openapi: 3.2.0 info: title: Privacy Automation - Assessment Automation Template API version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 description: The Assessment Automation APIs provide functionality for managing assessment template lifecycle operations, including template export and import for cross-environment migration, retrieving published template metadata with filtering by template type, and template deletion with comprehensive validation checks. servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Template description: APIs to manage assessment template operations including import and export functionality for cross-tenant migration, retrieval of published template listings with type-based filtering, and template deletion with dependency validation. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json x-displayName: Template paths: /api/template/v1/published-template-metadata: get: operationId: getAllBasicTemplateDetailsUsingGET summary: Get List of Templates description: 'Use this API to retrieve the details of all the published templates. The response includes basic template details such as the template name, template root version ID, and template type. > 🗒 Things to Know > > - The following template types are available: > > > > Template Types > > CONTROL: Control templates created in IT & Security Risk Management > > DISCLOSURE: Disclosure Management > > ESG: ESG Program Reporting & Disclosures > > EXCHANGE: Third-Party Risk Exchange > > INCIDENT: Incident Management > > ITRM: IT & Security Risk Management > > PIA: PIA & DPIA Automation > > VENDOR: Third-Party Risk Management > > > > - If the template type is not specified in the API request body, all template types will be included in the response.' tags: - Template x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json parameters: - name: template-types in: query description: The array of template types to filter by when retrieving published templates. required: false schema: type: array items: type: string description: Template types to filter by. If not specified, all template types will be included. enum: - CONTROL - DISCLOSURE - ESG - EXCHANGE - INCIDENT - ITRM - PIA - VENDOR example: - CONTROL - ITRM responses: '200': description: OK content: application/json: schema: type: array items: $ref: '#/components/schemas/Template_TemplateBasicDetailsDto' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - Template_OAUTH2: - INTEGRATION - ASSESSMENT_READ - ASSESSMENT /api/template/v2/templates/import: post: operationId: importTemplateByIdUsingPOST summary: Import Template description: 'Use this API to import the metadata of a specific template in JSON format in order to migrate the template from one environment/tenant to another environment/tenant. Before calling this API, use the Export Template API to obtain the template metadata in JSON format. The JSON response body obtained from the Export Template API can then be pasted within the Import Template request body (BODY PARAMS). > 🗒 Things to Know > > - After the import, the template will reflect on the Templates page in Draft status. > > - If a template with the same name already exists on the destination environment, then the migration will fail (HTTP Response Status Code 400: Duplicate template name). Please ensure that no templates (Active or Archived) already exist with the same name as the template being migrated. > > - If your template contains questions linked to custom inventory attributes, it is crucial that the same attributes have already been created in the destination environment/tenant and are an identical match.' tags: - Template x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json parameters: - name: matchAttributesByName in: query description: The flag indicating whether to match attributes by name during template import. required: true schema: description: If true, will match attributes by name during import type: boolean example: true requestBody: required: true content: application/json: schema: type: object example: '{"template": {"id": "7d271be5-0601-4190-96a7-65d7c427a725", "name": "OnePIA", "status": "PUBLISHED" }' additionalProperties: true responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/Template_TemplateCreateResponse' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - Template_OAUTH2: - INTEGRATION - ASSESSMENT /api/template/v2/templates/root-version/{rootVersionId}/templates: delete: operationId: deleteTemplateVersionsUsingDELETE summary: Delete Template description: 'The API can be used to delete a template using its root version identifier. > 🗒 Things to Know > > - The template should not be associated with any Assessment or any action rules of other templates. > > - Template of specific types PIA, VENDOR, ITRM, CONTROL, INCIDENT, EXCHANGE, ESG, DISCLOSURE, ERM, TPDD, DISCLOSURE_YOY can be deleted using the API. > > - The root version identifier of a template can be retrieved by calling the Get List of Templates API.' tags: - Template x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json parameters: - name: rootVersionId in: path description: The root version identifier of the template to be deleted. required: true schema: description: The UUID of the root version of the template to delete type: string format: uuid example: 7d271be5-0601-4190-96a7-65d7c427a725 responses: '204': description: No Content '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - Template_OAUTH2: - INTEGRATION - ASSESSMENT /api/template/v2/templates/{templateId}/export: get: operationId: exportTemplateWithBusinessKeysUsingGET summary: Export Template description: 'Use this API to export the metadata of a specific template in JSON format in order to migrate the template from one environment/tenant to another environment/tenant. The response body will be returned in JSON format and will include template details such as questions, rules, skip/show logic, etc. > 🗒 Things to Know > > - The JSON response body returned by this API can be pasted within the Import Template API''s request body to import the metadata of the template into the environment/tenant. > - The `templateRootVersionId` must be passed as the value for the `templateId` parameter if you are passing the `templateVersion` query parameter in the request. > - The response of this API will vary based on whether the `templateVersion` parameter is passed. > - If this parameter is not passed, then the template corresponding to the `templateId` will be exported. > - If a specific version value is passed for this parameter, then that version of the template will be exported. > - If `latest` is passed for this parameter, then the latest version of the template will be exported.' tags: - Template x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/privacy-automation-assessment-automation.json parameters: - name: templateId in: path description: The unique identifier of the template to export. required: true schema: description: The UUID of the template to export type: string format: uuid example: 7d271be5-0601-4190-96a7-65d7c427a725 - name: templateVersion in: query description: The specific version of the template to export or 'latest' for newest version. required: false schema: description: The version of the template to export. If not specified, exports the template corresponding to templateId. If 'latest' is passed, exports the latest version of the template. type: string example: latest responses: '200': description: OK content: application/json: schema: type: object example: template: id: 7d271be5-0601-4190-96a7-65d7c427a725 name: OnePIA status: PUBLISHED additionalProperties: true '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - Template_OAUTH2: - INTEGRATION - ASSESSMENT_READ - ASSESSMENT components: schemas: Template_TemplateCreateResponse: type: object properties: id: description: The unique identifier of the created template. type: string format: uuid example: 7d271be5-0601-4190-96a7-65d7c427a725 rootVersionId: description: The root version identifier of the template used for version management. type: string format: uuid example: 7d271be5-0601-4190-96a7-65d7c427a725 templateVersion: description: The version number of the template indicating its iteration. type: integer format: int32 example: 1 languageCode: description: The language code specifying the localization of the template. type: string example: en Template_TemplateBasicDetailsDto: type: object properties: name: description: The display name of the published template. type: string example: Sample Template rootVersionId: description: The root version identifier used for template management and operations. type: string format: uuid example: 7d271be5-0601-4190-96a7-65d7c427a725 templateType: description: The classification type of the template indicating its purpose and module. type: string example: PIA default: PIA enum: - PIA - VENDOR - ITRM - CONTROL - ESG - TPDD - AIGOVERNANCE securitySchemes: PrivacyAutomation-AssessmentAutomation_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: ASSESSMENT: Access to assessment scope for external systems ASSESSMENT_READ: Access to read assessment scope for external systems Template_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: ASSESSMENT: Access to assessment scope for external systems ASSESSMENT_READ: Access to read assessment scope for external systems x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false x-onetrust: spec-label: OpenAPI 3.1.0