openapi: 3.2.0 info: title: Consent & Preferences - Universal Consent & Preference… version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 description: The Universal Consent & Preference Management APIs are used to integrate external systems and streamline the flow of data with Universal Consent & Preference Management in the OneTrust Platform. servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Receipts description: The Receipts APIs are used to manage records of consent transactions. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json x-displayName: Receipts paths: /api/consentmanager/v1/receipt-list: get: operationId: getReceiptListUsingGET summary: Get List of Receipts by Data Subject description: '> ❗️ End of Support Notification > > As of September 1, 2024, these APIs are now deprecated. Any customers leveraging these APIs are encouraged to migrate to the Receipts V2 API. For more information, see OneTrust API Sunsetting & Deprecation Guidelines. Use this API to retrieve a list of consent receipts for a given data subject.' tags: - Receipts x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json parameters: - name: identifier in: header description: Data Subject Identifier filter. required: true schema: type: string example: user@example.com responses: '200': description: OK - Successfully retrieved receipts. content: application/json: examples: SuccessResponse: summary: Example receipt list response description: Sample response containing a list of receipts value: receipts: - Receipt Name - Last Modified Date '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - ConsentPreferences-UniversalConsentPreferenceManag_OAUTH2: - CONSENT - CONSENT_READ /api/consentmanager/v1/receipts: get: operationId: getReceiptListDetailsUsingGET summary: Get List of Receipt Details by Data Subject description: '> ❗️ End of Support Notification > > As of September 1, 2024, these APIs are now deprecated. Any customers leveraging these APIs are encouraged to migrate to the Receipts V2 API. For more information, see OneTrust API Sunsetting & Deprecation Guidelines. Use this API to retrieve a list of consent receipts for a given data subject along with details such as the associated Purposes, Purpose Preferences, and attributes. The response will also include relevant information about the latest Collection Point interactions and the current status of consent.' tags: - Receipts x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json parameters: - name: identifier in: header description: Data Subject Identifier filter. required: true schema: type: string example: user@example.com - name: includeNotgiven in: query description: If true, the response will include Non Given transactions. required: false schema: type: boolean default: false - name: page in: query description: Results page you want to retrieve (0-based). schema: type: integer example: 0 default: 0 minimum: 0 - name: size in: query description: Number of records per page (1-50) schema: type: integer example: 20 default: 50 maximum: 50 minimum: 1 responses: '200': description: OK - Successfully retrieved receipt details. content: application/json: schema: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_ReceiptInformationDetailSliceDto' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - ConsentPreferences-UniversalConsentPreferenceManag_OAUTH2: - CONSENT - CONSENT_READ /api/consentmanager/v1/receipts/{id}: get: operationId: findReceiptUsingGET summary: Get Receipt description: '> ❗️ End of Support Notification > > As of September 1, 2024, these APIs are now deprecated. Any customers leveraging these APIs are encouraged to migrate to the Receipts V2 API. For more information, see OneTrust API Sunsetting & Deprecation Guidelines. Use this API to retrieve a single receipt by its unique identifier. The response will return information such as the receipt interaction date along with details of the Purposes that the data subject has interacted with, and their corresponding statuses.' tags: - Receipts x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json parameters: - name: id in: path description: The unique identifier of the receipt. required: true schema: type: string format: uuid example: 97a87bf2-d84d-428d-9e3a-703f33ff8f6a - name: includeNotgiven in: query description: If true, the response will include Non Given transactions. required: false schema: type: boolean default: false - name: includeConsentStrings in: query description: If true, the response will include consent strings. required: false schema: type: boolean default: false responses: '200': description: OK - Successfully retrieved receipt. content: application/json: schema: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_ReceiptInformationDetailDto' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - ConsentPreferences-UniversalConsentPreferenceManag_OAUTH2: - CONSENT - CONSENT_READ components: schemas: ConsentPreferences-UniversalConsentPreferenceManag_DownStreamRuleAction: properties: actionType: type: string enum: - SEND_EMAIL - DATA_SUBJECT_UPDATE - DATA_SUBJECT_PROFILE_UPDATE - PUBLISH_INTEGRATION_EVENT ruleAction: type: string ruleActionParameter: type: string ConsentPreferences-UniversalConsentPreferenceManag_TopicLanguageDtoV2: properties: name: type: string language: type: string default: type: boolean ConsentPreferences-UniversalConsentPreferenceManag_DsAttachments: properties: id: type: string format: uuid ConsentPreferences-UniversalConsentPreferenceManag_PageableObject: properties: offset: type: integer format: int64 sort: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_SortObject' pageNumber: type: integer format: int32 pageSize: type: integer format: int32 paged: type: boolean unpaged: type: boolean ConsentPreferences-UniversalConsentPreferenceManag_CustomPreferenceLanguageDtoV2: properties: name: type: string description: type: string language: type: string default: type: boolean options: type: array items: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_CustomPreferenceOptionDtoV2' ConsentPreferences-UniversalConsentPreferenceManag_ReceiptInformationDetailSliceDto: type: object properties: content: items: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_ReceiptInformationDetailDto' type: array number: description: The page number of the results. type: integer format: int32 example: 1 size: description: The number of results per page. type: integer format: int32 example: 20 pageable: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_PageableObject' last: description: Flag indicating whether this is the last page or not. type: boolean example: false sort: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_SortObject' first: type: boolean numberOfElements: type: integer format: int32 empty: type: boolean ConsentPreferences-UniversalConsentPreferenceManag_RuleActionResult: properties: ruleAction: type: string ruleActionParameter: type: string ruleActionStatus: type: string enum: - COMPLETED - PARTIALLY_COMPLETED - NOT_INITIATED - FAILED downStreamRuleActions: type: array items: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_DownStreamRuleAction' ConsentPreferences-UniversalConsentPreferenceManag_PurposeInformationDtoV2: properties: id: description: Unique identifier of the purpose type: string format: uuid example: f2229953-b4b5-4042-8cb9-b78038cc4c46 name: description: Name of the purpose type: string example: Marketing Communications description: description: Detailed description of the purpose's data processing activities type: string example: Collect customer emails for marketing purposes status: description: Current status of the purpose type: string example: ACTIVE enum: - DRAFT - ACTIVE - RETIRED version: description: Version number of the purpose type: integer format: int64 example: 2 purposeType: description: Classification type of the purpose type: string example: STANDARD enum: - STANDARD - COOKIE - IAB - MOBILE - NOTIFICATION_OPT_OUT consentLifeSpan: description: Duration in seconds that consents for this purpose remain valid type: integer format: int64 example: 7889238 transactionType: description: Type of transaction associated with the purpose type: string example: CONFIRMED enum: - PENDING - CONFIRMED - WITHDRAWN - EXPIRED - NOTGIVEN - OPT_OUT - NO_CHOICE - HARD_OPT_OUT - EXTEND - CHANGE_PREFERENCES - OPT_IN - NO_OPT_OUT - CANCEL - IMPLICIT topics: description: List of topics associated with this purpose type: array items: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_PurposeTopicDtoV2' reactivationDate: description: Indicates the date and time on which a consent will be reactivated. This is set when a purpose is snoozed until the specified date and time. The consent remains snoozed until this date, after which it is automatically reactivated and becomes active again. type: string format: date-time purposeAttachments: description: List of file attachments or documents associated with the purpose type: array items: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_DsAttachments' purposeScopes: description: List of scopes or contexts where this purpose applies type: array items: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_DsPurposeScope' customPreferences: description: List of custom preferences associated with this purpose type: array items: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_PurposeCustomPreferenceDtoV2' purposeNote: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_PurposeNoteDtoV2' attributes: description: Key-value pairs of custom attributes associated with the purpose type: object additionalProperties: type: array description: Key-value pairs of custom attributes associated with the purpose items: type: string description: Key-value pairs of custom attributes associated with the purpose ConsentPreferences-UniversalConsentPreferenceManag_DsGeolocation: properties: country: description: Country of the DataSubject type: string example: US state: description: State Code of the DataSubject type: string example: GA stateName: description: State Name of the DataSubject type: string example: Georgia purposeIds: description: List of Unique Identifiers of the Purpose for which Geolocation parameters are sent type: array items: type: string format: uuid description: List of Unique Identifiers of the Purpose for which Geolocation parameters are sent example: '[f2229953-b4b5-4042-8cb9-b78038cc4c46, bc4836e2-c117-461b-a7a2-2b268c037a97]' uniqueItems: true ConsentPreferences-UniversalConsentPreferenceManag_PurposeCustomPreferenceDtoV2: properties: id: description: Unique identifier of the purpose-custom preference relationship type: string example: c4a57a38-3774-45ad-9fa4-dbc545542232 name: description: Name of the custom preference type: string example: Email Frequency displayAs: description: Display type for rendering the custom preference in the UI type: string example: BUTTONS enum: - BUTTONS - CHECKBOXES customPreferenceOptions: description: List of available options for this custom preference type: array items: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_CustomPreferenceOptionDtoV2' languages: description: List of language-specific content for the custom preference type: array items: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_CustomPreferenceLanguageDtoV2' required: - displayAs - id - name ConsentPreferences-UniversalConsentPreferenceManag_ConsentStringDto: properties: type: description: Type of the consent string (e.g., IAB_TCF_V2, ONETRUST) type: string example: IAB_TCF_V2 content: description: The actual consent string content (base64 encoded string) example: COzQOA8O1zG3YCABBDEA0CsAP_AAH_AAAAAI6td_H__bX9j-em_6bftr9Bf7a_9tfuA0mGcc1ZcnAkigTgQhRfmkfbO2JwY6D5Y6G1AAQhoQHtH6EGAAaEBAgIAAoACAIQAgQAgACBAAAAA type: string ConsentPreferences-UniversalConsentPreferenceManag_CustomPreferenceOptionDtoV2: properties: id: type: string transactionType: type: string label: type: string order: type: integer format: int32 isDefault: type: boolean ConsentPreferences-UniversalConsentPreferenceManag_PurposeNoteDtoV2: properties: noteId: description: Unique identifier of the reason template type: string format: uuid noteType: description: The type of the note type: string enum: - UNSUBSCRIBE_REASON noteLanguage: description: The language of the note type: string noteText: description: The actual text of the note type: string isValidNote: description: Flag indicating if the note is a valid reason template type: boolean ConsentPreferences-UniversalConsentPreferenceManag_PurposeTopicDtoV2: properties: id: description: Unique identifier of the purpose-topic relationship type: string format: uuid example: 497c4383-2c61-4906-aed0-660e3fd03ef0 transactionType: description: Type of transaction associated with the topic type: string example: OPT_IN name: description: Name of the topic type: string example: Car Marketing integrationKey: description: Integration key formed by combining purpose and topic names type: string example: Marketing-Communications_Car-Marketing languages: description: List of language-specific content for the topic type: array items: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_TopicLanguageDtoV2' canDelete: description: Indicates whether this topic can be deleted type: boolean example: true required: - id - name ConsentPreferences-UniversalConsentPreferenceManag_SortObject: properties: empty: type: boolean sorted: type: boolean unsorted: type: boolean ConsentPreferences-UniversalConsentPreferenceManag_SourceDto: properties: type: description: Type of the source (e.g., 'WEB', 'MOBILE_APP', 'API') type: string example: WEB content: description: Content or identifier from the source system example: https://example.com/consent type: string purposeIds: description: List of purpose IDs associated with this source type: array items: type: string format: uuid description: List of purpose IDs associated with this source example: '[550e8400-e29b-41d4-a716-446655440000]' ConsentPreferences-UniversalConsentPreferenceManag_DsPurposeScope: properties: key: type: string value: type: string ConsentPreferences-UniversalConsentPreferenceManag_RuleEvaluationResult: properties: ruleId: type: string format: uuid ruleGroupId: type: string format: uuid consentRuleType: type: string enum: - CONSENT_INGEST evaluationResult: type: boolean actionResults: type: array items: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_RuleActionResult' resultData: type: array items: type: object additionalParams: type: object additionalProperties: type: object ConsentPreferences-UniversalConsentPreferenceManag_ReceiptInformationDetailDto: type: object properties: id: description: The unique identifier for the receipt type: string format: uuid example: 09ccd1b9-84a0-4bcb-a167-f761391ebffa otJwtVersion: description: Version of the JWT token used for the receipt type: integer format: int64 example: 1 dataSubjectIdentifierHash: description: Hashed value of the data subject's identifier for privacy protection type: string example: ee26b0dd4af7e749aa1a8ee3c10ae9923f618980772e473f8819a5d4940e0db27ac185f8a0e1d5f84f88bc887fd67b143732c304cc5fa9ad8e6f57f50028a8ff dataSubjectIdentifier: description: The actual identifier of the data subject (e.g., email, user ID) type: string example: user@example.com collectionPointUUID: description: Unique identifier of the collection point that generated this receipt type: string format: uuid example: 25d9ccac-db88-4d34-849c-3d602a629961 collectionPointVersion: description: Version number of the collection point type: integer format: int64 example: 2 collectionPointName: description: Human-readable name of the collection point type: string example: Website Signup Form consentCreationDate: description: Timestamp when the consent was created type: string format: date-time example: '2023-10-08T12:00:00Z' receiptJwt: description: JWT token containing the receipt information type: string example: AABmODM2OGM0ZC1mMmUwLTQ2MGYtYjQyOC03ZTQyZjQ1MWI3MGVJovwdqc7MU+49lOy customPayload: description: Custom JSON payload included with the receipt type: string example: '{"payload1":"value1","payload2":"value2"}' purposes: description: List of purposes associated with this receipt type: array items: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_PurposeInformationDtoV2' test: description: Indicates if this receipt was created in test mode type: boolean example: false origin: description: Source origin of the consent request type: string enum: - IMPORT - API - SDK - ONETRUST - PREFERENCE_CENTER - EMAIL_CLIENT_ONE_CLICK - HISTORIC_IMPORT doubleOptIn: description: Indicates if double opt-in was required for this consent type: boolean example: true language: description: Language code for the consent interaction type: string example: en-US collectionPointType: description: Type of the collection point type: string example: WEB_FORM isAnonymous: description: Indicates if the consent was given anonymously type: boolean example: false attributes: description: Additional attributes associated with the receipt type: object additionalProperties: type: array description: Additional attributes associated with the receipt items: type: object description: Additional attributes associated with the receipt interactionDate: description: Timestamp of the user interaction that generated this receipt type: string format: date-time dsDataElements: description: Data subject related data elements type: object additionalProperties: type: object description: Data subject related data elements unsubscribeAll: description: Indicates if the user opted to unsubscribe from all communications type: boolean example: false attachments: description: List of attachments associated with the receipt type: array items: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_DsAttachments' additionalIdentifiers: description: Additional identifiers for the data subject type: object additionalProperties: type: object description: Additional identifiers for the data subject geolocation: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_DsGeolocation' ruleEvaluationResults: description: Results of any rules evaluated during consent processing type: array items: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_RuleEvaluationResult' consentStringDto: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_ConsentStringDto' source: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_SourceDto' required: - id - receiptJwt securitySchemes: ConsentPreferences-UniversalConsentPreferenceManag_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: CONSENT: Consent Scope gives the user access to read/write operations CONSENT_READ: Consent Read Scope gives the user read-only access ConsentAPI_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: CONSENT: Consent Scope gives the user access to read/write operations CONSENT_READ: Consent Read Scope gives the user read-only access DSPreferneceCache_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: CONSENT: Consent Scope gives the user access to read/write operations CONSENT_READ: Consent Read Scope gives the user read-only access x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false x-onetrust: spec-label: OpenAPI 3.1.0