared platform services (Access Management, SCIM 2.0 User Provisioning, Object Manager, Inventory, Bulk Export, Documents, Integrations, Task Management, Global Activity). Every API is authorized with OAuth 2.0 client credentials against a per-tenant environment host, and the portal also serves an RFC 9727 /.well-known/api-catalog, an llms.txt, and a public remote MCP server.

OneTrust publishes 37 APIs on the APIs.io network, including AI Governance — AI Governance, Platform — Global Activity, Consent & Preferences — Consent Interfaces, and 34 more. Tagged areas include Privacy, GRC, Compliance, Consent, and TPRM.

The OneTrust catalog on APIs.io includes 1 event-driven AsyncAPI specification.

OneTrust’s developer surface includes documentation, API reference, getting-started guide, support, engineering blog, pricing, changelog, and 35 more developer resources.

68.2/100 exemplar ▬ flat Agent 52/100 agent ready saas Full breakdown ↓
scored 2026-09-14 · rubric v0.22.0
AccessEnterpriseFree trial
37 APIs 1 MCP Servers
PrivacyGRCComplianceConsentTPRMAI GovernanceData GovernanceRisk ManagementData DiscoveryESGSecuritySCIM

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-14 · rubric v0.22.0
Create-or-Update Ergonomics applies to this provider. This API accepts writes, so it carries 10 points of the composite. It is scored from the published contracts themselves: whether a caller can create-or-update in one call, whether the write accepts a key the caller already holds, and whether the response says which branch ran. Without that, every write needs a search-and-branch in front of it, and the first time that check is skipped a duplicate record is created. Scored against the observed mean rather than raw — a provider at the catalog average is unchanged by this facet, not penalised by it.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/onetrust: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

Standards implemented 1

Interfaces this provider implements that became standards by being copied rather than ratified. Each is profiled by the API Commons, and the evidence column says how the claim was established — not that it was made.

prose — states compatibility; nothing published to check it against
5 core of 24 operations graded · api-commons/identity

APIs 37

Individual APIs this provider publishes, each with its own machine-readable definition.

OneTrust AI Governance — AI Governance

The AI Governance APIs are used to integrate external systems and streamline the flow of data with A I Governance in the OneTrust Platform. (20 operations.)

OneTrust Platform — Global Activity

The Platform - Global Activity API from OneTrust — 1 operation(s) documented on the OneTrust Develop er Portal.

OneTrust Consent & Preferences — Consent Interfaces

The Consent Interfaces APIs are used to integrate external systems and streamline the flow of data w ith Consent & Preferences user interfaces. (1 operations.)

OneTrust Consent & Preferences — Consent Management Platform (CMP)

These are server-based APIs that will act as a medium between the OT hosted server that owns busines s logic and the client-side SDK, which will take the responsibility to rende...

OneTrust Consent & Preferences — Consent Receipts

The Consent Receipts APIs are used to integrate external systems and streamline the flow of consent receipt data with the OneTrust Platform. (3 operations.)

OneTrust Consent & Preferences — Cookie Consent

The Cookie Consent APIs are used to integrate external systems and streamline the flow of data with Cookie Consent in the OneTrust Platform. (44 operations.)

OneTrust Consent & Preferences — Cookie Consent (Swagger)

The Consent & Preferences - Cookie Consent (Swagger) API from OneTrust — 11 operation(s) documented on the OneTrust Developer Portal.

OneTrust Consent & Preferences — Cookie Domain Data

Use this API to retrieve all templates, consent model, and vendor list data for a specific Website D omain by a user’s geolocation. The API returns a single JSON formatted for c...

OneTrust Consent & Preferences — Cross-Device Consent

The Consent & Preferences - Cross-Device Consent API from OneTrust — 1 operation(s) documented on th e OneTrust Developer Portal.

OneTrust Consent & Preferences — Mobile App Consent

Collection of APIs for the Mobile & OTT App Compliance SDKs. (1 operations.)

OneTrust Consent & Preferences — Policy & Notice Management

The Policy & Notice Management APIs are used to list privacy notices, page through results, view ver sion history for a notice, and retrieve the version that was effective at a ...

OneTrust Consent & Preferences — Universal Consent & Preference Management (OAS)

The Universal Consent & Preference Management APIs are used to integrate external systems and stream line the flow of data with Universal Consent & Preference Management in the ...

OneTrust Data Use Governance — Data Catalog

The Data Catalog APIs provide comprehensive functionality for managing data governance assets within Data Catalog, enabling users to create, retrieve, and organize business glos...

OneTrust Data Use Governance — Data Discovery

The Data Discovery API provides comprehensive REST endpoints for managing data discovery operations including data sources, scan profiles, credentials, and scan jobs with OAuth2...

OneTrust Data Use Governance — Data Discovery Worker Node

The Data Discovery Worker Node APIs enables secure communication with an on-premises Data Discovery worker node. It provides operations to retrieve, classify, and catalog data f...

OneTrust ESG Program Reporting & Disclosures

The ESG Program Reporting & Disclosures API from OneTrust — 5 operation(s) documented on the OneTrus t Developer Portal.

OneTrust Platform — Access Management

The Access Management APIs enable you to programmatically control user access, manage organizational hierarchies, and monitor authentication activities across your OneTrust plat...

OneTrust Platform — Bulk Export

The Bulk Export APIs are used to integrate external systems and extract specific data from Cookie Co nsent and Universal Consent & Preference Management in the OneTrust platform...

OneTrust Platform — Documents

The Documents API are used to integrate external systems and streamline the flow of data for documen ts in the OneTrust Platform. (3 operations.)

OneTrust Platform — Integrations

The Integrations APIs are used to configure, manage, and automate integrations. They provide functio nality to handle system credentials, import and export workflows, and manage...

OneTrust Platform — Inventory

The Inventory APIs are used to manage relationships and link data within the inventory. (13 operatio ns.)

OneTrust Platform — Object Manager

The Object Manager APIs are used to integrate external systems and streamline the flow of data for o bjects created via Object Manager in the OneTrust Platform. (38 operations.)

OneTrust Platform — Task Management

The Task Management APIs are used to integrate external systems and streamline the flow of data for tasks created across the OneTrust Platform. (3 operations.)

OneTrust Platform — User Provisioning

OneTrust supports cross-domain identity management through the SCIM 2.0 specification. System for Cr oss-Domain Identity Management (SCIM) is an open specification to help facil...

OneTrust Privacy Automation — Assessment Automation

The Assessment Automation APIs provide functionality for managing assessment template lifecycle oper ations, including template export and import for cross-environment migration...

OneTrust Privacy Automation — Data Mapping Automation

The Data Mapping Automation APIs are used to manage structured records (assets, vendors, processing activities, and legal entities), define schema attributes, traverse parent–ch...

OneTrust Privacy Automation — Data Mapping Automation (Swagger)

The Privacy Automation - Data Mapping Automation (Swagger) API from OneTrust — 4 operation(s) docume nted on the OneTrust Developer Portal.

OneTrust Privacy Automation — Data Subject Request (DSR) Automation

The Privacy Rights Automation are used to manage, process, and fulfill data subject access requests (DSARs), including request creation, subtask management, resolution codes, ve...

OneTrust Privacy Automation — Incident Management

The Incident Management API allows you to efficiently manage and respond to incidents. (7 operations .)

OneTrust The Trust Intelligence Platform — Document Gateway

The The Trust Intelligence Platform - Document Gateway API from OneTrust — 1 operation(s) documented on the OneTrust Developer Portal.

OneTrust Tech Risk & Compliance — Audit Management

The Audit Management API provides comprehensive REST endpoints for managing enterprise audits, workp apers, and compliance assessments with OAuth2 security and advanced filterin...

OneTrust Tech Risk & Compliance — Compliance Automation

The Compliance Automation APIs are used to integrate external systems and streamline the flow of dat a with Compliance Automation in the OneTrust Platform. (3 operations.)

OneTrust Tech Risk & Compliance — Enterprise Policy Management

The Enterprise Policy Management APIs are used to integrate external systems and streamline the flow of data with Enterprise Policy Management in the OneTrust platform. (6 opera...

OneTrust Tech Risk & Compliance — Issues Management

The Issues Management APIs are used to integrate external systems and streamline the flow of data wi th Issues Management in the OneTrust platform. (9 operations.)

OneTrust Tech Risk & Compliance — IT Risk Management

The IT Risk Management API provides comprehensive REST endpoints for managing enterprise security co ntrols, threats, vulnerabilities, and their implementations with OAuth2 secu...

OneTrust Tech Risk & Compliance — Training

The Tech Risk & Compliance - Training API from OneTrust — 5 operation(s) documented on the OneTrust Developer Portal.

OneTrust Third-Party Management — Third-Party Risk Management

The Third-Party Risk Management APIs provide comprehensive functionality for managing vendor relatio nships, engagements, and contracts within the GRC ecosystem, enabling organi...

Scroll for all 37

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

API Collection

OPEN COLLECTION

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

OneTrust Developer Portal MCP Server

OneTrust hosts a public remote MCP server on its developer portal. It is documented on a dedicated "MCP Server" page in the API reference, requires no authentication headers, an...

MCP SERVER

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Onetrust Rate Limits

12 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Event Specifications 1

AsyncAPI definitions for this provider's event-driven and streaming APIs.

Security Posture 4

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Onetrust Authentication

1 scheme

SECURITY

Onetrust Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Onetrust Trust Center

SOC 2, ISO 27001, GDPR

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

Onetrust Scopes

51 scopes · clientCredentials

51 scopes

SCOPES

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Onetrust Agentic Access

631 operations · 389 acting · 30 human-in-the-loop

631 operations · 389 acting

AGENTIC

Resources

Get Started 3

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 5

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 7

Pagination, idempotency, versioning, errors, and events

Scroll for all 7

Build 4

SDKs, sample code, and the tooling you integrate with

Access & Security 7

Authentication, authorization, and security posture

Scroll for all 7

Operate 5

Status, limits, changes, and where to get help

Commercial 5

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: onetrust
url: https://raw.githubusercontent.com/api-evangelist/onetrust/refs/heads/main/apis.yml
name: OneTrust
kind: company
description: OneTrust is an enterprise trust, privacy, and AI-governance platform. Its developer portal publishes 37 downloadable
  OpenAPI definitions covering roughly 631 operations across Universal Consent & Preference Management, Cookie Consent / CMP,
  Consent Receipts, Data Subject Request (DSR) Automation, Assessment Automation (PIA/DPIA), Data Mapping, Data Catalog and
  Data Discovery, Incident Management, IT & Security Risk Management, Audit Management, Issues Management, Enterprise Policy
  Management, Compliance Automation, Third-Party Risk Management, ESG Program Reporting, AI Governance, and the shared platform
  services (Access Management, SCIM 2.0 User Provisioning, Object Manager, Inventory, Bulk Export, Documents, Integrations,
  Task Management, Global Activity). Every API is authorized with OAuth 2.0 client credentials against a per-tenant environment
  host, and the portal also serves an RFC 9727 /.well-known/api-catalog, an llms.txt, and a public remote MCP server.
deliveryModel:
  model: saas
  open_source: false
  commercial: true
  callable_host: true
  label: Hosted service · you call their endpoint
  confidence: high
  source:
  - openapi
  - pricing
  generated: '2026-08-28'
  method: derived
accessModel:
  pricing: enterprise
  onboarding: sales-assisted
  trial: true
  try_now: false
  public: true
  label: Enterprise · Public docs + public OpenAPI, tenant-gated keys
  confidence: high
  source:
  - plans
  - authentication
  - openapi
  generated: '2026-08-27'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/onetrust.png
tags:
- Privacy
- GRC
- Compliance
- Consent
- TPRM
- AI Governance
- Data Governance
- Risk Management
- Data Discovery
- ESG
- Security
- SCIM
created: '2026-05-08'
modified: '2026-08-27'
specificationVersion: '0.23'
apis:
- aid: onetrust:ai-governance-ai-governance
  name: OneTrust AI Governance — AI Governance
  description: The AI Governance APIs are used to integrate external systems and streamline the flow of data with A I Governance
    in the OneTrust Platform. (20 operations.)
  humanURL: https://developer.onetrust.com/onetrust/reference/attribute-management
  baseURL: https://app.onetrust.com
  tags:
  - Attribute Management
  - Entity Management
  - Entity Type Management
  - Entity Workflow Management
  - Relationship Management
  - Task Management
  properties:
  - type: OpenAPI
    url: openapi/onetrust-ai-governance-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/attribute-management
  - type: Overlay
    url: overlays/onetrust-ai-governance-ai-governance-overlay.yaml
- aid: onetrust:platform-global-activity
  name: OneTrust Platform — Global Activity
  description: The Platform - Global Activity API from OneTrust — 1 operation(s) documented on the OneTrust Develop er Portal.
  humanURL: https://developer.onetrust.com/onetrust/reference/activity-log
  baseURL: https://app.onetrust.com
  tags:
  - Activity Log
  properties:
  - type: OpenAPI
    url: openapi/onetrust-audit-api-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/activity-log
  - type: Overlay
    url: overlays/onetrust-platform-global-activity-overlay.yaml
- aid: onetrust:consent-and-preferences-consent-interfaces
  name: OneTrust Consent & Preferences — Consent Interfaces
  description: The Consent Interfaces APIs are used to integrate external systems and streamline the flow of data w ith Consent
    & Preferences user interfaces. (1 operations.)
  humanURL: https://developer.onetrust.com/onetrust/reference/preferences-v2
  baseURL: https://consent-api.onetrust.com
  tags:
  - Preferences V2
  properties:
  - type: OpenAPI
    url: openapi/onetrust-consent-preferences-consent-interfaces-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/preferences-v2
  - type: Overlay
    url: overlays/onetrust-consent-and-preferences-consent-interfaces-overlay.yaml
- aid: onetrust:consent-and-preferences-consent-management-platform-cmp
  name: OneTrust Consent & Preferences — Consent Management Platform (CMP)
  description: These are server-based APIs that will act as a medium between the OT hosted server that owns busines s logic
    and the client-side SDK, which will take the responsibility to render elements on UI based o n the response sent via APIs.
    (6 operations.)
  humanURL: https://developer.onetrust.com/onetrust/reference/banner
  baseURL: https://mobile-data.onetrust.io
  tags:
  - Banner
  - Data Subject Access Request (DSAR)
  - Log Consent
  - Preference Center
  - UC Purposes
  - Vendors
  properties:
  - type: OpenAPI
    url: openapi/onetrust-consent-preferences-consent-management-platform-cmp-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/banner
  - type: Overlay
    url: overlays/onetrust-consent-and-preferences-consent-management-platform-cmp-overlay.yaml
- aid: onetrust:consent-and-preferences-consent-receipts
  name: OneTrust Consent & Preferences — Consent Receipts
  description: The Consent Receipts APIs are used to integrate external systems and streamline the flow of consent  receipt
    data with the OneTrust Platform. (3 operations.)
  humanURL: https://developer.onetrust.com/onetrust/reference/consent-receipts
  baseURL: https://app.onetrust.com/request/v1
  tags:
  - Consent Receipts
  properties:
  - type: OpenAPI
    url: openapi/onetrust-consent-preferences-consent-receipts-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/consent-receipts
  - type: Overlay
    url: overlays/onetrust-consent-and-preferences-consent-receipts-overlay.yaml
- aid: onetrust:consent-and-preferences-cookie-consent
  name: OneTrust Consent & Preferences — Cookie Consent
  description: The Cookie Consent APIs are used to integrate external systems and streamline the flow of data with  Cookie
    Consent in the OneTrust Platform. (44 operations.)
  humanURL: https://developer.onetrust.com/onetrust/reference/applications
  baseURL: https://app.onetrust.com
  tags:
  - Application
  - Cookies
  - Domains
  - Geolocation Rules
  - Scans
  - Scripts
  - Templates
  tags_raw:
  - Applications
  - Cookies
  - Domains
  - Geolocation Rules
  - Scans
  - Scripts
  - Templates
  properties:
  - type: OpenAPI
    url: openapi/onetrust-consent-preferences-cookie-consent-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/applications
  - type: Overlay
    url: overlays/onetrust-consent-and-preferences-cookie-consent-overlay.yaml
- aid: onetrust:consent-and-preferences-cookie-consent-swagger
  name: OneTrust Consent & Preferences — Cookie Consent (Swagger)
  description: The Consent & Preferences - Cookie Consent (Swagger) API from OneTrust — 11 operation(s) documented  on the
    OneTrust Developer Portal.
  humanURL: https://developer.onetrust.com/onetrust/reference/categorizations
  baseURL: https://customer.my.onetrust.com/api/cookiemanager
  tags:
  - Categorizations
  - Cookies
  - Domains
  - Scripts
  - Websites V2
  properties:
  - type: OpenAPI
    url: openapi/onetrust-consent-preferences-cookie-consent-swagger-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/categorizations
  - type: Overlay
    url: overlays/onetrust-consent-and-preferences-cookie-consent-swagger-overlay.yaml
- aid: onetrust:consent-and-preferences-cookie-domain-data
  name: OneTrust Consent & Preferences — Cookie Domain Data
  description: 'Use this API to retrieve all templates, consent model, and vendor list data for a specific Website D omain
    by a user’s geolocation. The API returns a single JSON formatted for custom UI development. ## # Additional Information
    * By default, the Country Code and Region Code to determine which data to b e returned is auto-computed by a geoIP lookup
    on the server. Optionally, `OT-Country-Code` and `OT-R egion-Code` parameters can be passed to bypass the auto-computed
    values. ### Example Request `GET ht tps://cookies-data.onetrust.io/bannersdk/domaindata` (1 operations.)'
  humanURL: https://developer.onetrust.com/onetrust/reference/domain-data
  baseURL: https://cookies-data.onetrust.io/bannersdk
  tags:
  - Domain Data
  properties:
  - type: OpenAPI
    url: openapi/onetrust-consent-preferences-cookie-domain-data-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/domain-data
  - type: Overlay
    url: overlays/onetrust-consent-and-preferences-cookie-domain-data-overlay.yaml
- aid: onetrust:consent-and-preferences-cross-device-consent
  name: OneTrust Consent & Preferences — Cross-Device Consent
  description: The Consent & Preferences - Cross-Device Consent API from OneTrust — 1 operation(s) documented on th e OneTrust
    Developer Portal.
  humanURL: https://developer.onetrust.com/onetrust/reference/preferences
  baseURL: https://consent-api.onetrust.com
  tags:
  - Preferences
  properties:
  - type: OpenAPI
    url: openapi/onetrust-consent-preferences-cross-device-consent-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/preferences
  - type: Overlay
    url: overlays/onetrust-consent-and-preferences-cross-device-consent-overlay.yaml
- aid: onetrust:consent-and-preferences-mobile-app-consent
  name: OneTrust Consent & Preferences — Mobile App Consent
  description: Collection of APIs for the Mobile & OTT App Compliance SDKs. (1 operations.)
  humanURL: https://developer.onetrust.com/onetrust/reference/mobile-app-data
  baseURL: https://customer.my.onetrust.com/bannersdk/v2
  tags:
  - Mobile App Data
  properties:
  - type: OpenAPI
    url: openapi/onetrust-consent-preferences-mobile-app-consent-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/mobile-app-data
  - type: Overlay
    url: overlays/onetrust-consent-and-preferences-mobile-app-consent-overlay.yaml
- aid: onetrust:consent-and-preferences-policy-and-notice-management
  name: OneTrust Consent & Preferences — Policy & Notice Management
  description: The Policy & Notice Management APIs are used to list privacy notices, page through results, view ver sion history
    for a notice, and retrieve the version that was effective at a specific date and time.  (3 operations.)
  humanURL: https://developer.onetrust.com/onetrust/reference/privacy-notice-v2
  baseURL: https://app.onetrust.com/api/privacynotice
  tags:
  - Privacy Notice V2
  properties:
  - type: OpenAPI
    url: openapi/onetrust-consent-preferences-policy-notice-management-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/privacy-notice-v2
  - type: Overlay
    url: overlays/onetrust-consent-and-preferences-policy-and-notice-management-overlay.yaml
- aid: onetrust:consent-and-preferences-universal-consent-and-preference-management-oas
  name: OneTrust Consent & Preferences — Universal Consent & Preference Management (OAS)
  description: The Universal Consent & Preference Management APIs are used to integrate external systems and stream line the
    flow of data with Universal Consent & Preference Management in the OneTrust Platform. (97 o perations.)
  humanURL: https://developer.onetrust.com/onetrust/reference/collection-points
  baseURL: https://app.onetrust.com
  tags:
  - Collection Points
  - Collection Points V2
  - Consent Attachments
  - Consent Groups
  - Consent Rate Optimization
  - Custom Index Management
  - Data Subject Groups
  - Data Subject Groups V4
  properties:
  - type: OpenAPI
    url: openapi/onetrust-consent-preferences-universal-consent-preference-management-oas-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/collection-points
  - type: Overlay
    url: overlays/onetrust-consent-and-preferences-universal-consent-and-preference-management-oas-overlay.yaml
- aid: onetrust:data-use-governance-data-catalog
  name: OneTrust Data Use Governance — Data Catalog
  description: "The Data Catalog APIs provide comprehensive functionality for managing data governance assets within\n Data\
    \ Catalog, enabling users to create, retrieve, and organize business glossaries, terms, and tags\n for effective data\
    \ classification and metadata management. (24 operations.)"
  humanURL: https://developer.onetrust.com/onetrust/reference/catalog-search-v1
  baseURL: https://app.onetrust.com
  tags:
  - Catalog Search V1
  - Catalog Search V2
  - Data Asset Attributes
  - Data Asset Management
  - Data Assets
  - Glossary
  - Tags
  - Terms
  tags_raw:
  - Catalog Search V1
  - Catalog Search V2
  - Data Asset Attributes
  - Data Asset Management
  - Data Assets
  - Glossaries
  - Tags
  - Terms
  properties:
  - type: OpenAPI
    url: openapi/onetrust-data-use-governance-data-catalog-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/catalog-search-v1
  - type: Overlay
    url: overlays/onetrust-data-use-governance-data-catalog-overlay.yaml
- aid: onetrust:data-use-governance-data-discovery
  name: OneTrust Data Use Governance — Data Discovery
  description: "The Data Discovery API provides comprehensive REST endpoints for managing data discovery operations  including\
    \ data sources, scan profiles, credentials, and scan jobs with OAuth2 security and extensive\n filtering capabilities.\
    \ (26 operations.)"
  humanURL: https://developer.onetrust.com/onetrust/reference/classification
  baseURL: https://app.onetrust.com
  tags:
  - Classification
  - Credentials
  - Data Sources
  - Installer
  - Scan Jobs
  - Scan Profiles
  properties:
  - type: OpenAPI
    url: openapi/onetrust-data-use-governance-data-discovery-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/classification
  - type: Overlay
    url: overlays/onetrust-data-use-governance-data-discovery-overlay.yaml
- aid: onetrust:data-use-governance-data-discovery-worker-node
  name: OneTrust Data Use Governance — Data Discovery Worker Node
  description: The Data Discovery Worker Node APIs enables secure communication with an on-premises Data Discovery  worker
    node. It provides operations to retrieve, classify, and catalog data from connected data sour ces, as well as manage and
    update custom connector scan jobs. Unlike the main OneTrust application A PIs, this API communicates directly with your
    worker node instance, using its hostname, FQDN, or IP  address. (4 operations.)
  humanURL: https://developer.onetrust.com/onetrust/reference/custom-scan
  baseURL: https://app.onetrust.com:8080/api/data-discovery-bridge
  tags:
  - Custom Scan
  properties:
  - type: OpenAPI
    url: openapi/onetrust-data-use-governance-data-discovery-worker-node-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/custom-scan
  - type: Overlay
    url: overlays/onetrust-data-use-governance-data-discovery-worker-node-overlay.yaml
- aid: onetrust:esg-program-reporting-and-disclosures
  name: OneTrust ESG Program Reporting & Disclosures
  description: The ESG Program Reporting & Disclosures API from OneTrust — 5 operation(s) documented on the OneTrus t Developer
    Portal.
  humanURL: https://developer.onetrust.com/onetrust/reference/carbon-management
  baseURL: https://app.onetrust.com/api/esg-management
  tags:
  - Carbon Management
  - Metric Details
  properties:
  - type: OpenAPI
    url: openapi/onetrust-esg-program-reporting-disclosures-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/carbon-management
  - type: Overlay
    url: overlays/onetrust-esg-program-reporting-and-disclosures-overlay.yaml
- aid: onetrust:platform-access-management
  name: OneTrust Platform — Access Management
  description: "The Access Management APIs enable you to programmatically control user access, manage organizational\n hierarchies,\
    \ and monitor authentication activities across your OneTrust platform. (36 operations.)"
  humanURL: https://developer.onetrust.com/onetrust/reference/audit-records
  baseURL: https://app.onetrust.com
  tags:
  - Audit Records
  - OAuth Token
  - Organization
  - User Groups
  - User Groups V2
  - Users V2
  tags_raw:
  - Audit Records
  - OAuth Token
  - Organizations
  - User Groups
  - User Groups V2
  - Users V2
  properties:
  - type: OpenAPI
    url: openapi/onetrust-platform-access-management-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/audit-records
  - type: Overlay
    url: overlays/onetrust-platform-access-management-overlay.yaml
- aid: onetrust:platform-bulk-export
  name: OneTrust Platform — Bulk Export
  description: The Bulk Export APIs are used to integrate external systems and extract specific data from Cookie Co nsent
    and Universal Consent & Preference Management in the OneTrust platform. (7 operations.)
  humanURL: https://developer.onetrust.com/onetrust/reference/bulk-export
  baseURL: https://app.onetrust.com
  tags:
  - Bulk Export
  properties:
  - type: OpenAPI
    url: openapi/onetrust-platform-bulk-export-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/bulk-export
  - type: Overlay
    url: overlays/onetrust-platform-bulk-export-overlay.yaml
- aid: onetrust:platform-documents
  name: OneTrust Platform — Documents
  description: The Documents API are used to integrate external systems and streamline the flow of data for documen ts in
    the OneTrust Platform. (3 operations.)
  humanURL: https://developer.onetrust.com/onetrust/reference/attachments
  baseURL: https://app.onetrust.com
  tags:
  - Attachments
  - Attachments V4
  properties:
  - type: OpenAPI
    url: openapi/onetrust-platform-documents-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/attachments
  - type: Overlay
    url: overlays/onetrust-platform-documents-overlay.yaml
- aid: onetrust:platform-integrations
  name: OneTrust Platform — Integrations
  description: "The Integrations APIs are used to configure, manage, and automate integrations. They provide functio nality\
    \ to handle system credentials, import and export workflows, and manage integration details. (4\n operations.)"
  humanURL: https://developer.onetrust.com/onetrust/reference/system-credentials
  baseURL: https://app.onetrust.com/api/integrationmanager
  tags:
  - System Credentials
  - Workflows V2
  properties:
  - type: OpenAPI
    url: openapi/onetrust-platform-integrations-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/system-credentials
  - type: Overlay
    url: overlays/onetrust-platform-integrations-overlay.yaml
- aid: onetrust:platform-inventory
  name: OneTrust Platform — Inventory
  description: The Inventory APIs are used to manage relationships and link data within the inventory. (13 operatio ns.)
  humanURL: https://developer.onetrust.com/onetrust/reference/inventory-relationships-v2
  baseURL: https://app.onetrust.com
  tags:
  - Inventory Relationships V2
  - Relationship Management
  properties:
  - type: OpenAPI
    url: openapi/onetrust-platform-inventory-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/inventory-relationships-v2
  - type: Overlay
    url: overlays/onetrust-platform-inventory-overlay.yaml
- aid: onetrust:platform-object-manager
  name: OneTrust Platform — Object Manager
  description: The Object Manager APIs are used to integrate external systems and streamline the flow of data for o bjects
    created via Object Manager in the OneTrust Platform. (38 operations.)
  humanURL: https://developer.onetrust.com/onetrust/reference/model-management
  baseURL: https://app.onetrust.com/api/custom-entity
  tags:
  - Model Management
  - Object Attribute Management
  - Object Management
  - Object Relationship Management
  - Object Relationship Type Management
  - Object Task Management
  - Object Type Management
  - Project Management
  properties:
  - type: OpenAPI
    url: openapi/onetrust-platform-object-manager-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/model-management
  - type: Overlay
    url: overlays/onetrust-platform-object-manager-overlay.yaml
- aid: onetrust:platform-task-management
  name: OneTrust Platform — Task Management
  description: The Task Management APIs are used to integrate external systems and streamline the flow of data for  tasks
    created across the OneTrust Platform. (3 operations.)
  humanURL: https://developer.onetrust.com/onetrust/reference/tasks
  baseURL: https://app.onetrust.com
  tags:
  - Task
  tags_raw:
  - Tasks
  properties:
  - type: OpenAPI
    url: openapi/onetrust-platform-task-management-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/tasks
  - type: Overlay
    url: overlays/onetrust-platform-task-management-overlay.yaml
- aid: onetrust:platform-user-provisioning
  name: OneTrust Platform — User Provisioning
  description: OneTrust supports cross-domain identity management through the SCIM 2.0 specification. System for Cr oss-Domain
    Identity Management (SCIM) is an open specification to help facilitate the automated mana gement of user identities and
    groups in cloud applications using RESTful APIs. This allows organizat ions to manage and update user information and
    group information across domains and applications. (2 6 operations.)
  humanURL: https://developer.onetrust.com/onetrust/reference/groups-v2
  baseURL: https://app.onetrust.com
  tags:
  - Groups V2
  - Resources V3
  - SCIM Schemas V3
  - Service Provider V3
  - User Groups V3
  - Users V2
  - Users V3
  properties:
  - type: OpenAPI
    url: openapi/onetrust-platform-user-provisioning-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/groups-v2
  - type: Overlay
    url: overlays/onetrust-platform-user-provisioning-overlay.yaml
- aid: onetrust:privacy-automation-assessment-automation
  name: OneTrust Privacy Automation — Assessment Automation
  description: The Assessment Automation APIs provide functionality for managing assessment template lifecycle oper ations,
    including template export and import for cross-environment migration, retrieving published t emplate metadata with filtering
    by template type, and template deletion with comprehensive validatio n checks. (36 operations.)
  humanURL: https://developer.onetrust.com/onetrust/reference/assessment-actions
  baseURL: https://app.onetrust.com
  tags:
  - Assessment Actions
  - Assessment Management
  - Assessments
  - Template
  properties:
  - type: OpenAPI
    url: openapi/onetrust-privacy-automation-assessment-automation-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/assessment-actions
  - type: Overlay
    url: overlays/onetrust-privacy-automation-assessment-automation-overlay.yaml
- aid: onetrust:privacy-automation-data-mapping-automation
  name: OneTrust Privacy Automation — Data Mapping Automation
  description: The Data Mapping Automation APIs are used to manage structured records (assets, vendors, processing  activities,
    and legal entities), define schema attributes, traverse parent–child hierarchies, and cr eate cross-record relationships—including
    links to personal data. (58 operations.)
  humanURL: https://developer.onetrust.com/onetrust/reference/inventory
  baseURL: https://app.onetrust.com
  tags:
  - Inventory
  - Inventory Hierarchies
  - Inventory Relationships V1
  - Inventory Schema
  - Personal Data
  - inventory-management-controller
  properties:
  - type: OpenAPI
    url: openapi/onetrust-privacy-automation-data-mapping-automation-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/inventory
  - type: Overlay
    url: overlays/onetrust-privacy-automation-data-mapping-automation-overlay.yaml
- aid: onetrust:privacy-automation-data-mapping-automation-swagger
  name: OneTrust Privacy Automation — Data Mapping Automation (Swagger)
  description: The Privacy Automation - Data Mapping Automation (Swagger) API from OneTrust — 4 operation(s) docume nted on
    the OneTrust Developer Portal.
  humanURL: https://developer.onetrust.com/onetrust/reference/inventory-1
  baseURL: https://customer.my.onetrust.com/api
  tags:
  - Inventory
  - Inventory Schema
  - Personal Data
  properties:
  - type: OpenAPI
    url: openapi/onetrust-privacy-automation-data-mapping-automation-swagger-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/inventory-1
  - type: Overlay
    url: overlays/onetrust-privacy-automation-data-mapping-automation-swagger-overlay.yaml
- aid: onetrust:privacy-automation-data-subject-request-dsr-automation
  name: OneTrust Privacy Automation — Data Subject Request (DSR) Automation
  description: "The Privacy Rights Automation are used to manage, process, and fulfill data subject access requests  (DSARs),\
    \ including request creation, subtask management, resolution codes, verification methods, and\n audit history. (41 operations.)"
  humanURL: https://developer.onetrust.com/onetrust/reference/drop-management
  baseURL: https://app.onetrust.com
  tags:
  - DROP Management
  - Request Queues
  - Resolutions
  - Results Summary
  - Subtasks
  - Targeted Data Discovery
  - Verification Methods
  properties:
  - type: OpenAPI
    url: openapi/onetrust-privacy-automation-data-subject-request-dsr-automation-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/drop-management
  - type: Overlay
    url: overlays/onetrust-privacy-automation-data-subject-request-dsr-automation-overlay.yaml
- aid: onetrust:privacy-automation-incident-management
  name: OneTrust Privacy Automation — Incident Management
  description: The Incident Management API allows you to efficiently manage and respond to incidents. (7 operations .)
  humanURL: https://developer.onetrust.com/onetrust/reference/incidents
  baseURL: https://app.onetrust.com/api
  tags:
  - Incidents
  properties:
  - type: OpenAPI
    url: openapi/onetrust-privacy-automation-incident-management-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/incidents
  - type: Overlay
    url: overlays/onetrust-privacy-automation-incident-management-overlay.yaml
- aid: onetrust:the-trust-intelligence-platform-document-gateway
  name: OneTrust The Trust Intelligence Platform — Document Gateway
  description: "The The Trust Intelligence Platform - Document Gateway API from OneTrust — 1 operation(s) documented\n on\
    \ the OneTrust Developer Portal."
  humanURL: https://developer.onetrust.com/onetrust/reference/document-controller
  baseURL: https://app.onetrust.com
  tags:
  - Document Gateway
  properties:
  - type: OpenAPI
    url: openapi/onetrust-referencedocument-gateway-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/document-controller
  - type: Overlay
    url: overlays/onetrust-the-trust-intelligence-platform-document-gateway-overlay.yaml
- aid: onetrust:tech-risk-and-compliance-audit-management
  name: OneTrust Tech Risk & Compliance — Audit Management
  description: The Audit Management API provides comprehensive REST endpoints for managing enterprise audits, workp apers,
    and compliance assessments with OAuth2 security and advanced filtering capabilities. (11 oper ations.)
  humanURL: https://developer.onetrust.com/onetrust/reference/audits
  baseURL: https://app.onetrust.com
  tags:
  - Audits
  - Workpapers
  properties:
  - type: OpenAPI
    url: openapi/onetrust-tech-risk-compliance-audit-management-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/audits
  - type: Overlay
    url: overlays/onetrust-tech-risk-and-compliance-audit-management-overlay.yaml
- aid: onetrust:tech-risk-and-compliance-compliance-automation
  name: OneTrust Tech Risk & Compliance — Compliance Automation
  description: The Compliance Automation APIs are used to integrate external systems and streamline the flow of dat a with
    Compliance Automation in the OneTrust Platform. (3 operations.)
  humanURL: https://developer.onetrust.com/onetrust/reference/initiatives
  baseURL: https://app.onetrust.com/api/compliance-wr
  tags:
  - Initiatives
  properties:
  - type: OpenAPI
    url: openapi/onetrust-tech-risk-compliance-compliance-automation-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/initiatives
  - type: Overlay
    url: overlays/onetrust-tech-risk-and-compliance-compliance-automation-overlay.yaml
- aid: onetrust:tech-risk-and-compliance-enterprise-policy-management
  name: OneTrust Tech Risk & Compliance — Enterprise Policy Management
  description: "The Enterprise Policy Management APIs are used to integrate external systems and streamline the flow\n of\
    \ data with Enterprise Policy Management in the OneTrust platform. (6 operations.)"
  humanURL: https://developer.onetrust.com/onetrust/reference/document-attachments
  baseURL: https://app.onetrust.com/api/enterprise-policy
  tags:
  - Document Attachments
  - Documents
  properties:
  - type: OpenAPI
    url: openapi/onetrust-tech-risk-compliance-enterprise-policy-management-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/document-attachments
  - type: Overlay
    url: overlays/onetrust-tech-risk-and-compliance-enterprise-policy-management-overlay.yaml
- aid: onetrust:tech-risk-and-compliance-issues-management
  name: OneTrust Tech Risk & Compliance — Issues Management
  description: The Issues Management APIs are used to integrate external systems and streamline the flow of data wi th Issues
    Management in the OneTrust platform. (9 operations.)
  humanURL: https://developer.onetrust.com/onetrust/reference/issues
  baseURL: https://app.onetrust.com/api/issue-management
  tags:
  - Issues
  properties:
  - type: OpenAPI
    url: openapi/onetrust-tech-risk-compliance-issues-management-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/issues
  - type: Overlay
    url: overlays/onetrust-tech-risk-and-compliance-issues-management-overlay.yaml
- aid: onetrust:tech-risk-and-compliance-it-risk-management
  name: OneTrust Tech Risk & Compliance — IT Risk Management
  description: The IT Risk Management API provides comprehensive REST endpoints for managing enterprise security co ntrols,
    threats, vulnerabilities, and their implementations with OAuth2 security and extensive custo mization capabilities. (57
    operations.)
  humanURL: https://developer.onetrust.com/onetrust/reference/control-implementations
  baseURL: https://app.onetrust.com
  tags:
  - Control Implementations
  - Control Links
  - Controls
  - Entity Types
  - Evidence Task Implementations
  - Risk Actions
  - Risk Management
  - Risk Relationships
  properties:
  - type: OpenAPI
    url: openapi/onetrust-tech-risk-compliance-it-risk-management-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/control-implementations
  - type: Overlay
    url: overlays/onetrust-tech-risk-and-compliance-it-risk-management-overlay.yaml
- aid: onetrust:tech-risk-and-compliance-training
  name: OneTrust Tech Risk & Compliance — Training
  description: The Tech Risk & Compliance - Training API from OneTrust — 5 operation(s) documented on the OneTrust  Developer
    Portal.
  humanURL: https://developer.onetrust.com/onetrust/reference/training
  baseURL: https://customer.my.onetrust.com/api/awareness-training
  tags:
  - Training
  properties:
  - type: OpenAPI
    url: openapi/onetrust-tech-risk-compliance-training-openapi.json
  - type: Documentation
    url: https://developer.onetrust.com/onetrust/reference/training
  - type: Overlay
    url: overlays/onetrust-tech-risk-and-compliance-training-overlay.yaml
- aid: onetrust:third-party-management-third-party-risk-management
  name: OneTrust Third-Party Management — Third-Party Risk Management
  description: The Third-Party Risk Management APIs pro

# --- truncated at 32 KB (35 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/onetrust/refs/heads/main/apis.yml

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/onetrust"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/onetrust/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/onetrust/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.