openapi: 3.2.0 info: title: Aerin Medical Site API (WordPress REST) Embed API version: em-locator/v1 + aerin + wp/v2 summary: Anonymously callable REST surface served by aerinmedical.com — the ENT doctor locator (1,012 treating locations), site search, and the site's form-submission endpoints. description: 'Aerin Medical is a medical-device company and operates no developer API product: it publishes no developer portal, no API documentation, no keys, no SDKs and no terms of use for programmatic access. Its corporate site, aerinmedical.com, does however serve a WordPress REST API at `https://aerinmedical.com/wp-json` with 321 registered routes across 15 namespaces. Most of the standard `wp/v2` content routes (posts, pages, media, users, taxonomies, types) are BLOCKED to anonymous callers by the iThemes Security plugin and return HTTP 401 `itsec_rest_api_access_restricted` — so, unlike most WordPress sites, the content library here is not machine-readable. What IS anonymously readable is the company''s own first-party doctor-finder plugin (`em-locator/v1`, the surface behind https://aerinmedical.com/find-ent-doctor/), the cross-content `wp/v2/search` index, the route discovery documents, and a small set of `aerin`-namespace POST endpoints that back the site''s lead-capture and NOSE-score assessment forms. This document was DERIVED by API Evangelist from the provider''s own live route index (`GET https://aerinmedical.com/wp-json/`) plus direct anonymous probing of each route, on 2026-07-31. Every path, method, parameter name, enumeration and response field is taken from that index or from an observed HTTP 200 response; nothing was invented. Routes observed to return 401 anonymously are deliberately omitted. The `aerin` namespace POST routes are listed because they are really registered and really public, but they declare NO argument schema in the route index and they have side effects (they submit leads / contact requests / newsletter sign-ups into the company''s systems), so they were NOT invoked and no request body is documented for them. Treat this as an incidental site surface, not a supported product API. Aerin Medical offers no availability, versioning or support commitment for it.' contact: name: Aerin Medical, Inc. url: https://aerinmedical.com/contact-us/ email: customerservice@aerinmedical.com x-origin: - url: https://aerinmedical.com/wp-json/ format: wordpress-rest-route-index version: wp/v2 x-apievangelist-method: derived x-apievangelist-derived-from: https://aerinmedical.com/wp-json/ (live route index + per-route anonymous probes, fetched 2026-07-31) x-apievangelist-note: Incidental site API, not a product API. Derived by API Evangelist, not published by Aerin Medical. servers: - url: https://aerinmedical.com/wp-json description: aerinmedical.com WordPress REST API tags: - name: Embed description: oEmbed representations of aerinmedical.com URLs. paths: /oembed/1.0/embed: get: tags: - Embed operationId: getOEmbed summary: Get an oEmbed representation of an aerinmedical.com URL parameters: - name: url in: query required: true description: The URL of the resource for which to fetch oEmbed data. schema: type: string format: uri - name: format in: query required: false schema: type: string enum: - json - xml default: json - name: maxwidth in: query required: false schema: type: integer default: 600 responses: '200': description: The oEmbed response. content: application/json: schema: type: object components: securitySchemes: applicationPassword: type: http scheme: basic description: WordPress application passwords, advertised by the site's own route index at `authentication.application-passwords.endpoints.authorization` = https://aerinmedical.com/wp-admin/authorize-application.php. This is the built-in WordPress mechanism for authenticated (administrative) calls; Aerin Medical issues no public credentials, and every operation in this document is reachable ANONYMOUSLY with no credential at all.