{
 "categories": [
  "enterprise",
  "devsecops"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-10-09",
   "fact": "homepage",
   "note": "The developer llms.txt describes the OneTrust Developer Portal for APIs and SDKs that integrate external systems with the OneTrust platform.",
   "source": "https://developer.onetrust.com/onetrust/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "license",
   "note": "API credentials are created inside a OneTrust application under Global Settings. The quick start uses a tenant hostname such as trial.onetrust.com.",
   "source": "https://developer.onetrust.com/onetrust/reference/quick-start-guide",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.api.exists",
   "note": "The quick start says OneTrust APIs are RESTful and support standard HTTP verbs over HTTPS.",
   "source": "https://developer.onetrust.com/onetrust/reference/quick-start-guide",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.api.kinds[0]",
   "note": "The same page says all API endpoints are RESTful.",
   "source": "https://developer.onetrust.com/onetrust/reference/quick-start-guide",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.api.auth[0]",
   "note": "OAuth 2.0 client credentials are created in Global Settings. The access token is sent as Authorization: Bearer, or generated with POST /v1/oauth/token.",
   "source": "https://developer.onetrust.com/onetrust/reference/quick-start-guide",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.api.auth[1]",
   "note": "OAuth 2.0 API keys are created on the API Keys tab. The key is the access token and may be sent as a Bearer header or as a query parameter.",
   "source": "https://developer.onetrust.com/onetrust/reference/quick-start-guide",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.api.coverage",
   "note": "The guide says each endpoint requires OAuth scopes and that reference pages are organized by Trust Management Platform clouds. A 429 means the rate limit was exceeded. This pass did not open every cloud.",
   "source": "https://developer.onetrust.com/onetrust/reference/quick-start-guide",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.api.docs",
   "note": "Opened the OneTrust API quick start.",
   "source": "https://developer.onetrust.com/onetrust/reference/quick-start-guide",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.mcp.first_party",
   "note": "OneTrust hosts https://developer.onetrust.com/mcp. The page says no authentication headers are required and describes developer-portal API help, documentation search, and code generation.",
   "source": "https://developer.onetrust.com/onetrust/reference/mcp",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.data_access.export[0]",
   "note": "The authorize example sets Content-Type: application/json. The guide also points to Swagger or OpenAPI files.",
   "source": "https://developer.onetrust.com/onetrust/reference/quick-start-guide",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "Opened a text/plain OneTrust developer index that links API, SDK, and changelog section indexes.",
   "source": "https://developer.onetrust.com/onetrust/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "verdict.scores.api",
   "note": "Client credentials and API keys authorize tenant REST calls. Scope and hostname setup remain per environment, and this pass did not inventory every cloud.",
   "source": "https://developer.onetrust.com/onetrust/reference/quick-start-guide",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "verdict.scores.mcp",
   "note": "The documented MCP server is a developer-portal helper for docs and code samples. It does not publish a list of tenant operations tools.",
   "source": "https://developer.onetrust.com/onetrust/reference/mcp",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "freshness.watch[0].url",
   "note": "Opened the OneTrust API quick start.",
   "source": "https://developer.onetrust.com/onetrust/reference/quick-start-guide",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "freshness.watch[1].url",
   "note": "Opened the OneTrust Developer Portal MCP page.",
   "source": "https://developer.onetrust.com/onetrust/reference/mcp",
   "tier": "declared"
  },
  {
   "date": "2026-10-09",
   "fact": "freshness.watch[2].url",
   "note": "Opened the OneTrust developer llms.txt index.",
   "source": "https://developer.onetrust.com/onetrust/llms.txt",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-10-09",
  "volatility": "medium",
  "watch": [
   {
    "type": "docs",
    "url": "https://developer.onetrust.com/onetrust/reference/quick-start-guide"
   },
   {
    "type": "docs",
    "url": "https://developer.onetrust.com/onetrust/reference/mcp"
   },
   {
    "type": "docs",
    "url": "https://developer.onetrust.com/onetrust/llms.txt"
   }
  ]
 },
 "homepage": "https://www.onetrust.com/",
 "id": "onetrust",
 "license": "commercial",
 "modalities": {
  "agent_docs": {
   "llms_txt": true
  },
  "api": {
   "auth": [
    "oauth2-client-credentials",
    "oauth2-api-key"
   ],
   "coverage": "partial",
   "docs": "https://developer.onetrust.com/onetrust/reference/quick-start-guide",
   "exists": true,
   "kinds": [
    "rest"
   ]
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "json"
   ],
   "import": []
  },
  "extensibility": {
   "scripting": [],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No UI probe was run. OneTrust documents tenant REST APIs and a separate developer-portal MCP for docs and code generation.\n",
   "ui_stack": [],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "OneTrust",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "drata",
   "vanta"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "OneTrust",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 7,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": 4,
   "overall": 7,
   "rpa": null
  },
  "summary": "OneTrust is automatable today through its REST APIs. This record is the OneTrust privacy, consent, and governance platform. It is not Drata or Vanta. The developer quick start says APIs are HTTPS and REST. Client credentials and API keys are created in Global Settings, Access Management, Client Credentials. Client-credentials tokens come from POST /v1/oauth/token or from the application. API keys are sent as Authorization: Bearer, and API keys may also be passed as a query parameter. Calls use the tenant hostname, such as trial.onetrust.com. The quick start lists 429 for rate limits and points at an OpenAPI download index. The remote MCP at https://developer.onetrust.com/mcp is a developer-portal server. The page says no authentication headers are required. Its examples are documentation search and code generation for inventories, DSAR export, and assessments. It does not list tenant admin tools. A supported CLI and connector catalogs were not opened. Computer-use viability is unassessed. The API scores 7 and is the best path. The MCP scores 4.\n"
 }
}