openapi: 3.2.0 info: title: Platform - User Provisioning Service Provider V3 API description: OneTrust supports cross-domain identity management through the SCIM 2.0 specification. System for Cross-Domain Identity Management (SCIM) is an open specification to help facilitate the automated management of user identities and groups in cloud applications using RESTful APIs. This allows organizations to manage and update user information and group information across domains and applications. version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Service Provider V3 description: V3 version APIs to manager the Service Provider. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/platform-user-provisioning.json paths: /api/scim/v3/ServiceProviderConfig: get: operationId: getServiceProviderConfigUsingGET summary: Get Service Provider Configuration description: 'Use this API to retrieve the service provider configuration resource. The service provider configuration resource enables discovery of SCIM specification features in a standardized form and provides additional implementation details. This API should only be used when provisioning and managing users from your Identity Provider using the System for Cross-Domain Identity Management (SCIM) standard to facilitate the automated creation of user identities from a third-party identity management application. > 🗒 Things to Know > > - This API supports OneTrust''s Legacy SCIM Integration that leverages SCIM groups, which are unique role-organization combinations that each represent a specific role within a particular organization. For more information, see Legacy SCIM User Provisioning.' tags: - Service Provider V3 x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/platform-user-provisioning.json responses: '200': description: Service provider configuration retrieved successfully content: application/json: schema: $ref: '#/components/schemas/ServiceProviderConfig' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - OAUTH2: - SCIM components: schemas: AuthenticationScheme: type: object properties: name: description: Name of the authentication scheme type: string example: Oauth2 Bearer description: description: Description of the authentication scheme type: string example: OAuth2 Bearer access token is used for authorization. specUrl: description: URI of the specification for the authentication scheme type: string example: http://tools.ietf.org/html/rfc6749 documentationUrl: description: URI to retrieve more information about the authentication scheme type: string example: http://oauth.net/2/ type: description: Type of the authentication scheme type: string example: oauthbearertoken primary: description: Indicates whether the authentication scheme is primary type: boolean example: true Meta: type: object properties: created: description: The date and time when the resource was created type: string format: date-time example: '2022-05-27T15:28:14.298Z' lastModified: description: The date and time when the resource was last modified type: string format: date-time example: '2022-05-27T15:28:14.298Z' location: description: The URL for the resource type: string format: uri example: /api/scim/v3/Users/53b1325c-081f-4f05-b41b-ba8cbdb7bae9 maxLength: 2083 minLength: 1 version: description: The version of the resource type: string example: W/"f0f2a936" maxLength: 100 minLength: 1 attributes: type: array items: description: The set of attributes example: - active - emails - userName uniqueItems: true resourceType: description: The resource type type: string example: Group enum: - User - Group - ResourceType - ServiceProviderConfig - Schema maxLength: 100 minLength: 1 readOnly: true title: Meta ServiceProviderConfig: type: object properties: schemas: description: A collection of resource types supported by the service provider type: array items: type: string description: A collection of resource types supported by the service provider example: '["urn:ietf:params:scim:schemas:core:2.0:ServiceProviderConfig"]' example: - urn:ietf:params:scim:schemas:core:2.0:ServiceProviderConfig uniqueItems: true patch: $ref: '#/components/schemas/Supported' bulk: $ref: '#/components/schemas/BulkSupported' filter: $ref: '#/components/schemas/FilterSupported' changePassword: $ref: '#/components/schemas/Supported' sort: $ref: '#/components/schemas/Supported' etag: $ref: '#/components/schemas/Supported' xmlDataFormat: $ref: '#/components/schemas/Supported' authenticationSchemes: type: array items: $ref: '#/components/schemas/AuthenticationScheme' meta: $ref: '#/components/schemas/Meta' readOnly: true title: ServiceProviderConfig FilterSupported: type: object properties: supported: description: Indicates whether the service provider supports the operation type: boolean example: false maxResults: type: integer format: int32 BulkSupported: type: object properties: supported: description: Indicates whether the service provider supports the operation type: boolean example: false maxOperations: type: integer format: int32 maxPayloadSize: type: integer format: int32 Supported: type: object properties: supported: description: Indicates whether the service provider supports the operation type: boolean example: false securitySchemes: OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: SCIM: Grants full access to the SCIM APIs for User Provisioning. This includes all the endpoints under Users, Groups, Resources, Schemas and Service Provider. x-onetrust: spec-label: OpenAPI 3.1.0 links: - '{''SCIM User & Group Provisioning'': ''https://my.onetrust.com/s/article/UUID-93f936ef-8076-280c-a58e-ba2d3437dfad?topicId=0TO1Q000000ItSxWAK''}' x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false