openapi: 3.1.0 info: title: Colossal Content API (WordPress REST wp/v2) Discovery API version: wp/v2 summary: 'Public read surface of colossal.com content: news and science posts, marketing and species pages, the media library, taxonomies, contributor profiles and site-wide search.' description: 'Colossal Laboratories & Biosciences publishes colossal.com on WordPress (WP Engine), which exposes the WordPress REST API at https://colossal.com/wp-json/. The wp/v2 namespace is anonymously readable and returns the company''s news and science posts (238 published), marketing / species / FAQ pages (59 published), the media library (990 items), categories (15), tags (156), contributor profiles (8) and a site-wide search endpoint (297 indexed objects) as JSON. This document was DERIVED mechanically by API Evangelist from the route-discovery document served at https://colossal.com/wp-json/ on 2026-08-09 — every path, method and parameter below is taken verbatim from that descriptor. Colossal does not publish an OpenAPI definition of its own, and this is not a product API: it is the content API the CMS exposes. Write operations exist on these routes but require authentication (WordPress Application Passwords over HTTP Basic). Colossal''s custom content types visible in the sitemap — papers, podcast episodes, team members, FAQs and PDFs — are NOT registered with the REST API (show_in_rest false), so they do not appear here and cannot be read as JSON.' contact: name: Colossal Laboratories & Biosciences url: https://colossal.com/ x-derived-by: API Evangelist enrichment pipeline x-derived-from: https://colossal.com/wp-json/ x-derived-on: '2026-08-09' x-provider-published: false servers: - url: https://colossal.com/wp-json description: Production tags: - name: Discovery paths: /wp/v2: get: operationId: getRoot summary: GET /wp/v2 tags: - Discovery parameters: - name: namespace in: query required: false schema: default: wp/v2 - name: context in: query required: false schema: default: view responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' /wp/v2/statuses: get: operationId: getStatuses summary: GET /wp/v2/statuses tags: - Discovery parameters: - name: context in: query required: false schema: type: string enum: - view - embed - edit default: view description: Scope under which the request is made; determines fields present in response. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' /wp/v2/statuses/{status}: parameters: - name: status in: path required: true schema: type: string description: Path segment taken verbatim from the WordPress route pattern. get: operationId: getStatusesByStatus summary: GET /wp/v2/statuses/{status} tags: - Discovery parameters: - name: status in: query required: false schema: type: string description: An alphanumeric identifier for the status. - name: context in: query required: false schema: type: string enum: - view - embed - edit default: view description: Scope under which the request is made; determines fields present in response. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' /wp/v2/types: get: operationId: getTypes summary: GET /wp/v2/types tags: - Discovery parameters: - name: context in: query required: false schema: type: string enum: - view - embed - edit default: view description: Scope under which the request is made; determines fields present in response. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' /wp/v2/types/{type}: parameters: - name: type in: path required: true schema: type: string description: Path segment taken verbatim from the WordPress route pattern. get: operationId: getTypesByType summary: GET /wp/v2/types/{type} tags: - Discovery parameters: - name: type in: query required: false schema: type: string description: An alphanumeric identifier for the post type. - name: context in: query required: false schema: type: string enum: - view - embed - edit default: view description: Scope under which the request is made; determines fields present in response. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' components: responses: BadRequest: description: Invalid parameter (rest_invalid_param). content: application/json: schema: $ref: '#/components/schemas/WpError' NotFound: description: No route or resource matched (rest_no_route / rest_post_invalid_id). content: application/json: schema: $ref: '#/components/schemas/WpError' Forbidden: description: Authenticated but not permitted (rest_cannot_view / rest_forbidden). content: application/json: schema: $ref: '#/components/schemas/WpError' Unauthorized: description: Authentication required or rejected (rest_forbidden / rest_not_logged_in). content: application/json: schema: $ref: '#/components/schemas/WpError' schemas: WpError: type: object description: The WordPress REST API error envelope (WP_Error serialized to JSON). properties: code: type: string description: Machine-readable error code, e.g. rest_forbidden. message: type: string description: Human-readable error message. data: type: object properties: status: type: integer securitySchemes: applicationPassword: type: http scheme: basic description: WordPress Application Passwords, advertised by the site at https://colossal.com/wp-json/ under authentication.application-passwords; authorization endpoint https://colossal.com/wp-admin/authorize-application.php. Read operations on wp/v2 are anonymous.