openapi: 3.2.0 info: title: Consent & Preferences - Universal Consent & Preference… version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 description: The Universal Consent & Preference Management APIs are used to integrate external systems and streamline the flow of data with Universal Consent & Preference Management in the OneTrust Platform. servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Deletion Certificates description: APIs to retrieve a paginated list of deletion certificates. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json x-displayName: Deletion Certificates paths: /rest/api/consent/v1/deletion-certificates: get: operationId: getListOfDeletionCertificates summary: Get List of Deletion Certificates description: Use this API to retrieve a paginated list of deletion certificates. Each result contains information about a data subject or receipts deletion certificate. Supports continuation tokens for pagination. tags: - Deletion Certificates x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json parameters: - name: requestContinuation in: header description: The token used to paginate a response if the number of records is more than a page. required: false schema: type: string example: '{\"compositeToken\": \"jmxpAKZxe9nZkAoAAAAAAA==\"}' - name: identifier in: header description: The unique identifier for a data subject. required: true schema: type: string example: example@otprivacy.com - name: page in: query description: The page number of the results. schema: type: integer default: 0 minimum: 0 example: 0 - name: size in: query description: The number of results per page. schema: type: integer default: 20 maximum: 50 minimum: 1 example: 20 responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/ConsentAPI_DeletionCertificateSliceDto' '400': description: Bad Request '401': description: Unauthorized content: application/json: schema: type: string '403': description: Forbidden content: application/json: schema: type: string '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - ConsentAPI_OAUTH2: - CONSENT - CONSENT_READ components: schemas: ConsentAPI_DeletionCertificateSliceDto: type: object properties: content: items: $ref: '#/components/schemas/ConsentAPI_DeletionCertificateResponseDto' type: array number: description: The page number of the results. type: integer format: int32 example: 1 size: description: The number of results per page. type: integer format: int32 example: 20 pageable: $ref: '#/components/schemas/ConsentAPI_PageableObject' last: description: Flag indicating whether this is the last page or not. type: boolean example: false sort: $ref: '#/components/schemas/ConsentAPI_SortObject' first: type: boolean numberOfElements: type: integer format: int32 empty: type: boolean requestContinuation: description: The token used to paginate a response if the number of records is more than a page. type: string example: '{\"compositeToken\": \"jmxpAKZxe9nZkAoAAAAAAA==\"}' ConsentAPI_DeletionCertificateResponseDto: type: object properties: objectId: description: The unique identifier of the deleted object type: string format: uuid example: 633ba071-61b0-485f-81a0-a2245777b432 objectType: description: The type of the deleted object type: string example: DATA_SUBJECT enum: - RECEIPT - DATA_SUBJECT - DATA_SUBJECT_PROFILE deleteTime: description: The date and time when the object was marked for deletion type: string format: date-time example: '2025-12-02T17:16:57.256567343' deleteType: description: Indicates the source from which the delete request was initiated type: string example: RETENTION enum: - RETENTION - API retentionPolicyRuleId: description: The identifier of the retention policy rule associated with this deletion type: string format: uuid example: 633ba071-61b0-485f-81a0-a2245777b432 ConsentAPI_PageableObject: type: object properties: offset: type: integer format: int64 sort: $ref: '#/components/schemas/ConsentAPI_SortObject' pageNumber: type: integer format: int32 paged: type: boolean pageSize: type: integer format: int32 unpaged: type: boolean ConsentAPI_SortObject: type: object properties: empty: type: boolean sorted: type: boolean unsorted: type: boolean securitySchemes: ConsentPreferences-UniversalConsentPreferenceManag_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: CONSENT: Consent Scope gives the user access to read/write operations CONSENT_READ: Consent Read Scope gives the user read-only access ConsentAPI_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: CONSENT: Consent Scope gives the user access to read/write operations CONSENT_READ: Consent Read Scope gives the user read-only access DSPreferneceCache_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: CONSENT: Consent Scope gives the user access to read/write operations CONSENT_READ: Consent Read Scope gives the user read-only access x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false x-onetrust: spec-label: OpenAPI 3.1.0