openapi: 3.2.0 info: title: Consent & Preferences - Universal Consent & Preference… version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 description: The Universal Consent & Preference Management APIs are used to integrate external systems and streamline the flow of data with Universal Consent & Preference Management in the OneTrust Platform. servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Transactions V2 description: APIs for managing consent transactions. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json x-displayName: Transactions V2 paths: /api/consent/v2/transactions: post: operationId: getTransactionsUsingPOST summary: Get List of Transactions description: 'Use this API to retrieve a list of all consent transactions. The response will include information about each transaction, the corresponding consent date, and details of the Purposes and the associated Purpose Preferences that the data subject has interacted with. > 🗒 Things to Know > > - The timespan for the `fromDate` and `toDate` values must be 24 hours or less. > - The `collectionPointAttributes` parameter will be returned as `null` when left blank during normal ingestion (API collection point, webform) and as `{} ` when left blank during bulk import.' tags: - Transactions V2 x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/consent-preferences-universal-consent-preference-management-oas.json parameters: - name: fromDate in: query description: 'Retrieve transactions recorded after the specified date. Formats accepted: YYYY-MM-DD or YYYY-MM-DDTHH:MM:SS' required: false schema: type: string format: date-time example: '2024-07-01T12:30:00' - name: toDate in: query description: 'Retrieve transactions recorded up to the specified date. Formats accepted: YYYY-MM-DD or YYYY-MM-DDTHH:MM:SS' required: false schema: type: string format: date-time example: '2025-07-02T10:15:40' - name: collectionPointGuid in: query description: UUID of the Collection Point required: false schema: type: string format: uuid example: f312dd9b-58b4-4f34-b5ff-10b9b464bc4f - name: page in: query description: Results page to be retrieved (0..N). schema: type: integer format: int32 default: 0 minimum: 0 example: 0 - name: size in: query description: Number of records per page (1..50). schema: type: integer format: int32 default: 20 maximum: 50 minimum: 1 example: 20 - name: sort in: query description: 'Sorting criteria in the format: property,direction (where direction is asc or desc). Supported properties: **consentCreationDate**.' schema: type: string example: consentCreationDate,desc default: consentCreationDate,desc enum: - consentCreationDate,asc - consentCreationDate,desc requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ConsentAPI_ContinuationToken' responses: '200': description: Successfully retrieved list of transactions content: application/json: schema: $ref: '#/components/schemas/ConsentAPI_TransactionSliceDto' '400': description: Bad Request '401': description: Unauthorized content: application/json: schema: type: string '403': description: Forbidden content: application/json: schema: type: string '404': description: Not Found content: application/json: schema: type: string '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - ConsentAPI_OAUTH2: - CONSENT - CONSENT_READ components: schemas: ConsentAPI_PurposeNoteDto: type: object properties: noteId: description: Unique identifier for the purpose note type: string format: uuid example: d1a8f6f2-781a-4b2b-b1db-07e25f1c9a94 noteType: description: Type of the note type: string enum: - UNSUBSCRIBE_REASON noteLanguage: description: Language of the purpose note type: string example: en-us noteText: description: The actual text of the note type: string example: 0e7ed8b7-a64d-4e38-a7ea-7c28dbdd5869 ConsentAPI_PreferenceDto: type: object properties: topicId: description: Unique Identifier identifying a Topic type: string format: uuid example: 8b2cbb9f-c567-4872-b063-139d0b64cb1c transactionType: description: Transaction type for the topic type: string example: OPT_IN ConsentAPI_TransactionDto: type: object properties: receiptId: description: The unique identifier identifying the Receipt type: string example: 51a3384e-46d5-43ec-8d88-d7a4b95c7e3e collectionPointUUID: description: Unique Identifier identifying a Collection Point type: string format: uuid example: eb27838a-1ce2-4438-9601-82d88ade6af1 identifier: description: Unique Identifier identifying a Data Subject type: string example: example@otprivacy.com consentCreationDate: description: The Date the Data Subject consented type: string format: date-time example: '2024-01-01T00:00:00.000' interactionDate: description: The date and time that the data subject data subject consent was interacted. type: string format: date-time example: '2022-10-01T00:00:00.000' collectionPointAttributes: type: object additionalProperties: type: array items: type: string transactionGuid: description: The unique identifier for the transaction. type: string format: uuid example: 2f726312-73b8-4d17-90d1-0c9bb1f09f0f guid: description: The unique identifier for purpose. type: string format: uuid example: 0e7ed8b7-a64d-4e38-a7ea-7c28dbdd5869 purposeGuid: description: The unique identifier for purpose. type: string format: uuid example: 0e7ed8b7-a64d-4e38-a7ea-7c28dbdd5869 purposeVersion: description: The version of the purpose. type: integer format: int64 example: 2 expiryDate: description: The Date by which the consent will expire. type: string format: date-time example: '2024-01-01T00:00:00.000' removeExpiry: description: Whether the purpose's expiry can be removed type: boolean example: true topics: description: The topics tied to the transaction. type: array items: $ref: '#/components/schemas/ConsentAPI_PreferenceDto' customPreferences: description: List of CustomPreferences for the purpose type: array items: $ref: '#/components/schemas/ConsentAPI_CustomPreferenceDto' transactionType: description: The transaction type. type: string enum: - PENDING - CONFIRMED - WITHDRAWN - EXPIRED - NOTGIVEN - OPT_OUT - NO_CHOICE - HARD_OPT_OUT - EXTEND - CHANGE_PREFERENCES - CANCEL - NO_OPT_OUT - OPT_IN - IMPLICIT attributes: description: The attributes attached to the purpose. type: object additionalProperties: type: array items: type: string purposeNote: description: The notes tied to the purpose example: 0e7ed8b7-a64d-4e38-a7ea-7c28dbdd5869 $ref: '#/components/schemas/ConsentAPI_PurposeNoteDto' autoGenerated: type: boolean purposeAttachments: description: The attachment guids tied to the purpose type: array items: $ref: '#/components/schemas/ConsentAPI_AttachmentDto' consentDate: description: The date and time when the consent was given by the data subject. type: string format: date-time example: '2025-01-15T00:00:00.000' issueDate: description: The date and time when the consent receipt was issued. type: string format: date-time example: '2025-01-15T10:46:05Z' withdrawalDate: description: The date and time when the consent was withdrawn, if applicable. type: string format: date-time example: '2025-03-02T14:22:10Z' activationDate: description: The date and time when the consent became active. type: string format: date-time example: '2025-01-15T11:00:00Z' createdBy: description: The guid of the user or system that created the consent record. type: string example: d72b29b1-5b0c-4c07-b09c-0e71f48bbdde withdrawnBy: description: The guid of the user or system that withdrew the consent, if applicable. type: string example: 51a3384e-46d5-43ec-8d88-d7a4b95c7e3e doubleOptIn: description: Indicates whether the consent requires Double Opt-In confirmation. type: boolean example: true test: description: Indicates whether the data subject is marked as a test record. type: boolean example: false purposePrivacyNotices: description: List of privacy notices associated with the purposes of this consent. type: array items: $ref: '#/components/schemas/ConsentAPI_PrivacyNoticeDto' collectionPointPrivacyNotices: description: List of privacy notices associated with the collection point where the consent was captured. type: array items: $ref: '#/components/schemas/ConsentAPI_PrivacyNoticeDto' purposeScopes: description: The specific scope of purposes for which the consent applies. type: array items: $ref: '#/components/schemas/ConsentAPI_PurposeScopeDto' ConsentAPI_AttachmentDto: type: object properties: id: description: The unique identifier of the uploaded attachment. type: string format: uuid example: 3f6b0b58-1c9e-4f65-92b6-8e5c0cb9a1d2 ConsentAPI_PurposeScopeDto: type: object properties: key: description: The key representing a specific scope of the purpose. type: string value: description: The description of the purpose scope. type: string ConsentAPI_PageableObjectWithContinuationToken: type: object properties: paged: type: boolean pageNumber: type: integer format: int32 offset: type: integer format: int64 pageSize: type: integer format: int32 unpaged: type: boolean sort: $ref: '#/components/schemas/ConsentAPI_SortObject' requestContinuation: description: The token used to paginate a response if the number of records is more than a page. type: string ConsentAPI_CustomPreferenceChoiceDto: type: object properties: optionId: description: The identifier of the selected option for this preference. type: string format: uuid example: 8f3c2a47-6b2d-4b9d-9d8b-1b5f3c8f1a23 transactionType: description: The type of transaction associated with this option. type: string example: OPT_IN ConsentAPI_SortObject: type: object properties: empty: type: boolean sorted: type: boolean unsorted: type: boolean ConsentAPI_PrivacyNoticeDto: type: object properties: id: description: The unique identifier of the privacy notice. type: string format: uuid example: a1b2c3d4-e5f6-7a89-b0c1-d2e3f4a5b6c7 version: description: The major version number of the privacy notice. type: integer format: int64 example: 3 minorVersion: description: The minor version number of the privacy notice. type: integer format: int64 example: 2 ConsentAPI_ContinuationToken: type: object properties: requestContinuation: description: Request continuation token used to paginate. If the number of records in the response is more than a page, it returns a `requestContinuation` token in the response. This `requestContinuation` token should be passed to the next request's body to paginate. type: string example: compositeToken: token: +RID:iNFkAI-ei-4uLDsAAAAAAA==#RT:2#SRC:1#TRC:40#RTD:0Idx9i7ua9Rq4VL3LfZOBTMxMzMuMjMuMjpVMjY7NTo7MjIvMzE5Nzo1AA==#ISV:2#IEO:65567#QCF:8#FPC:AgHq7OoGADE1APzASusCAABA7GoAIVt//sFH5/+hQP9/EUD/f/JAn8/9/xFAv/9DQP/7v//f/yJA//f/+2FC//sxQf9/IUD/O1FA/38RQP7/IUD7/5VA/7/t/93u93+2/xFA/58hQH/6MUB/+xhAv2//99v//f+//ev//+EfAA== range: min: '' max: FF orderByItems: - item: '2022-12-19T15:49:11.236953' rid: iNFkAI-ei-4FKjsAAAAAAA== inclusive: true nextMarker: description: Request continuation token used to paginate over historical receipts type: string example: TGp8AqS3Gfnzwc5srJKeaA== ConsentAPI_TransactionSliceDto: type: object properties: content: items: $ref: '#/components/schemas/ConsentAPI_TransactionDto' type: array pageable: $ref: '#/components/schemas/ConsentAPI_PageableObjectWithContinuationToken' first: type: boolean last: description: Flag indicating whether this is the last page or not. type: boolean example: false number: description: The page number of the results. type: integer format: int32 example: 1 sort: $ref: '#/components/schemas/ConsentAPI_SortObject' size: description: The number of results per page. type: integer format: int32 example: 20 numberOfElements: type: integer format: int32 empty: type: boolean ConsentAPI_CustomPreferenceDto: type: object properties: id: description: The unique identifier of the custom preference. type: string format: uuid example: 3f6b0b58-1c9e-4f65-92b6-8e5c0cb9a1d2 options: description: List of options linked to this preference. type: array items: type: string format: uuid example: - 8f3c2a47-6b2d-4b9d-9d8b-1b5f3c8f1a23 - f1d24c56-9873-4c43-84af-2c94a7f9b11d choices: description: List of choices made for this custom preference. type: array items: $ref: '#/components/schemas/ConsentAPI_CustomPreferenceChoiceDto' securitySchemes: ConsentPreferences-UniversalConsentPreferenceManag_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: CONSENT: Consent Scope gives the user access to read/write operations CONSENT_READ: Consent Read Scope gives the user read-only access ConsentAPI_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: CONSENT: Consent Scope gives the user access to read/write operations CONSENT_READ: Consent Read Scope gives the user read-only access DSPreferneceCache_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: CONSENT: Consent Scope gives the user access to read/write operations CONSENT_READ: Consent Read Scope gives the user read-only access x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false x-onetrust: spec-label: OpenAPI 3.1.0