OneTrust · OAuth Scopes
OneTrust OAuth Scopes
OAuth 2.0
searched
OneTrust publishes 51 OAuth 2.0 scopes via the clientCredentials flow. Scopes are the fine-grained permissions an application requests at authorization time to act against the OneTrust API on a user’s behalf.
Tokens are issued from https://{hostname}/api/access/v1/oauth/token.
This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.
PrivacyGRCComplianceConsentTPRMAI GovernanceData GovernanceRisk ManagementData DiscoveryESGSecuritySCIM
Scopes: 51
Flows: clientCredentials
Method: searched
OAuth endpoints
Token URL
https://{hostname}/api/access/v1/oauth/token https://{$$.env.host}/api/access/v1/oauth/token
https://{hostname}/api/access/v1/oauth/token https://{$$.env.host}/api/access/v1/oauth/token
Flows
clientCredentials
clientCredentials
Scopes (51)
| Scope | Description | Flows |
|---|---|---|
| ACTIVITY_LOG | ||
| AI_GOVERNANCE | ||
| AI_GOVERNANCE_READ | ||
| AI_GOVERNANCE_WRITE | ||
| ASSESSMENT | Read, write and delete templates and assessments. | |
| ASSESSMENT_READ | Read the template and assessment information. | |
| ATTACHMENT | Grants access to view and manage attachments. | |
| ATTACHMENT_READ | Grants access to view attachments. | |
| AUDIT_MANAGEMENT | READ, WRITE and DELETE operations used for Audit Management. | |
| BULK_EXPORT | Grants access to view and manage bulk exports. | |
| COMPLIANCE_AUTOMATION_READ | ||
| COMPLIANCE_AUTOMATION_WRITE | ||
| CONSENT | Read/write/delete operations inside the Consent & Preference Management module. | |
| CONSENT_READ | Read operations inside the Consent & Preference Management module. | |
| CONTROL | Access to Control Implementation operations for external systems. | |
| COOKIE | Read/write operations inside the Cookie Consent module. | |
| COOKIE_FREE | ||
| COOKIE_READ | Read-only access to the Cookie Consent module. | |
| DATA_CATALOG_READ | Grants Read access to Data Catalog operations for external systems. | |
| DATA_CATALOG_WRITE | Grants Write access to Data Catalog operations for external systems. | |
| DATA_DISCOVERY | Access Data Discovery actions for external systems operating with on-premises accounts. | |
| DSAR | ||
| DSAR_READ | Read-only access to the Data Subject Access Requests module. | |
| DSAR_WRITE | Object creation and edit access to the Data Subject Access Requests module. | |
| ESG | ||
| ESG_READ | ||
| INCIDENT | View and manage incident details. | |
| INCIDENT_CREATE | Create an incident. | |
| INCIDENT_READ | View an incident and its details. | |
| INTEGRATION | ||
| INTEGRATIONS | Invoke the Integration service API from an external system. | |
| INVENTORY | Read, write and delete operations on the Inventory module. | |
| INVENTORY_READ | Read operations on the Inventory module. | |
| INVENTORY_WRITE | Write operations on the Inventory module. | |
| ISSUE | ||
| ISSUE_READ | ||
| ITRM | Access to ITRM operations for external systems. | |
| OBJECT_MANAGER | ||
| OBJECT_MANAGER_READ | ||
| OBJECT_MANAGER_WRITE | ||
| ORGANIZATION | Full access to manage organizations (Create, Read, Update, Delete). | |
| POLICY | Policy scope for external systems. | |
| POLICY_READ | ||
| RISK | Access to RISK operations for external systems. | |
| RISK_READ | ||
| SCIM | Full access to the SCIM APIs for User Provisioning — Users, Groups, Resources, Schemas and Service Provider endpoints. | |
| TRAINING | ||
| TRAINING_READ | ||
| USER | Full access to manage Users, User Groups and User Group membership (Create, Read, Update, Delete). | |
| VRM | Read/write operations on VRM (Third-Party Risk) components. | |
| VRM_READ | View details of VRM components. |
📄 Provider scope reference: https://developer.onetrust.com/onetrust/reference/oauth-20-scopes
Source
OAuth Scopes
Work with this as data
Every scope set here is available over the APIs.io API and to AI agents over MCP.