openapi: 3.2.0 info: title: Platform - Documents Attachments V4 API version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 description: The Documents API are used to integrate external systems and streamline the flow of data for documents in the OneTrust Platform. servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Attachments V4 paths: /api/document/v4/attachments/token/{attachmentId}: get: operationId: getAttachmentDownloadTokenV4 summary: Get Download Token description: Use this API to obtain a short-lived download token for an attachment. The token must be presented to the document-gateway to download the file content. tags: - Attachments V4 parameters: - name: attachmentId in: path description: ID of the attachment. This corresponds to the `attachmentId` returned by the V4 upload flow. required: true schema: type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000 responses: '200': description: Download token generated successfully content: application/json: schema: $ref: '#/components/schemas/TokenResponse' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - OAUTH2: - ATTACHMENT - ATTACHMENT_READ components: schemas: TokenResponse: type: object properties: attachmentId: type: string format: uuid token: type: string securitySchemes: OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: ATTACHMENT: Grants access to view and manage attachments ATTACHMENT_READ: Grants access to view attachments x-onetrust: spec-label: OpenAPI 3.1.0 x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false