openapi: 3.2.0 info: title: Platform - User Provisioning SCIM Schemas V3 API description: OneTrust supports cross-domain identity management through the SCIM 2.0 specification. System for Cross-Domain Identity Management (SCIM) is an open specification to help facilitate the automated management of user identities and groups in cloud applications using RESTful APIs. This allows organizations to manage and update user information and group information across domains and applications. version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: SCIM Schemas V3 description: V3 version APIs to manager Schemas. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/platform-user-provisioning.json paths: /api/scim/v3/Schemas: get: operationId: getSchemasUsingGET summary: Get List of Supported SCIM Schemas description: 'Use this API to retrieve a list of schemas supported by SCIM 2.0 specifications. The response will include a collection of attributes that describe the contents of SCIM resources (i.e. User and Group). The attribute definitions specify the name of the attribute, metadata such as type (string, binary), cardinality (singular, multi, complex), mutability, and returnability. This API should only be used when provisioning and managing users from your Identity Provider using the System for Cross-Domain Identity Management (SCIM) standard to facilitate the automated creation of user identities from a third-party identity management application. > 🗒 Things to Know > > - This API supports OneTrust''s Legacy SCIM Integration that leverages SCIM groups, which are unique role-organization combinations that each represent a specific role within a particular organization. For more information, see Legacy SCIM User Provisioning.' tags: - SCIM Schemas V3 x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/platform-user-provisioning.json responses: '200': description: List of schemas retrieved successfully content: application/json: schema: $ref: '#/components/schemas/ListResponse' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - OAUTH2: - SCIM /api/scim/v3/Schemas/{schemaName}: get: operationId: getSchemasByNameUsingGET summary: Get SCIM Schema description: 'Use this API to retrieve details of a specific schema supported by SCIM 2.0 specifications. The response will include a collection of attributes that describe the contents of the specified SCIM resource. The attribute definitions specify the name of the attribute, metadata such as type (string, binary), cardinality (singular, multi, complex), mutability, and returnability. This API should only be used when provisioning and managing users from your Identity Provider using the System for Cross-Domain Identity Management (SCIM) standard to facilitate the automated creation of user identities from a third-party identity management application. > 🗒 Things to Know > > - This API supports OneTrust''s Legacy SCIM Integration that leverages SCIM groups, which are unique role-organization combinations that each represent a specific role within a particular organization. For more information, see Legacy SCIM User Provisioning.' tags: - SCIM Schemas V3 x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/platform-user-provisioning.json parameters: - name: schemaName in: path description: 'The name of the schema to retrieve. This identifies a specific schema supported by SCIM 2.0 specifications that describes the contents of SCIM resources (i.e. User and Group). The schema name can be obtained using the [Get List of Supported SCIM Schemas](/onetrust/reference/getschemasusingget) API. ' required: true schema: type: string enum: - urn:ietf:params:scim:schemas:core:2.0:User - urn:ietf:params:scim:schemas:core:2.0:Group - urn:ietf:params:scim:schemas:onetrust:Group - urn:ietf:params:scim:schemas:extension:enterprise:2.0:User maxLength: 255 minLength: 1 example: urn:ietf:params:scim:schemas:core:2.0:Group responses: '200': description: Schema retrieved successfully content: application/json: schema: $ref: '#/components/schemas/SchemaResource' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - OAUTH2: - SCIM components: schemas: Member: type: object properties: value: description: The unique ID of the user that you want to add to the Group. type: string format: uuid example: 3da9fe38-7845-4658-a96e-00071fa20c2e type: description: The type of the resource. type: string default: User enum: - User $ref: description: A hyperlink to the resource type: string format: url example: /api/scim/v3/Users/1bd418b2-85dd-4f04-955f-e4870e119ef1" readOnly: true required: - value title: Member Name: type: object properties: familyName: description: Family name (last name) of the user. type: string example: Smith maxLength: 100 minLength: 1 givenName: description: Given name (first name) of the user. type: string example: John maxLength: 100 minLength: 1 title: Name ResourceTypeResource: type: object properties: id: description: Unique identifier of the resource type type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 name: description: Name of the resource type type: string example: Users enum: - Users - Groups endpoint: description: Resource URL endpoint type: string example: /Users description: description: Description of the resource type type: string example: A user account in the OneTrust system maxLength: 255 minLength: 1 schema: description: Schema URI for the resource type type: string example: urn:ietf:params:scim:schemas:core:2.0:User enum: - urn:ietf:params:scim:schemas:core:2.0:User - urn:ietf:params:scim:schemas:core:2.0:Group meta: $ref: '#/components/schemas/Meta' readOnly: true schemaExtensions: $ref: '#/components/schemas/SchemaExtension' required: - description - endpoint - id - name - schema GroupResource: type: object properties: id: description: Unique identifier for the user created by the OneTrust application. type: string format: uuid example: aeb3d45d-0c05-4ff0-b635-6e3c3b2f86ea maxLength: 100 readOnly: true externalId: description: External Id type: string example: 3PNdoRZES0GLfV+9y1dDwQ== maxLength: 100 meta: $ref: '#/components/schemas/Meta' readOnly: true schemas: type: array items: type: string default: urn:ietf:params:scim:schemas:core:2.0:Group description: A collection of attribute definitions that describe the contents of an entire or partial resource. enum: - urn:ietf:params:scim:schemas:core:2.0:Group - urn:ietf:params:scim:schemas:onetrust:Group example: urn:ietf:params:scim:schemas:core:2.0:Group uniqueItems: true displayName: description: Assessments Manager - ADFS type: string example: Test Group maxLength: 255 minLength: 1 members: type: array items: $ref: '#/components/schemas/Member' urn:ietf:params:scim:schemas:onetrust:Group: $ref: '#/components/schemas/OneTrustGroup' required: - displayName title: GroupResource Supported: type: object properties: supported: description: Indicates whether the service provider supports the operation type: boolean example: false Email: type: object properties: value: description: Email of the user. type: string format: email example: gpburdell@onetrust.com minLength: 1 display: description: Email of the user. type: string format: email example: gpburdell@onetrust.com readOnly: true primary: description: Is the email the user's primary. Always `true` in the OneTrust application. type: boolean example: true default: 'true' readOnly: true $ref: description: Reference for the attribute type: string format: string type: description: The type of the email. In the OneTrust application, type is always 'work'. type: string example: work default: work required: - value SchemaExtension: type: object properties: schema: description: The schema extension schema type: string example: urn:ietf:params:scim:schemas:onetrust:Group required: description: True if the schema extension is required type: boolean example: true required: - required - schema AuthenticationScheme: type: object properties: name: description: Name of the authentication scheme type: string example: Oauth2 Bearer description: description: Description of the authentication scheme type: string example: OAuth2 Bearer access token is used for authorization. specUrl: description: URI of the specification for the authentication scheme type: string example: http://tools.ietf.org/html/rfc6749 documentationUrl: description: URI to retrieve more information about the authentication scheme type: string example: http://oauth.net/2/ type: description: Type of the authentication scheme type: string example: oauthbearertoken primary: description: Indicates whether the authentication scheme is primary type: boolean example: true ServiceProviderConfig: type: object properties: schemas: description: A collection of resource types supported by the service provider type: array items: type: string description: A collection of resource types supported by the service provider example: '["urn:ietf:params:scim:schemas:core:2.0:ServiceProviderConfig"]' example: - urn:ietf:params:scim:schemas:core:2.0:ServiceProviderConfig uniqueItems: true patch: $ref: '#/components/schemas/Supported' bulk: $ref: '#/components/schemas/BulkSupported' filter: $ref: '#/components/schemas/FilterSupported' changePassword: $ref: '#/components/schemas/Supported' sort: $ref: '#/components/schemas/Supported' etag: $ref: '#/components/schemas/Supported' xmlDataFormat: $ref: '#/components/schemas/Supported' authenticationSchemes: type: array items: $ref: '#/components/schemas/AuthenticationScheme' meta: $ref: '#/components/schemas/Meta' readOnly: true title: ServiceProviderConfig FilterSupported: type: object properties: supported: description: Indicates whether the service provider supports the operation type: boolean example: false maxResults: type: integer format: int32 ListResponse: type: object properties: schemas: type: array items: type: string description: List of Schemas. example: urn:ietf:params:scim:schemas:core:2.0:User uniqueItems: true totalResults: description: The total number of results in the list. type: integer format: int32 example: 2 minimum: 0 startIndex: description: TThe starting point of the result list. type: integer format: int32 example: 1 minimum: 1 itemsPerPage: description: The number of items per results page. type: integer format: int32 example: 25 minimum: 0 Resources: type: array items: type: object anyOf: - $ref: '#/components/schemas/GroupResource' - $ref: '#/components/schemas/UserResource' - $ref: '#/components/schemas/ResourceTypeResource' - $ref: '#/components/schemas/ServiceProviderConfig' description: Resources. SchemaResource: type: object properties: id: description: Unique identifier of the schema type: string format: uuid example: b430e8b1-748a-4f03-aa18-d32a79a3fae8 name: description: Name of the schema type: string example: User enum: - User - Group - OneTrustGroup - EnterpriseUser description: description: Description of the schema type: string example: User schema representation attributes: type: array items: type: object description: Attribute definition example: name: name type: string schema: urn:ietf:params:scim:schemas:core:2.0 subAttributes: [] meta: description: Metadata about the schema example: resourceType: User $ref: '#/components/schemas/Meta' readOnly: true required: - attributes - description - id - meta - name UserGroup: type: object properties: value: description: Unique identifier of a group in the application. type: string example: 5175be33-9b8d-4483-9d8b-1a9fb78bd97d display: description: Name of the User Group in the application. type: string example: R&D readOnly: true title: Group OneTrustGroup: type: object properties: category: description: The display name of the group type: string example: HR maxLength: 255 minLength: 1 description: description: The description of the group type: string example: HR User Group maxLength: 255 minLength: 1 title: UserGroup UserResource: type: object allOf: - $ref: '#/components/schemas/AbstractBaseResource' - type: object properties: schemas: type: array items: description: A collection of attribute definitions that describe the contents of an entire or partial resource. enum: - urn:ietf:params:scim:schemas:core:2.0:User example: urn:ietf:params:scim:schemas:core:2.0:User uniqueItems: true userName: description: Username of the user in the OneTrust application. type: string format: email example: gpburdell@onetrust.com maxLength: 256 name: $ref: '#/components/schemas/Name' userType: description: Type of the user. type: string example: Internal enum: - Internal - External active: description: The flag to check whether the user is an active or an inactive user. type: boolean example: true groups: type: array items: $ref: '#/components/schemas/UserGroup' readOnly: true readOnly: true emails: type: array items: $ref: '#/components/schemas/Email' roles: type: array items: format: json description: Role of the user within the OneTrust application. examples: - '["Auditor","Business Owner","Employee","Privacy Officer","Site Admin"]' title: description: Job title of the user type: string example: Product Manager maxLength: 255 urn:ietf:params:scim:schemas:extension:enterprise:2.0:User: description: Enterprise user details $ref: '#/components/schemas/EnterpriseUser' required: - name title: UserResource Meta: type: object properties: created: description: The date and time when the resource was created type: string format: date-time example: '2022-05-27T15:28:14.298Z' lastModified: description: The date and time when the resource was last modified type: string format: date-time example: '2022-05-27T15:28:14.298Z' location: description: The URL for the resource type: string format: uri example: /api/scim/v3/Users/53b1325c-081f-4f05-b41b-ba8cbdb7bae9 maxLength: 2083 minLength: 1 version: description: The version of the resource type: string example: W/"f0f2a936" maxLength: 100 minLength: 1 attributes: type: array items: description: The set of attributes example: - active - emails - userName uniqueItems: true resourceType: description: The resource type type: string example: Group enum: - User - Group - ResourceType - ServiceProviderConfig - Schema maxLength: 100 minLength: 1 readOnly: true title: Meta EnterpriseUser: type: object properties: businessUnit: description: User's business unit. type: string example: ESG maxLength: 255 division: description: The division with which the user is associated. type: string example: North America maxLength: 255 employeeNumber: description: User's employee number or ID. type: string example: '8675309' maxLength: 255 officeLocation: description: The office location of the user. type: string example: New York maxLength: 255 department: description: The department with which the user is associated. type: string example: R&D maxLength: 255 manager: $ref: '#/components/schemas/Manager' organization: description: Organization of the user within the OneTrust application. type: string example: OneTrust maxLength: 255 legacyManager: description: The legacy manager of the user. type: string example: legacy manager maxLength: 255 title: Additional Attributes Manager: type: object properties: value: description: The manager's GUID or `id` in the OneTrust application. Leverage the [Get List of Users](/onetrust/reference/getusers) API to obtain a list of users. Use the manager's `id` to populate `value`. type: string example: 23498234-9283-4620-8204-652982504620 maxLength: 100 minLength: 1 displayName: description: Manager's full name in the application. type: string example: John Doe readOnly: true $ref: description: Reference URL to the user type: string format: url example: /api/scim/v3/Users/23498234-9283-4620-8204-652982504620 readOnly: true required: - value title: Manager BulkSupported: type: object properties: supported: description: Indicates whether the service provider supports the operation type: boolean example: false maxOperations: type: integer format: int32 maxPayloadSize: type: integer format: int32 AbstractBaseResource: type: object properties: id: description: Unique identifier for the user created by the OneTrust application. type: string format: uuid example: aeb3d45d-0c05-4ff0-b635-6e3c3b2f86ea maxLength: 100 readOnly: true externalId: description: External Id type: string example: 3PNdoRZES0GLfV+9y1dDwQ== maxLength: 100 meta: $ref: '#/components/schemas/Meta' readOnly: true schemas: type: array items: type: string uniqueItems: true writeOnly: true title: AbstractBaseResource securitySchemes: OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: SCIM: Grants full access to the SCIM APIs for User Provisioning. This includes all the endpoints under Users, Groups, Resources, Schemas and Service Provider. x-onetrust: spec-label: OpenAPI 3.1.0 links: - '{''SCIM User & Group Provisioning'': ''https://my.onetrust.com/s/article/UUID-93f936ef-8076-280c-a58e-ba2d3437dfad?topicId=0TO1Q000000ItSxWAK''}' x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false