OneTrust
The OneTrust integration connects Ploy to your OneTrust tenant through OneTrust's API, using an OAuth 2.0 client-credentials API credential. Once connected, Ploy ingests the users in your OneTrust tenant — including each user's email, name, and account status — and surfaces them alongside your other identities for access review.
What Ploy syncs
Users — Ploy reads your tenant's user directory and creates an identity for each user, with their email, username, display name, account status (active or deactivated), and the date the account was created.
App access — each ingested user is recorded as having access to OneTrust, with their OneTrust user type (Internal or External) as the access level.
Login activity — where your API credential has access to OneTrust's login-history feed, Ploy also ingests successful sign-ins to power each user's last-activity date. If the credential does not have access to this feed, Ploy simply skips login activity — the user sync is unaffected.
By default Ploy ingests only Internal OneTrust users (your own staff). You can choose to also ingest External users (third parties) during setup — see the "Ingest external users?" step below.
OneTrust does not expose MFA status through this API, so Ploy does not collect MFA data for OneTrust users. The integration is read-only: Ploy does not make any changes in your OneTrust tenant.
Before you begin
You need administrator access to your OneTrust tenant to create an API credential.
The credential must be granted the USER scope, which lets Ploy read your tenant's users.
Have your OneTrust tenant hostname ready — the host you use to sign in, for example
acme.my.onetrust.com(regional tenants may look likeapp-uk.onetrust.com).
Create an API credential in OneTrust
Sign in to OneTrust as an administrator.
Open Global Settings, then go to Access Management and select Client Credentials.
Create a new credential and give it a recognisable name, for example
Ploy.Grant it the USER scope so it can read users.
Save the credential, then copy the Client ID and Client Secret. The client secret is shown only once — store it somewhere safe before leaving the page.
Connect OneTrust in Ploy
In Ploy, go to Integrations and select OneTrust.
In Tenant Hostname, enter your OneTrust hostname without
https://or a trailing path, for exampleacme.my.onetrust.com. All API calls are made against this host.In Client ID, paste the Client ID from the credential you created.
In Client Secret, paste the Client Secret. It is stored encrypted and never displayed again.
In Ingest external users?, choose whether Ploy should ingest External OneTrust users (third parties) as well as Internal ones (your own staff). This defaults to No, which ingests Internal users only.
Continue to the next page and click Test Connection to confirm Ploy can reach your tenant.
Troubleshooting
The connection test says the credential is missing a scope. Edit the credential in OneTrust and make sure the USER scope is granted, then run the test again.
The credentials are rejected. Double-check the Client ID and Client Secret. If you have rotated the secret in OneTrust, paste the new value into Ploy and re-test.
Ploy cannot reach your tenant. Confirm the Tenant Hostname is correct and entered without https:// or any path — just the host, for example acme.my.onetrust.com. The hostname must be a OneTrust domain.
OneTrust rate limited the request. OneTrust occasionally rate limits API calls — wait a short while and run the connection test again.
Some users are missing. If the missing users are External (third parties), check the "Ingest external users?" setting — with it set to No, Ploy ingests Internal users only. You can change it at any time by editing the integration.