openapi: 3.2.0 info: title: Consent & Preferences - Universal Consent & Preference… version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 description: The Universal Consent & Preference Management APIs are used to integrate external systems and streamline the flow of data with Universal Consent & Preference Management in the OneTrust Platform. servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Transactions description: The Transactions APIs are used to manage consent transactions. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json x-displayName: Transactions paths: /api/consentmanager/v1/transactions/withdraw/fordatasubject: put: operationId: withdrawTransactionBehalfOfDatasubjectUsingPUT summary: Withdraw Consent on Behalf of a Data Subject description: Use this API to withdraw consent on behalf of a data subject for a specific Purpose. The data subject identifier must be included either in the `identifier` query or header parameter, preferably passed in the header. tags: - Transactions x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json parameters: - name: identifier in: query description: Data Subject Identifier (prefer the header parameter). required: false schema: type: string example: user@example.com deprecated: true - name: identifier in: header description: Data Subject Identifier (prefer the header parameter). required: false schema: type: string example: user@example.com - name: withdrawnBy in: query description: User withdrawing consent on behalf of data subject. required: true schema: type: string example: admin@example.com requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_WithdrawOnBehalfOfRequest' responses: '200': description: OK - Successfully withdrew consent on behalf of data subject content: application/json: schema: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_TransactionWithdrawResult' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error deprecated: true security: - ConsentPreferences-UniversalConsentPreferenceManag_OAUTH2: - CONSENT /api/consentmanager/v1/transactions/withdraw/purpose/{purposeId}: get: operationId: withdrawTransactionByPurposeAndIdentifierUsingGET summary: Withdraw Data Subject's Consent description: 'Use this API to withdraw a data subject''s consent for a specific Purpose. The data subject identifier must be included either in the `identifier` query or header parameter, preferably passed in the header. > 🗒 Things to Know > > - This API is not designed to be used in synchronous workflows. As an alternative, the Create Consent Receipts API can be called.' tags: - Transactions x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json parameters: - name: identifier in: query description: Data Subject Identifier (prefer the header parameter). required: false schema: type: string example: user@example.com deprecated: true - name: identifier in: header description: Data Subject Identifier (prefer the header parameter). required: false schema: type: string example: user@example.com - name: purposeId in: path description: Unique Identifier for Purpose. required: true schema: type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 responses: '200': description: OK - Successfully withdrew consent content: application/json: schema: $ref: '#/components/schemas/ConsentPreferences-UniversalConsentPreferenceManag_TransactionWithdrawResult' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error deprecated: true security: - ConsentPreferences-UniversalConsentPreferenceManag_OAUTH2: - CONSENT - CONSENT_READ components: schemas: ConsentPreferences-UniversalConsentPreferenceManag_TransactionWithdrawResult: type: object properties: Status: description: Message representing the consent withdrawal status type: string example: Consent withdrawn successfully ConsentPreferences-UniversalConsentPreferenceManag_WithdrawOnBehalfOfRequest: type: object properties: Notes: description: Additional notes to be recorded as part of withdrawal type: string example: Withdrawing consent as per data subject request PurposeId: description: Unique identifier of the purpose for which consent is being withdrawn type: string format: uuid example: f2229953-b4b5-4042-8cb9-b78038cc4c46 Origin: description: Source or origin of the withdrawal request (e.g., IMPORT, API, SDK, ONETRUST, PREFERENCE_CENTER) type: string example: API required: - PurposeId securitySchemes: ConsentPreferences-UniversalConsentPreferenceManag_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: CONSENT: Consent Scope gives the user access to read/write operations CONSENT_READ: Consent Read Scope gives the user read-only access ConsentAPI_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: CONSENT: Consent Scope gives the user access to read/write operations CONSENT_READ: Consent Read Scope gives the user read-only access DSPreferneceCache_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: CONSENT: Consent Scope gives the user access to read/write operations CONSENT_READ: Consent Read Scope gives the user read-only access x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false x-onetrust: spec-label: OpenAPI 3.1.0