# authorship: generated by API Evangelist tooling. Stamped 2026-08-18 # on the file's own generator header (roadmap#64). An unmarked file is # NOT assumed to be ours -- absence of evidence was never stamped. x-method: generated overlay: 1.0.0 info: title: API Evangelist enhancements for the Boundless Bio Content API version: 1.0.0 extends: openapi/boundless-bio-content-openapi.yml x-generated: '2026-08-08' x-method: generated x-source: >- Generated by the API Evangelist enrichment pipeline on 2026-08-08. Records the enhancements API Evangelist added on top of the raw WordPress route index at https://boundlessbio.com/wp-json/. Boundless Bio publishes no OpenAPI, so there is no provider-authored original to mutate — this overlay documents what we contributed so the derivation stays auditable and separable from the provider's own contract. actions: - target: $.info update: x-apievangelist-profile: https://apis.io/providers/boundless-bio/ x-apievangelist-harvested: '2026-08-08' x-apievangelist-contribution: >- Operation summaries, operationIds, tag groupings, response schemas, pagination headers and error responses were authored by API Evangelist. The route paths, HTTP methods and every query and body parameter were taken verbatim from the provider's published route index. - target: $.info update: x-provider-publishes-openapi: false x-provider-developer-program: false x-surface-class: cms-content-api - target: $.paths['/wp/v2/who-we-are'].get update: x-apievangelist-note: >- The highest-value operation on this surface — 27 published Leadership records covering the executive team, the board of directors and the scientific / clinical advisors, each with a full rendered biography, a headshot and a LinkedIn URL under `acf`. x-apievangelist-observed: x_wp_total: 27 date: '2026-08-08' - target: $.paths['/wp/v2/pages'].get update: x-apievangelist-note: >- 9 published pages, but `content.rendered` is an EMPTY STRING on all of them. The page body is served through the public `acf.modules` flexible-content array instead. A client that reads `content` will see nothing. See conventions/boundless-bio-conventions.yml. x-apievangelist-observed: x_wp_total: 9 content_rendered_empty: true - target: $.paths['/wp/v2/media'].get update: x-apievangelist-note: >- 255 attachments. Notably this is where Boundless Bio's primary scientific material lives — conference posters such as the AACR 2026 poster are stored here as application/pdf with `post: null`, so they are reachable only by enumerating the library. x-apievangelist-observed: x_wp_total: 255 - target: $.paths['/wp/v2/categories'].get update: x-apievangelist-note: >- Four terms — Board of Directors (4), Leadership (4), Scientific / Clinical Advisors (slug `scientific-founders`, 5), Uncategorized (0). They cover only 13 of the 27 Leadership records; the remaining 14 are uncategorized, so this taxonomy is not a complete role filter. The advisors term's slug and display name diverge. - target: $.paths['/wp/v2/posts'].get update: x-apievangelist-note: >- Registered and reachable but EMPTY (X-WP-Total 0) on this deployment — modelled so the surface is complete, not because it carries data. Boundless Bio publishes no blog here; the RSS feed at /feed/ is a valid channel with zero items. - target: $.paths['/wp/v2/tags'].get update: x-apievangelist-note: Registered and reachable but empty (X-WP-Total 0) on this deployment. - target: $.paths['/wp/v2/comments'].get update: x-apievangelist-note: Registered and reachable but empty (X-WP-Total 0) on this deployment. - target: $.paths['/wp/v2/users'].get update: x-apievangelist-note: >- Readable ANONYMOUSLY on this deployment (HTTP 200, 4 records) where most WordPress sites return 401. It discloses the display names and author-archive slugs of internal CMS staff accounts. Recorded as an exposure, deliberately not exemplified and deliberately not packaged as an agent skill. x-apievangelist-personal-data: true - target: $.paths['/wp/v2/settings'].get update: x-apievangelist-note: 'Gated — returns 401 rest_forbidden anonymously.' - target: $.components.securitySchemes.applicationPassword update: x-apievangelist-note: >- Advertised by the site itself in the `authentication.application-passwords` block of https://boundlessbio.com/wp-json/. Every read operation modelled here is anonymous; the scheme applies only to the write operations, which are unreachable without a WordPress account. - target: $.components.schemas.WpError update: x-apievangelist-note: >- The WordPress REST error envelope. Deliberately not remapped to RFC 9457 problem+json — see errors/boundless-bio-problem-types.yml for why no problem-type URIs are invented here. Note that the theme route /wp/v2/global/search returns a THIRD shape (`data: null`) with HTTP 500; that namespace is out of scope for this document.