# OneTrust — API Agent Score

> Score: 73/100 (Grade: B) | Domain: onetrust.com | Rubric: 1.0.0 | Checked: July 29, 2026

OneTrust scored 73/100 (B), classified "partially-ready".

[View full report](https://www.postman.com/ai/ai-ready-apis/company/onetrust)
[All organizations](https://www.postman.com/ai/ai-ready-apis/llms.txt)

## Summary

- Overall: 73/100 (B)
- Classification: partially-ready

## Category Scores

- API Design: 88/100 (A)
- Developer Experience: 58/100 (D)
- Agent Discovery: 100/100 (A+)
- Agent Understanding: 82/100 (A)
- Agent Usability: 47/100 (F)

## Check Results

### API Design

- [pass] Schema coverage & depth — 1/1 enums are named types (not bare strings). Investigated: sdk 100%, spec 63%.
- [warn] Auth declared & discoverable — No securitySchemes declared. Investigated: spec 81%, docs 75%, wellknown 0%.
- [warn] Machine-readable, versioned contract — info.version="1.0" set but no versioning scheme (URL / header / media type) detected. Investigated: spec 78%, docs 56%.
- [warn] Security & governance hygiene — 1 credential-shaped string detected in spec: bearer-jwt. Investigated: spec 75%, wellknown 0%.
- [pass] Example coverage — 47% example coverage. Investigated: spec 100%, docs 100%, sdk 100%.

### Developer Experience

- [pass] Code samples in docs — Code samples present on 1/19 pages across 1 language(s); broader multi-language coverage missing. Investigated: docs 100%.
- [pass] Description completeness — 47% description completeness. Investigated: spec 100%.
- [warn] Quickstart present — Quickstart page reachable (2 variants scanned starting at https://developer.onetrust.com/) but no runnable code sample detected in HTML or .md variant. Investigated: docs 50%.
- [fail] Self-service developer portal — Signup page is sales-gated (contact-sales/request-access language detected). Investigated: docs 0%.
- [fail] Changelog published — No changelog URL or mention found in spec metadata. Investigated: spec 0%, docs 0%.

### Agent Discovery

- [pass] llms.txt present, valid & comprehensive — llms-full.txt reachable at https://developer.onetrust.com/llms-full.txt. Investigated: docs 100%, sdk 0%.
- [pass] Registry & SDK presence — Indexed on Context7 (websites/developer_onetrust_onetrust, 3624 snippets). Investigated: docs 100%, cli 100%, sdk 42%.
- [pass] Crawlable / AEO — Docs paths crawlable by all monitored AI agents. Investigated: wellknown 100%.
- [skip] Docs reachable, not hard auth-gated — No surface produced evidence for this capability in this run.

### Agent Understanding

- [pass] Machine-readable errors (RFC 9457) — 5 distinct 4xx/5xx response codes documented. Investigated: docs 100%, spec 50%.
- [pass] Operation purpose clarity — 100% of operations have a clear summary + operationId an agent can select on. Investigated: spec 100%.
- [pass] Docs structured data — JSON-LD Article markup on 15/15 assessed pages (100%) with dateModified present. Investigated: docs 100%.
- [warn] Description consistency across surfaces — Mean pairwise description similarity across 3 surfaces (spec, docs, sdk) is 3% (threshold 35% for full credit).
- [fail] Agent instructions file (AGENTS.md) — No AGENTS.md at the site root or /.well-known/. Investigated: wellknown 0%.
- [skip] Agent-navigable, token-efficient docs — No surface produced evidence for this capability in this run.

### Agent Usability

- [warn] Rate-limit signaling — Only 1 rate-limit header(s) documented. Investigated: spec 50%, docs 50%.
- [warn] Sandbox separation — No test-mode flag or sandbox environment is exposed. Investigated: sdk 50%, spec 0%, docs 0%.
- [warn] Pagination documented & consistent — No pagination on list endpoints. Investigated: spec 17%, docs 17%.
- [fail] Idempotency documented — 0% of mutating operations document idempotency. Investigated: spec 0%, docs 0%, sdk 0%.
- [fail] Runnable collection with test scripts — No public Postman workspace discovered for the org. Investigated: platform 0%.

## Executive Summary

OneTrust's API program shows strong foundations in contract design and security, but two areas are holding back partner adoption: partners and their agents cannot reliably run, test, or trust API workflows (no runnable collections, no idempotency guidance), and the onboarding experience has meaningful gaps — no published changelog and no self-service developer portal — that force partners to rely on manual processes instead of getting hands-on quickly. Closing the runnable-truth and onboarding gaps should be the immediate priority to unlock self-serve partner success and enable AI agents to integrate confidently.
