generated: '2026-09-05' method: derived source: openapi/civil-infrastructure-platform-events-openapi-original.json, openapi/civil-infrastructure-platform-tec-v1-openapi-original.json, live response headers on https://cip-project.org/wp-json/tribe/events/v1/events note: Cross-cutting semantics of the CIP events REST API. Contract generated by The Events Calendar (StellarWP) WordPress plugin running on CIP's own site; servers[] names https://cip-project.org/wp-json/..., so the instance and the data are CIP's. authentication: style: HTTP Basic (WordPress Application Passwords) for writes; anonymous for published reads scheme: BasicAuth (components.securitySchemes on the tec/v1 document) application_password_authorization_endpoint: https://cip-project.org/wp-admin/authorize-application.php artifact: authentication/civil-infrastructure-platform-authentication.yml idempotency: coverage: none mechanism: null note: No idempotency key header, parameter or replay-protection contract appears anywhere in the three OpenAPI documents or in the live response headers. POST /events, /venues, /organizers create a new record on every call. Recorded as none rather than omitted — a missing mechanism is a measured fact, not an unchecked field. reversibility: grade: documented note: 'Deletes are soft by default: the API trashes the record and answers 410 "has already been trashed" on a repeat, and 501 "does not support trashing. Set force=true to delete" where the post type has trashing disabled. A trashed record is restorable from WordPress, but NEITHER the contract NOR any CIP or Events Calendar page we fetched states a retention window, so this grades documented, not verified.' write_surfaces: - operation: deleteEvent path: DELETE /tec/v1/events/{id} reversal: restore from trash (WordPress admin) window: null window_source: null evidence: 410 "The event has already been trashed"; 501 "…Set force=true to delete" - operation: deleteVenue path: DELETE /tec/v1/venues/{id} reversal: restore from trash (WordPress admin) window: null window_source: null evidence: 410 "The venue has already been trashed" - operation: deleteOrganizer path: DELETE /tec/v1/organizers/{id} reversal: restore from trash (WordPress admin) window: null window_source: null evidence: 410 "The organizer has already been trashed" - operation: createEvent / updateEvent path: POST|PUT /tec/v1/events[/{id}] reversal: delete (trash) the created record, or a further update window: null window_source: null evidence: no undo operation is declared in the contract force_delete: parameter: force effect: bypasses the trash and deletes permanently — irreversible declared_in: tec/v1 and tribe/events/v1 delete operations dry_run_mode: supported: false note: No preview/validate-only mode is declared in any of the three documents. pagination: style: page-number params: - page - per_page response_fields: - total - total_pages - rest_url - next_rest_url - previous_rest_url response_headers: - X-WP-Total - X-WP-TotalPages - Link header_evidence: 'access-control-expose-headers: X-WP-Total, X-WP-TotalPages, Link (observed on GET /wp-json/tribe/events/v1/events)' max_per_page: null filtering: params: - search - start_date - end_date - status - categories - tags - venue - organizer - featured - order - orderby field_expansion: supported: false note: Related venue/organizer objects are embedded in full on the event representation; there is no sparse-fieldset or expand parameter. metadata: supported: false request_tracing: request_id_header: null note: No request-id or correlation header is documented or observed. versioning: scheme: uri-path namespace current: - tribe/events/v1 - tec/v1 note: 'Two coexisting namespaces: the legacy tribe/events/v1 surface and the newer tec/v1 surface with operationIds and declared securitySchemes.' error_envelope: shape: WordPress REST error object {code, message, data.status} rfc9457: false artifact: errors/civil-infrastructure-platform-problem-types.yml rate_limit_signaling: headers_observed: [] documented: false artifact: rate-limits/civil-infrastructure-platform-rate-limits.yml note: No RateLimit-*, X-RateLimit-* or Retry-After header appeared on a live 200; caching is public, max-age=604800. caching: cache_control: public, max-age=604800 observed_on: GET https://cip-project.org/wp-json/tribe/events/v1/events event_surface: kind: polling-triggers webhooks: false asyncapi: false note: >- CIP serves NO webhook or event-streaming surface. There is no callback registration endpoint, no subscription resource and no delivery-retry contract anywhere in the 127 routes the WordPress REST index advertises, and https://cip-project.org/asyncapi.yaml is 404. What does exist is a set of POLLING trigger endpoints published by the plugin's Zapier and Power Automate integrations — an automation client GETs them on a schedule and diffs the result. That is an integration surface, not an event surface, so no AsyncAPI or Webhooks pointer is emitted. polling_triggers: - GET /wp-json/tribe/zapier/v1/new-events - GET /wp-json/tribe/zapier/v1/updated-events - GET /wp-json/tribe/zapier/v1/canceled-events - GET /wp-json/tribe/zapier/v1/find-events - GET /wp-json/tribe/power-automate/v1/new-events - GET /wp-json/tribe/power-automate/v1/updated-events - GET /wp-json/tribe/power-automate/v1/canceled-events trigger_auth: >- access_token query parameter — required on the Zapier triggers, optional on the Power Automate ones. Issued through GET /wp-json/tribe/zapier/v1/authorize, which takes consumer_id and consumer_secret. evidence: - url: https://cip-project.org/wp-json/ status: 200 note: route index listing all seven trigger routes, saved to well-known/ - url: https://cip-project.org/asyncapi.yaml status: 404 - url: https://cip-project.org/wp-json/tribe/webhooks/v1 status: 404 cross_links: errors: errors/civil-infrastructure-platform-problem-types.yml lifecycle: lifecycle/civil-infrastructure-platform-lifecycle.yml authentication: authentication/civil-infrastructure-platform-authentication.yml rate_limits: rate-limits/civil-infrastructure-platform-rate-limits.yml