openapi: 3.1.0 info: title: Colossal Content API (WordPress REST wp/v2) Media API version: wp/v2 summary: 'Public read surface of colossal.com content: news and science posts, marketing and species pages, the media library, taxonomies, contributor profiles and site-wide search.' description: 'Colossal Laboratories & Biosciences publishes colossal.com on WordPress (WP Engine), which exposes the WordPress REST API at https://colossal.com/wp-json/. The wp/v2 namespace is anonymously readable and returns the company''s news and science posts (238 published), marketing / species / FAQ pages (59 published), the media library (990 items), categories (15), tags (156), contributor profiles (8) and a site-wide search endpoint (297 indexed objects) as JSON. This document was DERIVED mechanically by API Evangelist from the route-discovery document served at https://colossal.com/wp-json/ on 2026-08-09 — every path, method and parameter below is taken verbatim from that descriptor. Colossal does not publish an OpenAPI definition of its own, and this is not a product API: it is the content API the CMS exposes. Write operations exist on these routes but require authentication (WordPress Application Passwords over HTTP Basic). Colossal''s custom content types visible in the sitemap — papers, podcast episodes, team members, FAQs and PDFs — are NOT registered with the REST API (show_in_rest false), so they do not appear here and cannot be read as JSON.' contact: name: Colossal Laboratories & Biosciences url: https://colossal.com/ x-derived-by: API Evangelist enrichment pipeline x-derived-from: https://colossal.com/wp-json/ x-derived-on: '2026-08-09' x-provider-published: false servers: - url: https://colossal.com/wp-json description: Production tags: - name: Media paths: /wp/v2/media: get: operationId: getMedia summary: GET /wp/v2/media tags: - Media parameters: - name: context in: query required: false schema: type: string enum: - view - embed - edit default: view description: Scope under which the request is made; determines fields present in response. - name: page in: query required: false schema: type: integer default: 1 minimum: 1 description: Current page of the collection. - name: per_page in: query required: false schema: type: integer default: 10 minimum: 1 maximum: 100 description: Maximum number of items to be returned in result set. - name: search in: query required: false schema: type: string description: Limit results to those matching a string. - name: after in: query required: false schema: type: string format: date-time description: Limit response to posts published after a given ISO8601 compliant date. - name: modified_after in: query required: false schema: type: string format: date-time description: Limit response to posts modified after a given ISO8601 compliant date. - name: author in: query required: false schema: type: array items: type: integer default: [] description: Limit result set to posts assigned to specific authors. - name: author_exclude in: query required: false schema: type: array items: type: integer default: [] description: Ensure result set excludes posts assigned to specific authors. - name: before in: query required: false schema: type: string format: date-time description: Limit response to posts published before a given ISO8601 compliant date. - name: modified_before in: query required: false schema: type: string format: date-time description: Limit response to posts modified before a given ISO8601 compliant date. - name: exclude in: query required: false schema: type: array items: type: integer default: [] description: Ensure result set excludes specific IDs. - name: include in: query required: false schema: type: array items: type: integer default: [] description: Limit result set to specific IDs. - name: search_semantics in: query required: false schema: type: string enum: - exact description: How to interpret the search input. - name: offset in: query required: false schema: type: integer description: Offset the result set by a specific number of items. - name: order in: query required: false schema: type: string enum: - asc - desc default: desc description: Order sort attribute ascending or descending. - name: orderby in: query required: false schema: type: string enum: - author - date - id - include - modified - parent - relevance - slug - include_slugs - title default: date description: Sort collection by post attribute. - name: parent in: query required: false schema: type: array items: type: integer default: [] description: Limit result set to items with particular parent IDs. - name: parent_exclude in: query required: false schema: type: array items: type: integer default: [] description: Limit result set to all items except those of a particular parent ID. - name: search_columns in: query required: false schema: type: array items: type: string enum: - post_title - post_content - post_excerpt default: [] description: Array of column names to be searched. - name: slug in: query required: false schema: type: array items: type: string description: Limit result set to posts with one or more specific slugs. - name: status in: query required: false schema: type: array items: type: string enum: - inherit - private - trash default: inherit description: Limit result set to posts assigned one or more statuses. - name: media_type in: query required: false schema: type: array items: type: string enum: - image - video - text - application - audio default: null description: Limit result set to attachments of a particular media type or media types. - name: mime_type in: query required: false schema: type: array items: type: string default: null description: Limit result set to attachments of a particular MIME type or MIME types. responses: '200': description: Successful response content: application/json: schema: type: array items: type: object headers: X-WP-Total: description: Total number of records in the collection schema: type: integer X-WP-TotalPages: description: Total number of pages available schema: type: integer '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' post: operationId: createMedia summary: POST /wp/v2/media tags: - Media requestBody: required: false content: application/json: schema: type: object properties: date: type: string format: date-time description: The date the post was published, in the site's timezone. date_gmt: type: string format: date-time description: The date the post was published, as GMT. slug: type: string description: An alphanumeric identifier for the post unique to its type. status: type: string enum: - publish - future - draft - pending - private - acf-disabled description: A named status for the post. title: type: object description: The title for the post. author: type: integer description: The ID for the author of the post. featured_media: type: integer description: The ID of the featured media for the post. comment_status: type: string enum: - open - closed description: Whether or not comments are open on the post. ping_status: type: string enum: - open - closed description: Whether or not the post can be pinged. meta: type: object description: Meta fields. template: type: string description: The theme file to use to display the post. alt_text: type: string description: Alternative text to display when attachment is not displayed. caption: type: object description: The attachment caption. description: type: object description: The attachment description. post: type: integer description: The ID for the associated post of the attachment. security: - applicationPassword: [] responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' /wp/v2/media/{id}: parameters: - name: id in: path required: true schema: type: integer description: Unique identifier for the resource. get: operationId: getMediaById summary: GET /wp/v2/media/{id} tags: - Media parameters: - name: id in: query required: false schema: type: integer description: Unique identifier for the post. - name: context in: query required: false schema: type: string enum: - view - embed - edit default: view description: Scope under which the request is made; determines fields present in response. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' post: operationId: createMediaById summary: POST /wp/v2/media/{id} tags: - Media requestBody: required: false content: application/json: schema: type: object properties: id: type: integer description: Unique identifier for the post. date: type: string format: date-time description: The date the post was published, in the site's timezone. date_gmt: type: string format: date-time description: The date the post was published, as GMT. slug: type: string description: An alphanumeric identifier for the post unique to its type. status: type: string enum: - publish - future - draft - pending - private - acf-disabled description: A named status for the post. title: type: object description: The title for the post. author: type: integer description: The ID for the author of the post. featured_media: type: integer description: The ID of the featured media for the post. comment_status: type: string enum: - open - closed description: Whether or not comments are open on the post. ping_status: type: string enum: - open - closed description: Whether or not the post can be pinged. meta: type: object description: Meta fields. template: type: string description: The theme file to use to display the post. alt_text: type: string description: Alternative text to display when attachment is not displayed. caption: type: object description: The attachment caption. description: type: object description: The attachment description. post: type: integer description: The ID for the associated post of the attachment. security: - applicationPassword: [] responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' put: operationId: replaceMediaById summary: PUT /wp/v2/media/{id} tags: - Media requestBody: required: false content: application/json: schema: type: object properties: id: type: integer description: Unique identifier for the post. date: type: string format: date-time description: The date the post was published, in the site's timezone. date_gmt: type: string format: date-time description: The date the post was published, as GMT. slug: type: string description: An alphanumeric identifier for the post unique to its type. status: type: string enum: - publish - future - draft - pending - private - acf-disabled description: A named status for the post. title: type: object description: The title for the post. author: type: integer description: The ID for the author of the post. featured_media: type: integer description: The ID of the featured media for the post. comment_status: type: string enum: - open - closed description: Whether or not comments are open on the post. ping_status: type: string enum: - open - closed description: Whether or not the post can be pinged. meta: type: object description: Meta fields. template: type: string description: The theme file to use to display the post. alt_text: type: string description: Alternative text to display when attachment is not displayed. caption: type: object description: The attachment caption. description: type: object description: The attachment description. post: type: integer description: The ID for the associated post of the attachment. security: - applicationPassword: [] responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' patch: operationId: updateMediaById summary: PATCH /wp/v2/media/{id} tags: - Media requestBody: required: false content: application/json: schema: type: object properties: id: type: integer description: Unique identifier for the post. date: type: string format: date-time description: The date the post was published, in the site's timezone. date_gmt: type: string format: date-time description: The date the post was published, as GMT. slug: type: string description: An alphanumeric identifier for the post unique to its type. status: type: string enum: - publish - future - draft - pending - private - acf-disabled description: A named status for the post. title: type: object description: The title for the post. author: type: integer description: The ID for the author of the post. featured_media: type: integer description: The ID of the featured media for the post. comment_status: type: string enum: - open - closed description: Whether or not comments are open on the post. ping_status: type: string enum: - open - closed description: Whether or not the post can be pinged. meta: type: object description: Meta fields. template: type: string description: The theme file to use to display the post. alt_text: type: string description: Alternative text to display when attachment is not displayed. caption: type: object description: The attachment caption. description: type: object description: The attachment description. post: type: integer description: The ID for the associated post of the attachment. security: - applicationPassword: [] responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' delete: operationId: deleteMediaById summary: DELETE /wp/v2/media/{id} tags: - Media parameters: - name: id in: query required: false schema: type: integer description: Unique identifier for the post. - name: force in: query required: false schema: type: boolean default: false description: Whether to bypass Trash and force deletion. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' /wp/v2/media/{id}/edit: parameters: - name: id in: path required: true schema: type: integer description: Unique identifier for the resource. post: operationId: createMediaByIdEdit summary: POST /wp/v2/media/{id}/edit tags: - Media requestBody: required: true content: application/json: schema: type: object properties: src: type: string format: uri description: URL to the edited image file. modifiers: type: array items: type: object description: Array of image edits. rotation: type: integer minimum: 0 maximum: 360 description: 'The amount to rotate the image clockwise in degrees. DEPRECATED: Use `modifiers` instead.' x: type: number minimum: 0 maximum: 100 description: 'As a percentage of the image, the x position to start the crop from. DEPRECATED: Use `modifiers` instead.' y: type: number minimum: 0 maximum: 100 description: 'As a percentage of the image, the y position to start the crop from. DEPRECATED: Use `modifiers` instead.' width: type: number minimum: 0 maximum: 100 description: 'As a percentage of the image, the width to crop the image to. DEPRECATED: Use `modifiers` instead.' height: type: number minimum: 0 maximum: 100 description: 'As a percentage of the image, the height to crop the image to. DEPRECATED: Use `modifiers` instead.' caption: type: object description: The attachment caption. description: type: object description: The attachment description. title: type: object description: The title for the post. post: type: integer description: The ID for the associated post of the attachment. alt_text: type: string description: Alternative text to display when attachment is not displayed. required: - src security: - applicationPassword: [] responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' components: responses: BadRequest: description: Invalid parameter (rest_invalid_param). content: application/json: schema: $ref: '#/components/schemas/WpError' NotFound: description: No route or resource matched (rest_no_route / rest_post_invalid_id). content: application/json: schema: $ref: '#/components/schemas/WpError' Forbidden: description: Authenticated but not permitted (rest_cannot_view / rest_forbidden). content: application/json: schema: $ref: '#/components/schemas/WpError' Unauthorized: description: Authentication required or rejected (rest_forbidden / rest_not_logged_in). content: application/json: schema: $ref: '#/components/schemas/WpError' schemas: WpError: type: object description: The WordPress REST API error envelope (WP_Error serialized to JSON). properties: code: type: string description: Machine-readable error code, e.g. rest_forbidden. message: type: string description: Human-readable error message. data: type: object properties: status: type: integer securitySchemes: applicationPassword: type: http scheme: basic description: WordPress Application Passwords, advertised by the site at https://colossal.com/wp-json/ under authentication.application-passwords; authorization endpoint https://colossal.com/wp-admin/authorize-application.php. Read operations on wp/v2 are anonymous.