openapi: 3.2.0 info: title: Consent & Preferences - Universal Consent & Preference… version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 description: The Universal Consent & Preference Management APIs are used to integrate external systems and streamline the flow of data with Universal Consent & Preference Management in the OneTrust Platform. servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Consent Attachments description: APIs for managing Consent Attachments. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json x-displayName: Consent Attachments paths: /rest/api/preferences/v1/attachments: post: operationId: uploadConsentAttachments summary: Upload Consent Attachment description: 'Use this API to upload and store files which contain written consent of data subjects'' transactions. > 🗒 Things to Know > > - The size of uploaded files must be less than 4MB. > > - The following file formats are allowed: .pdf, .jpeg, .jpg, and .png. > > - The `RefID` parameter returned within the response body can be used to attach file references to incoming data subject consents using the Create Consent Receipts API. > > - File references can be attached to a given data subject or data subject purpose by using the `attachments` or `PurposeAttachments` parameters in the Create Consent Receipts API respectively.' tags: - Consent Attachments x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json requestBody: required: true content: multipart/form-data: schema: type: object properties: file: description: 'The file to upload. Supported formats: .pdf, .jpeg, .jpg, .png. Max size: 4MB.' type: string format: binary required: - file responses: '200': description: File uploaded successfully. content: application/json: schema: $ref: '#/components/schemas/DSPreferneceCache_UploadDataDto' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - DSPreferneceCache_OAUTH2: - CONSENT /rest/api/preferences/v1/attachments/{attachmentId}: get: operationId: downloadGivenConsentAttachments summary: Download Consent Attachment description: 'Use this API to download a specific file reference attached to a given data subject. The file will be downloaded in .zip format. > 🗒 Things to Know > > - The `attachmentId` parameter value corresponds to the `RefId` parameter value returned after uploading a file using the Upload Consent Attachment API.' tags: - Consent Attachments x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json parameters: - name: attachmentId in: path description: Unique `refId` UUID of the file to be downloaded. required: true schema: type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 - name: identifier in: header description: The identifier of the data subject. required: true schema: type: string example: user@example.com responses: '200': description: ZIP file containing the requested attachment. content: application/zip: schema: description: Binary content of the ZIP file containing the requested attachment. type: string format: binary '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - DSPreferneceCache_OAUTH2: - CONSENT - CONSENT_READ /rest/api/preferences/v1/attachments-reference/{attachmentId}: delete: operationId: removeGivenConsentAttachmentRefs summary: Remove Consent Attachment description: 'Use this API to remove a specific file reference attached to a given data subject. > 🗒 Things to Know > > - The `attachmentId` parameter value corresponds to the `RefId` parameter value returned after uploading a file using the Upload Attachments API.' tags: - Consent Attachments x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json parameters: - name: attachmentId in: path description: Unique referenceId `refId` UUID of the file which has to removed from Data Subject. required: true schema: type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 - name: identifier in: header description: The identifier of the data subject. required: true schema: type: string example: user@example.com responses: '202': description: Attachment reference deletion request accepted for processing. content: application/json: schema: $ref: '#/components/schemas/DSPreferneceCache_ConsentAttachmentReferencesResponse' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - DSPreferneceCache_OAUTH2: - CONSENT /rest/api/preferences/v1/datasubjects/{identifier}/attachment-references: delete: operationId: removeAllConsentAttachmentRefs summary: Remove All Consent Attachments description: Use this API to remove all file references attached to a given data subject. tags: - Consent Attachments x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json parameters: - name: identifier in: path description: The identifier of the data subject. required: true schema: type: string example: user@example.com responses: '202': description: All attachment references deletion request accepted for processing. content: application/json: schema: $ref: '#/components/schemas/DSPreferneceCache_ConsentAttachmentReferencesResponse' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - DSPreferneceCache_OAUTH2: - CONSENT /rest/api/preferences/v1/datasubjects/{identifier}/attachments: get: operationId: downloadConsentAttachments summary: Download All Consent Attachments description: Use this API to retrieve all available file references attached to a given data subject. The files will be downloaded in .zip format. tags: - Consent Attachments x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json parameters: - name: identifier in: path description: The identifier of the data subject. required: true schema: type: string example: user@example.com responses: '200': description: ZIP file containing all attachments. content: application/zip: schema: description: Binary content of the ZIP file containing all the data subject's attachments. type: string format: binary '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - DSPreferneceCache_OAUTH2: - CONSENT - CONSENT_READ components: schemas: DSPreferneceCache_UploadDataDto: type: object properties: refId: description: Reference ID for the uploaded file. type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 filename: description: Original name of the uploaded file. type: string example: consent_form.pdf fileSize: description: Size of the uploaded file in bytes. type: integer format: int64 example: 1024 contentType: description: MIME type of the uploaded file. type: string example: application/pdf qualifiedName: description: Fully qualified name/path of the uploaded file in storage. type: string example: tenant123/attachments/consent_form.pdf DSPreferneceCache_ConsentAttachmentReferencesResponse: type: object properties: identifier: description: Identifier of the data subject type: string example: user@example.com statusMessage: description: Status message describing the result of the operation type: string example: Attachment references deletion Request has been accepted for processing securitySchemes: ConsentPreferences-UniversalConsentPreferenceManag_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: CONSENT: Consent Scope gives the user access to read/write operations CONSENT_READ: Consent Read Scope gives the user read-only access ConsentAPI_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: CONSENT: Consent Scope gives the user access to read/write operations CONSENT_READ: Consent Read Scope gives the user read-only access DSPreferneceCache_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: CONSENT: Consent Scope gives the user access to read/write operations CONSENT_READ: Consent Read Scope gives the user read-only access x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false x-onetrust: spec-label: OpenAPI 3.1.0