# TrustArc > TrustArc is an enterprise privacy management platform (Walnut Creek, California) covering > consumer consent, data subject rights, privacy program governance and third-party > assurance. Its developer surface is real but enterprise-gated: credentials are issued by a > TrustArc account administrator, not self-service. One machine-readable contract is > published — the Guardian identity API, which includes a SCIM 2.0 provisioning surface. All > other APIs are documented in prose in the public help center. Generated by API Evangelist on 2026-08-27. This is a third-party profile, not a TrustArc publication. TrustArc serves no llms.txt of its own (https://trustarc.com/llms.txt → 404). ## APIs - [Guardian identity API](https://login.truste.com/v3/api-docs): OpenAPI 3.1.0, 205 paths, 276 operations, 158 schemas. Includes SCIM 2.0 Users/Groups plus account, client, permission-profile and SSO administration. The only TrustArc API with a published spec. - [SCIM 2.0 provisioning](https://trustarchelp.zendesk.com/hc/en-us/articles/45629008459155-User): `https://login.truste.com/external/api/v2/scim/` — Users, Groups, ServiceProviderConfig, Schemas, ResourceTypes. - [CCM External API v1](https://trustarchelp.zendesk.com/hc/en-us/articles/53517557106963-API-Reference): `/external/v1/websites`, `/external/v1/scans`, `/external/tracker/inventory/{cmId}`. - [CCM Reporting API](https://trustarchelp.zendesk.com/hc/en-us/articles/35645279167891-Overview): `https://api.trustarc.com/api/ccm-reporting/` — analytics, consent locations, GDPR reports (JSON and CSV). - [Individual Rights Manager external API](https://trustarchelp.zendesk.com/hc/en-us/articles/52354102146579-DROP-Process-to-IRM-API-Integration-Guide): `https://irm.trustarc.com/server/api/v1/external/` — forms, requests, labels, close, search, callbacks. - [Consent & Preference Manager external API](https://trustarchelp.zendesk.com/hc/en-us/articles/40520220419475-External-Consent-Controller): `https://cpm.trustarc.com/server/api/v1/external/` (EU: `https://cpm.trustarc.eu/...`) — consents, consent forms, data subjects, callbacks. - [Data Mapping Hub external-integration API](https://trustarchelp.zendesk.com/hc/en-us/articles/49882097212435-Retrieve-All-Business-Processes): `https://api.trustarc.com/api/hub/external-integration/` — business processes, IT systems, company affiliates, third parties, plus dated change-event feeds. - [Assessment Manager API](https://trustarchelp.zendesk.com/hc/en-us/articles/38618198125331-Understanding-the-API-Endpoint): `https://assess.truste.com/api/v1/` — create assessments (PIA/DPIA/TIA). - [Reporting data extract API](https://trustarchelp.zendesk.com/hc/en-us/articles/41667887953683-Check-for-Request-Status): `https://api.trustarc.com/api/reporting/data-extract` — queue, poll, reset. ## Authentication - [Authorization and Authentication](https://trustarchelp.zendesk.com/hc/en-us/articles/49881862843155-Authorization-and-Authentication): OAuth 2.0 client credentials. `POST https://api.trustarc.com/api/auth/oauth/token` or `POST https://login.truste.com/oauth/token`. Bearer JWT, ~6 hour lifetime. - [OpenID Connect discovery](https://login.truste.com/.well-known/openid-configuration) - [OAuth authorization server metadata](https://login.truste.com/.well-known/oauth-authorization-server) — supports authorization_code, client_credentials, refresh_token, token-exchange, PKCE S256, mTLS-bound tokens and DPoP. ## Docs - [TrustArc Help Center](https://trustarchelp.zendesk.com/hc/en-us) - [API Guides](https://trustarchelp.zendesk.com/hc/en-us/sections/36115648969363-API-Guides) - [CCM External API versioning and changelog](https://trustarchelp.zendesk.com/hc/en-us/articles/53518189041043-API-Versioning-Changelog) - [CCM External API FAQs and troubleshooting](https://trustarchelp.zendesk.com/hc/en-us/articles/53518128482707-FAQs-Troubleshooting) - [Mobile Consent SDK implementation guide](https://trustarchelp.zendesk.com/hc/en-us/articles/50542272652947-Mobile-Consent-SDK-Implementation-Guide) - [Status page](https://status.trustarc.com/) and [status API](https://status.trustarc.com/api/v2/summary.json) - [Trust Center](https://trust.trustarc.com/en-US/) ## SDKs and packages - [@trustarc/trustarc-segment-wrapper](https://www.npmjs.com/package/@trustarc/trustarc-segment-wrapper) — 1.1.2, 2026-01-16, Apache-2.0 - [@trustarc/react-cookie-consent-manager](https://www.npmjs.com/package/@trustarc/react-cookie-consent-manager) — 1.0.1, 2026-07-23, Apache-2.0 - Mobile Consent SDK for iOS, Android, React Native and Flutter — documented, distributed to customers, not on any public registry - [github.com/trustarc](https://github.com/trustarc) — Google Consent Mode templates, Segment wrapper, sample apps ## What TrustArc does not publish - No pricing page (https://trustarc.com/pricing/ → 404); enterprise contact-us only - No llms.txt, no /.well-known/security.txt, no /.well-known/api-catalog - No A2A agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host - No MCP server, hosted or local - No AsyncAPI document (webhooks and change-event feeds exist and are documented in prose) - No public vulnerability-disclosure or bug-bounty program - No idempotency key, no dry-run mode, no published rate-limit numbers or headers - No public Postman workspace (postman.com/trustarc renders a shell; workspace search returns zero) - No Swagger UI — /swagger-ui/index.html returns 403 on every host even though /v3/api-docs is open on login.truste.com