openapi: 3.2.0 info: title: Onetrust Users V2 API version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 description: 'Operations tagged Users V2 across 2 of this provider''s published API definitions: onetrust-platform-access-management-openapi.json, onetrust-platform-user-provisioning-openapi.json. Each path carries the servers of the definition it was published in.' servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Users V2 description: APIs to manage users and their memberships and access levels. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/platform-access-management.json x-displayName: Users V2 paths: /api/access/v2/users: get: operationId: getAllUserDetailsV2 summary: Get List of Users description: Use this API to retrieve a list of all users in your account. tags: - Users V2 x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/platform-access-management.json parameters: - name: page in: query description: The page number for the results to be retrieved. schema: type: integer format: int32 default: 0 minimum: 0 example: 1 - name: size in: query description: The number of records to be retrieved per page. schema: type: integer format: int32 default: 20 maximum: 2000 minimum: 1 example: 20 - name: sort in: query description: 'The sorting criteria in the format: `property,(asc|desc)`. The default sort order is ascending. Multiple sort criteria are supported.' schema: type: string default: name,asc enum: - name,asc - name,desc - email,asc - email,desc - organizationname,asc - organizationname,desc example: name,asc responses: '200': description: User details retrieved successfully content: application/json: schema: $ref: '#/components/schemas/Platform-AccessManagement_PagePublicOrgUserDetailsResponse' '400': description: Bad Request '401': description: Unauthorized - Invalid or missing authentication '403': description: Forbidden - Insufficient permissions '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - Platform-AccessManagement_OAUTH2: - USER post: operationId: createUserV2 summary: Create User description: Use this API to create a new user in your account. tags: - Users V2 x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/platform-access-management.json requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/Platform-AccessManagement_PublicOrgUserCreateRequest' responses: '201': description: User created successfully content: application/json: schema: description: Identifier of the newly created user type: string '400': description: Invalid request data '401': description: Unauthorized - Invalid or missing authentication '403': description: Forbidden - Insufficient permissions '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - Platform-AccessManagement_OAUTH2: - USER servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. /api/access/v2/users/{userId}: get: operationId: getUserV2 summary: Get User description: Use this API to retrieve details for a single user in your account. tags: - Users V2 x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/platform-access-management.json parameters: - name: userId in: path description: The unique identifier of the user. required: true schema: type: string format: uuid example: c01233a5-482c-4274-8f88-15e24c1c96a4 responses: '200': description: User retrieved successfully content: application/json: schema: $ref: '#/components/schemas/Platform-AccessManagement_PublicOrgUserDetailsResponse' '400': description: Bad Request '401': description: Unauthorized - Invalid or missing authentication '403': description: Forbidden - Insufficient permissions '404': description: User not found '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - Platform-AccessManagement_OAUTH2: - USER put: operationId: updateUserV2 summary: Update User description: Use this API to update the details for a single user in your account. tags: - Users V2 x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/platform-access-management.json parameters: - name: userId in: path description: The unique identifier of the user. required: true schema: type: string format: uuid example: c01233a5-482c-4274-8f88-15e24c1c96a4 requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/Platform-AccessManagement_PublicOrgUserUpdateRequest' responses: '200': description: User updated successfully '400': description: Invalid request data '401': description: Unauthorized - Invalid or missing authentication '403': description: Forbidden - Insufficient permissions '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - Platform-AccessManagement_OAUTH2: - USER servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. /api/access/v2/users/{userId}/access-levels: get: operationId: getUserAccessLevelsV2 summary: Get User Roles description: Use this API to retrieve a list of roles assigned to a specific user. tags: - Users V2 x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/platform-access-management.json parameters: - name: userId in: path description: The unique identifier of the user. required: true schema: type: string format: uuid example: c01233a5-482c-4274-8f88-15e24c1c96a4 responses: '200': description: User access levels retrieved successfully content: application/json: schema: type: array items: $ref: '#/components/schemas/Platform-AccessManagement_PublicAccessLevelResponse' '400': description: Bad Request '401': description: Unauthorized - Invalid or missing authentication '403': description: Forbidden - Insufficient permissions '404': description: User not found '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - Platform-AccessManagement_OAUTH2: - USER post: operationId: addUserAccessLevelV2 summary: Add User Role description: Use this API to add a new role to a specific user. tags: - Users V2 x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/platform-access-management.json parameters: - name: userId in: path description: The unique identifier of the user. required: true schema: type: string format: uuid example: c01233a5-482c-4274-8f88-15e24c1c96a4 requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/Platform-AccessManagement_PublicAccessLevelRequest' responses: '201': description: Access level added successfully '400': description: Invalid request data - malformed UUID, invalid request body, attempting to add INVITED role, or user already has access level in the specified organization '401': description: Unauthorized - Invalid or missing authentication '403': description: Forbidden - Insufficient permissions '404': description: Organization or role not found '409': description: Conflict - User does not exist '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - Platform-AccessManagement_OAUTH2: - USER delete: operationId: removeUserAccessLevelV2 summary: Remove User Role description: Use this API to remove a specific role from a user. tags: - Users V2 x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/platform-access-management.json parameters: - name: userId in: path description: The unique identifier of the user. required: true schema: type: string format: uuid example: c01233a5-482c-4274-8f88-15e24c1c96a4 requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/Platform-AccessManagement_PublicAccessLevelRequest' responses: '204': description: Access level removed successfully '400': description: Invalid request data - malformed UUID, invalid request body, removal would leave user with no roles in default organization, or removal would leave no site admins in root organization '401': description: Unauthorized - Invalid or missing authentication '403': description: Forbidden - Insufficient permissions '404': description: Organization, role or access level not found '409': description: Conflict - User does not exist '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - Platform-AccessManagement_OAUTH2: - USER servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. /api/access/v2/users/{userId}/default-organization: patch: operationId: setUserDefaultOrganizationV2 summary: Modify User Default Organization description: Use this API to modify the default organization for a specific user. The user must have at least one role in the specified organization. tags: - Users V2 x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/platform-access-management.json parameters: - name: userId in: path description: The unique identifier of the user. required: true schema: type: string format: uuid example: c01233a5-482c-4274-8f88-15e24c1c96a4 - name: organizationId in: query description: The unique identifier of the organization to set as default. required: true schema: type: string format: uuid example: d01233a5-482c-4274-8f88-15e24c1c96a5 responses: '204': description: Default organization updated successfully '400': description: Invalid request – User does not have access to the specified organization '401': description: Unauthorized - Invalid or missing authentication '403': description: Forbidden - Insufficient permissions '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - Platform-AccessManagement_OAUTH2: - USER servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. /api/scim/v2/Users: get: operationId: getAllUsersUsingGET summary: Get List of Users description: 'Use this API to retrieve a list of users along with user details such as the created date, last modified date, name, and email. This API should only be used when provisioning and managing users from your Identity Provider using the System for Cross-Domain Identity Management (SCIM) standard to facilitate the automated creation of user identities from a third-party identity management application. > 🗒 Things to Know > > - This API supports OneTrust''s Legacy SCIM Integration that leverages SCIM groups, which are unique role-organization combinations that each represent a specific role within a particular organization. For more information, see Legacy SCIM User Provisioning. > - OneTrust supports the use of SCIM filters to identify specific users: > - Filters can be applied on the `id`, `externalId`, `email`, `emails`, `givenName`, `familyName`, `userType`, and `active` attributes. > - The supported logical operators are `eq` (equal), `co` (contains), `sw` (starts with), `gt` (greater than), `ge` (greater than or equal to), `lt` (less than), and `le` (less than or equal to). > - The `filter` query parameter is applied in the following format: attribute operator "value". For example, emails co "onetrust.com" would return a list of user records that contain emails with the onetrust.com domain.' tags: - Users V2 x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/platform-user-provisioning.json parameters: - name: startIndex in: query description: Start index of the users to be retrieved. schema: type: string default: '1' minimum: 1 - name: count in: query description: 'The number of users to be returned. ' schema: type: string default: '25' minimum: 1 responses: '200': description: 'OK Users retrieved successfully. ' content: application/json: schema: $ref: '#/components/schemas/ListResponse' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - OAUTH2: - SCIM - INTEGRATION - USER post: operationId: createUserUsingPOST summary: Create User description: 'Use this API to create a user and associate that user with the configured organization and role. This API should only be used when provisioning and managing users from your Identity Provider using the System for Cross-Domain Identity Management (SCIM) standard to facilitate the automated creation of user identities from a third-party identity management application. > 🗒 Things to Know > > - This API supports OneTrust''s Legacy SCIM Integration that leverages SCIM groups, which are unique role-organization combinations that each represent a specific role within a particular organization. For more information, see Legacy SCIM User Provisioning. > - If a value is not provided for `roles` or `organization` in the request, the newly created user will be assigned the default role and organization as configured on the **User Provisioning** screen within **Global Settings** in the OneTrust application. > - This API supports assigning the user to multiple roles within one organization. If the user should be assigned to other role-organization combinations (SCIM groups), use the Modify Group Members API.' tags: - Users V2 x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/platform-user-provisioning.json requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UserResource' responses: '201': description: Created content: application/json: schema: $ref: '#/components/schemas/UserResource' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - OAUTH2: - SCIM - INTEGRATION - USER servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. /api/scim/v2/Users/{id}: get: operationId: getUserUsingGET summary: Get User description: 'Use this API to retrieve the details of a specific user. The response will include details such as the created date, emails, and SCIM groups to which the user belongs. This API should only be used when provisioning and managing users from your Identity Provider using the System for Cross-Domain Identity Management (SCIM) standard to facilitate the automated creation of user identities from a third-party identity management application. > 🗒 Things to Know > > - This API supports OneTrust''s Legacy SCIM Integration that leverages SCIM groups, which are unique role-organization combinations that each represent a specific role within a particular organization. For more information, see Legacy SCIM User Provisioning.' tags: - Users V2 x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/platform-user-provisioning.json parameters: - name: id in: path description: Unique identifier of the user required: true schema: type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 responses: '200': description: 'OK User retrieved successfully. ' content: application/json: schema: $ref: '#/components/schemas/UserResource' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - OAUTH2: - SCIM - INTEGRATION - USER put: operationId: updateUserUsingPUT summary: Update User description: 'Use this API to fully update all attributes for a user. This API should only be used when provisioning and managing users from your Identity Provider using the System for Cross-Domain Identity Management (SCIM) standard to facilitate the automated creation of user identities from a third-party identity management application. > 🗒 Things to Know > > - This API supports OneTrust''s Legacy SCIM Integration that leverages SCIM groups, which are unique role-organization combinations that each represent a specific role within a particular organization. For more information, see Legacy SCIM User Provisioning. > - The following user attributes will be updated using this API: `givenName`, `familyName`, `externalId`, `active`, `division`, `userType`, `employeeNumber`, `department`, `manager`, and `title`. > - Any attributes not included in the request will be replaced with a `null` value. It is best to first retrieve the latest user record using the Get User API, and then modify that response to use in the request for this API. If you only need to update some but not all attributes, use the Modify User API.' tags: - Users V2 x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/platform-user-provisioning.json parameters: - name: id in: path description: Unique identifier of the user required: true schema: type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UserResource' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/UserResource' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - OAUTH2: - SCIM - INTEGRATION - USER delete: operationId: deleteUserUsingDELETE summary: Delete User description: The Delete User feature is not available at this time. tags: - Users V2 x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/platform-user-provisioning.json parameters: - name: id in: path description: ID that uniquely identifies a user. The `id` can be obtained using the [Get List of Users](/onetrust/reference/getallusersusingget) API. required: true schema: type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 responses: '204': description: No Content '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - OAUTH2: - SCIM - INTEGRATION - USER patch: operationId: patchUserUsingPATCH summary: Modify User description: 'Use this API to activate a user, deactivate a user, or partially update a user''s attributes. This API should only be used when provisioning and managing users from your Identity Provider using the System for Cross-Domain Identity Management (SCIM) standard to facilitate the automated creation of user identities from a third-party identity management application. > 🗒 Things to Know > > - This API supports OneTrust''s Legacy SCIM Integration that leverages SCIM groups, which are unique role-organization combinations that each represent a specific role within a particular organization. For more information, see Legacy SCIM User Provisioning. > - The following user attributes can be modified using this API: `givenName`, `familyName`, `externalId`, `active`, `division`, `userType`, `employeeNumber`, `department`, `manager`, and `title`.' tags: - Users V2 x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/platform-user-provisioning.json parameters: - name: id in: path description: Unique identifier of the user required: true schema: type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PatchUserResourceRequest' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/UserResource' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - OAUTH2: - SCIM - INTEGRATION - USER servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. components: schemas: Platform-AccessManagement_PagePublicOrgUserDetailsResponse: type: object properties: content: description: The list of users on the current page. items: $ref: '#/components/schemas/Platform-AccessManagement_PublicOrgUserDetailsResponse' type: array empty: description: The flag to check if the result list is empty. type: boolean first: description: The flag to check if this is the first page. type: boolean last: description: The flag to check if this is the last page. type: boolean number: description: The current page number (0-based). type: integer format: int32 numberOfElements: description: The number of elements on the current page. type: integer format: int32 example: 1 size: description: The page size. type: integer format: int32 example: 20 totalElements: description: The total number of elements across all pages. type: integer format: int64 example: 1 totalPages: description: The total number of pages. type: integer format: int32 example: 1 sort: $ref: '#/components/schemas/Platform-AccessManagement_SortObject' pageable: description: 'Pagination information with page number (0-based, min: 0) and page size (min: 1)' type: object example: offset: 0 pageNumber: 0 pageSize: 20 paged: true sort: - ascending: true descending: false direction: ASC ignoreCase: false nullHandling: NATIVE property: name unpaged: false Platform-AccessManagement_SortObject: type: object properties: empty: description: Indicates whether the result set is empty, meaning no records were found. type: boolean sorted: description: Indicates whether the results are sorted in a specific order, such as ascending or descending. type: boolean unsorted: description: The indicator of whether the results are unsorted. type: boolean Platform-AccessManagement_PublicOrgUserUpdateRequest: type: object properties: firstName: description: The first name of the user. type: string example: Michael maxLength: 100 minLength: 0 lastName: description: The last name of the user. type: string example: Douglas maxLength: 100 minLength: 0 internal: description: The indicator of whether the user is an internal user. type: boolean example: true default: 'false' expirationDateTime: description: User expiration date in the system type: string format: date-time example: '2029-05-01T12:34:56Z' externalId: description: The external identifier for the user. type: string example: 1A2234-abc maxLength: 128 minLength: 0 accessLevels: type: array items: $ref: '#/components/schemas/Platform-AccessManagement_PublicAccessLevelCreateRequest' minItems: 1 uniqueItems: true required: - firstName - lastName Platform-AccessManagement_PublicAccessLevelRequest: type: object properties: organizationId: description: The unique identifier of the organization. type: string format: uuid example: 323e4567-e89b-12d3-a456-426614174000 roleId: description: The unique identifier of the role. type: string format: uuid example: 223e4567-e89b-12d3-a456-426614174000 required: - organizationId - roleId Platform-AccessManagement_PublicAccessLevelResponse: type: object properties: organizationId: description: The unique identifier of the organization. type: string format: uuid example: 423e4567-e89b-12d3-a456-426614174000 organizationName: description: The name of the organization. type: string example: My Org maxLength: 100 minLength: 1 roleId: description: The unique identifier of the role. type: string format: uuid example: 423e4567-e89b-12d3-a456-426614174001 roleName: description: The name of the role. type: string example: Audit Manager maxLength: 256 minLength: 1 Platform-AccessManagement_PublicAccessLevelCreateRequest: type: object properties: organizationId: description: The unique identifier of the organization. type: string format: uuid example: 323e4567-e89b-12d3-a456-426614174000 roleIds: description: The list of role identifiers to be associated with the organization. type: array items: type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 minItems: 1 minItems: 1 uniqueItems: true defaultOrganization: description: The indicator of whether the provided organization will be treated as the default organization. type: boolean example: true default: 'false' required: - organizationId Platform-AccessManagement_PublicOrgUserCreateRequest: type: object properties: firstName: description: The first name of the user. type: string example: Michael maxLength: 100 minLength: 0 lastName: description: The last name of the user. type: string example: Douglas maxLength: 100 minLength: 0 email: description: The email address of the user. type: string format: email example: abc@abc.com maxLength: 100 minLength: 0 internal: description: Indicates whether the user is an internal user. type: boolean example: true default: 'false' expirationDateTime: description: The expiration date for the user in the system. type: string format: date-time example: '2029-05-01T12:34:56Z' externalId: description: The external identifier for the user. type: string example: 1A2234-abc maxLength: 128 minLength: 0 accessLevels: type: array items: $ref: '#/components/schemas/Platform-AccessManagement_PublicAccessLevelCreateRequest' minItems: 1 uniqueItems: true suppressNotification: description: The indicator to suppress notifying the user on creation. type: boolean example: true default: 'false' required: - email - firstName - lastName Platform-AccessManagement_PublicOrgUserDetailsResponse: type: object properties: userId: description: The unique identifier of the user. type: string format: uuid example: 423e4567-e89b-12d3-a456-426614174000 firstName: description: The first name of the user, as it appears in their profile. type: string example: Ross maxLength: 100 lastName: description: The last name of the user, as it appears in their profile. type: string example: Taylor maxLength: 100 fullName: description: The full name of the user, combining their first and last names. type: string example: Ross Taylor maxLength: 256 email: description: The email address associated with the user's account. type: string format: email example: jane.doe@example.com maxLength: 255 minLength: 5 accessLevels: description: The access levels assigned to the user. type: array items: $ref: '#/components/schemas/Platform-AccessManagement_PublicAccessLevelResponse' uniqueItems: true emailConfirmed: description: The indicator of whether the user's email address has been confirmed. type: boolean example: true active: description: The indicator of whether the user account is currently active. type: boolean example: true internal: description: The indicator of whether the user is an internal user, meaning they are part of the organization. type: boolean example: false externalId: description: The external identifier for the user, which may be used to reference them in external systems. type: string example: ext-123456 maxLength: 128 expirationDateTime: description: The date and time the user account will expire. type: string format: date-time example: '2025-01-01T12:00:00Z' disabledDateTime: description: The date and time the user account was disabled. type: string format: date-time example: '2024-06-15T08:30:00Z' createdDate: description: The date and time the user account was created. type: string format: date-time example: '2023-10-01T09:15:00Z' lastModifiedDate: description: The date and time the user account was last modified. type: string format: date-time example: '2024-02-20T14:45:00Z' lastLoginDate: description: The date and time the user last logged in. type: string format: date-time example: '2024-09-10T07:05:00Z' disabledBy: description: The name of the user who disabled the current user. type: string example: Michael Douglas maxLength: 256 defaultOrganizationName: description: The name of the default organization for the user. type: string example: My Org maxLength: 100 defaultOrganizationId: description: The unique identifier of the user's default organization. type: string format: uuid example: 423e4567-e89b-12d3-a456-426614174111 Member: type: object properties: value: description: The unique ID of the user that you want to add to the Group. type: string format: uuid example: 3da9fe38-7845-4658-a96e-00071fa20c2e type: description: The type of the resource. type: string default: User enum: - User $ref: description: A hyperlink to the resource type: string format: url example: /api/scim/v3/Users/1bd418b2-85dd-4f04-955f-e4870e119ef1" readOnly: true required: - value title: Member Name: type: object properties: familyName: description: Family name (last name) of the user. type: string example: Smith maxLength: 100 minLength: 1 givenName: description: Given name (first name) of the user. type: string example: John maxLength: 100 minLength: 1 title: Name ResourceTypeResource: type: object properties: id: description: Unique identifier of the resource type type: string format: uuid example: 550e8400-e29b-41d4-a716-446655440000 name: description: Name of the resource type type: string example: Users enum: - Users - Groups endpoint: description: Resource URL endpoint type: string example: /Users description: description: Description of the resource type type: string example: A user account in the OneTrust system maxLength: 255 minLength: 1 schema: description: Schema URI for the resource type type: string example: urn:ietf:params:scim:schemas:core:2.0:User enum: - urn:ietf:params:scim:schemas:core:2.0:User - urn:ietf:params:scim:schemas:core:2.0:Group meta: $ref: '#/components/schemas/Meta' readOnly: true schemaExtensions: $ref: '#/components/schemas/SchemaExtension' required: - description - endpoint - id - name - schema GroupResource: type: object properties: id: description: Unique identifier for the user created by the OneTrust application. type: string format: uuid example: aeb3d45d-0c05-4ff0-b635-6e3c3b2f86ea maxLength: 100 readOnly: true externalId: description: External Id type: string example: 3PNdoRZES0GLfV+9y1dDwQ== maxLength: 100 meta: $ref: '#/components/schemas/Meta' readOnly: true schemas: type: array items: type: string default: urn:ietf:params:scim:schemas:core:2.0:Group description: A collection of attribute definitions that describe the contents of an entire or partial resource. enum: - urn:ietf:params:scim:schemas:core:2.0:Group - urn:ietf:params:scim:schemas:onetrust:Group example: urn:ietf:params:scim:schemas:core:2.0:Group uniqueItems: true displayName: description: Assessments Manager - ADFS type: string example: Test Group maxLength: 255 minLength: 1 members: type: array items: $ref: '#/components/schemas/Member' urn:ietf:params:scim:schemas:onetrust:Group: $ref: '#/components/schemas/OneTrustGroup' required: - displayName title: GroupResource Email: type: object properties: value: description: Email of the user. type: string format: email example: gpburdell@onetrust.com minLength: 1 display: description: Email of the user. type: string format: email example: gpburdell@onetrust.com readOnly: true primary: description: Is the email the user's primary. Always `true` in the OneTrust application. type: boolean example: true default: 'true' readOnly: true $ref: description: Reference for the attribute type: string format: string type: description: The type of the email. In the OneTrust application, type is always 'work'. type: string example: work default: work required: - value Supported: type: object properties: supported: description: Indicates whether the service provider supports the operation type: boolean example: false SchemaExtension: type: object properties: schema: description: The schema extension schema type: string example: urn:ietf:params:scim:schemas:onetrust:Group required: description: True if the schema extension is required type: boolean example: true required: - required - schema AuthenticationScheme: type: object properties: name: description: Name of the authentication scheme type: string example: Oauth2 Bearer description: description: Description of the authentication scheme type: string example: OAuth2 Bearer access token is used for authorization. specUrl: description: URI of the specification for the authentication scheme type: string example: http://tools.ietf.org/html/rfc6749 documentationUrl: description: URI to retrieve more information about the authentication scheme type: string example: http://oauth.net/2/ type: description: Type of the authentication scheme type: string example: oauthbearertoken primary: description: Indicates whether the authentication scheme is primary type: boolean example: true ServiceProviderConfig: type: object properties: schemas: description: A collection of resource types supported by the service provider type: array items: type: string description: A collection of resource types supported by the service provider example: '["urn:ietf:params:scim:schemas:core:2.0:ServiceProviderConfig"]' example: - urn:ietf:params:scim:schemas:core:2.0:ServiceProviderConfig uniqueItems: true patch: $ref: '#/components/schemas/Supported' bulk: $ref: '#/components/schemas/BulkSupported' filter: $ref: '#/components/schemas/FilterSupported' changePassword: $ref: '#/components/schemas/Supported' sort: $ref: '#/components/schemas/Supported' etag: $ref: '#/components/schemas/Supported' xmlDataFormat: $ref: '#/components/schemas/Supported' authenticationSchemes: type: array items: $ref: '#/components/schemas/AuthenticationScheme' meta: $ref: '#/components/schemas/Meta' readOnly: true title: ServiceProviderConfig PatchUserResourceRequest: type: object properties: id: description: Unique identifier for the user created by the OneTrust application. type: string format: uuid example: aeb3d45d-0c05-4ff0-b635-6e3c3b2f86ea maxLength: 100 readOnly: true externalId: description: External Id type: string example: 3PNdoRZES0GLfV+9y1dDwQ== maxLength: 100 meta: $ref: '#/components/schemas/Meta' readOnly: true schemas: type: array items: description: A collection of attribute definitions that describe the contents of an entire or partial resource. enum: - urn:ietf:params:scim:schemas:core:2.0:User example: urn:ietf:params:scim:schemas:core:2.0:User uniqueItems: true Operations: type: array items: $ref: '#/components/schemas/UserPatchApiOperation' FilterSupported: type: object properties: supported: description: Indicates whether the service provider supports the operation type: boolean example: false maxResults: type: integer format: int32 ListResponse: type: object properties: schemas: type: array items: type: string description: List of Schemas. example: urn:ietf:params:scim:schemas:core:2.0:User uniqueItems: true totalResults: description: The total number of results in the list. type: integer format: int32 example: 2 minimum: 0 startIndex: description: TThe starting point of the result list. type: integer format: int32 example: 1 minimum: 1 itemsPerPage: description: The number of items per results page. type: integer format: int32 example: 25 minimum: 0 Resources: type: array items: type: object anyOf: - $ref: '#/components/schemas/GroupResource' - $ref: '#/components/schemas/UserResource' - $ref: '#/components/schemas/ResourceTypeResource' - $ref: '#/components/schemas/ServiceProviderConfig' description: Resources. UserGroup: type: object properties: value: description: Unique identifier of a group in the application. type: string example: 5175be33-9b8d-4483-9d8b-1a9fb78bd97d display: description: Name of the User Group in the application. type: string example: R&D readOnly: true title: Group OneTrustGroup: type: object properties: category: description: The display name of the group type: string example: HR maxLength: 255 minLength: 1 description: description: The description of the group type: string example: HR User Group maxLength: 255 minLength: 1 title: UserGroup UserResource: type: object allOf: - $ref: '#/components/schemas/AbstractBaseResource' - type: object properties: schemas: type: array items: description: A collection of attribute definitions that describe the contents of an entire or partial resource. enum: - urn:ietf:params:scim:schemas:core:2.0:User example: urn:ietf:params:scim:schemas:core:2.0:User uniqueItems: true userName: description: Username of the user in the OneTrust application. type: string format: email example: gpburdell@onetrust.com maxLength: 256 name: $ref: '#/components/schemas/Name' userType: description: Type of the user. type: string example: Internal enum: - Internal - External active: description: The flag to check whether the user is an active or an inactive user. type: boolean example: true groups: type: array items: $ref: '#/components/schemas/UserGroup' readOnly: true readOnly: true emails: type: array items: $ref: '#/components/schemas/Email' roles: type: array items: format: json description: Role of the user within the OneTrust application. examples: - '["Auditor","Business Owner","Employee","Privacy Officer","Site Admin"]' title: description: Job title of the user type: string example: Product Manager maxLength: 255 urn:ietf:params:scim:schemas:extension:enterprise:2.0:User: description: Enterprise user details $ref: '#/components/schemas/EnterpriseUser' required: - name title: UserResource Meta: type: object properties: created: description: The date and time when the resource was created type: string format: date-time example: '2022-05-27T15:28:14.298Z' lastModified: description: The date and time when the resource was last modified type: string format: date-time example: '2022-05-27T15:28:14.298Z' location: description: The URL for the resource type: string format: uri example: /api/scim/v3/Users/53b1325c-081f-4f05-b41b-ba8cbdb7bae9 maxLength: 2083 minLength: 1 version: description: The version of the resource type: string example: W/"f0f2a936" maxLength: 100 minLength: 1 attributes: type: array items: description: The set of attributes example: - active - emails - userName uniqueItems: true resourceType: description: The resource type type: string example: Group enum: - User - Group - ResourceType - ServiceProviderConfig - Schema maxLength: 100 minLength: 1 readOnly: true title: Meta EnterpriseUser: type: object properties: businessUnit: description: User's business unit. type: string example: ESG maxLength: 255 division: description: The division with which the user is associated. type: string example: North America maxLength: 255 employeeNumber: description: User's employee number or ID. type: string example: '8675309' maxLength: 255 officeLocation: description: The office location of the user. type: string example: New York maxLength: 255 department: description: The department with which the user is associated. type: string example: R&D maxLength: 255 manager: $ref: '#/components/schemas/Manager' organization: description: Organization of the user within the OneTrust application. type: string example: OneTrust maxLength: 255 legacyManager: description: The legacy manager of the user. type: string example: legacy manager maxLength: 255 title: Additional Attributes UserPatchApiOperation: type: object properties: op: description: Operation to be performed. `add` will add new attributes, `replace` will update current attributes, and `remove` deletes attributes. type: string example: replace enum: - add - remove - replace path: description: Path of operation. If using `path` then only send the `value` as a string not an array. For example, for the `path` of `name.familyName`, send the `value` as `\"Burdell\"`. type: string example: members value: description: User attributes to be updated. This is a map of attribute names to their values. type: object additionalProperties: type: string allOf: - $ref: '#/components/schemas/AbstractBaseResource' - $ref: '#/components/schemas/EnterpriseUser' required: - op - value Manager: type: object properties: value: description: The manager's GUID or `id` in the OneTrust application. Leverage the [Get List of Users](/onetrust/reference/getusers) API to obtain a list of users. Use the manager's `id` to populate `value`. type: string example: 23498234-9283-4620-8204-652982504620 maxLength: 100 minLength: 1 displayName: description: Manager's full name in the application. type: string example: John Doe readOnly: true $ref: description: Reference URL to the user type: string format: url example: /api/scim/v3/Users/23498234-9283-4620-8204-652982504620 readOnly: true required: - value title: Manager BulkSupported: type: object properties: supported: description: Indicates whether the service provider supports the operation type: boolean example: false maxOperations: type: integer format: int32 maxPayloadSize: type: integer format: int32 AbstractBaseResource: type: object properties: id: description: Unique identifier for the user created by the OneTrust application. type: string format: uuid example: aeb3d45d-0c05-4ff0-b635-6e3c3b2f86ea maxLength: 100 readOnly: true externalId: description: External Id type: string example: 3PNdoRZES0GLfV+9y1dDwQ== maxLength: 100 meta: $ref: '#/components/schemas/Meta' readOnly: true schemas: type: array items: type: string uniqueItems: true writeOnly: true title: AbstractBaseResource securitySchemes: Platform-AccessManagement_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: ORGANIZATION: Grants full access to manage organizations. This includes Create, Read, Update and Delete operations. USER: Grants full access to manage Users, User Groups and User Group membership. This includes Create, Read, Update and Delete operations. AuditRecords_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: USER: Grants full access to manage Users, User Groups and User Group membership. This includes Create, Read, Update and Delete operations. OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: SCIM: Grants full access to the SCIM APIs for User Provisioning. This includes all the endpoints under Users, Groups, Resources, Schemas and Service Provider. x-refined-from: - onetrust-platform-access-management-openapi.json - onetrust-platform-user-provisioning-openapi.json x-onetrust: spec-label: OpenAPI 3.1.0 x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false