openapi: 3.1.0 info: title: Colossal Content API (WordPress REST wp/v2) Settings API version: wp/v2 summary: 'Public read surface of colossal.com content: news and science posts, marketing and species pages, the media library, taxonomies, contributor profiles and site-wide search.' description: 'Colossal Laboratories & Biosciences publishes colossal.com on WordPress (WP Engine), which exposes the WordPress REST API at https://colossal.com/wp-json/. The wp/v2 namespace is anonymously readable and returns the company''s news and science posts (238 published), marketing / species / FAQ pages (59 published), the media library (990 items), categories (15), tags (156), contributor profiles (8) and a site-wide search endpoint (297 indexed objects) as JSON. This document was DERIVED mechanically by API Evangelist from the route-discovery document served at https://colossal.com/wp-json/ on 2026-08-09 — every path, method and parameter below is taken verbatim from that descriptor. Colossal does not publish an OpenAPI definition of its own, and this is not a product API: it is the content API the CMS exposes. Write operations exist on these routes but require authentication (WordPress Application Passwords over HTTP Basic). Colossal''s custom content types visible in the sitemap — papers, podcast episodes, team members, FAQs and PDFs — are NOT registered with the REST API (show_in_rest false), so they do not appear here and cannot be read as JSON.' contact: name: Colossal Laboratories & Biosciences url: https://colossal.com/ x-derived-by: API Evangelist enrichment pipeline x-derived-from: https://colossal.com/wp-json/ x-derived-on: '2026-08-09' x-provider-published: false servers: - url: https://colossal.com/wp-json description: Production tags: - name: Settings paths: /wp/v2/settings: get: operationId: getSettings summary: GET /wp/v2/settings tags: - Settings responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' post: operationId: createSettings summary: POST /wp/v2/settings tags: - Settings requestBody: required: false content: application/json: schema: type: object properties: title: type: string description: Site title. description: type: string description: Site tagline. url: type: string format: uri description: Site URL. email: type: string format: email description: This address is used for admin purposes, like new user notification. timezone: type: string description: A city in the same timezone as you. date_format: type: string description: A date format for all date strings. time_format: type: string description: A time format for all time strings. start_of_week: type: integer description: A day number of the week that the week should start on. language: type: string description: WordPress locale code. use_smilies: type: boolean description: Convert emoticons like :-) and :-P to graphics on display. default_category: type: integer description: Default post category. default_post_format: type: string description: Default post format. posts_per_page: type: integer description: Blog pages show at most. show_on_front: type: string description: What to show on the front page page_on_front: type: integer description: The ID of the page that should be displayed on the front page page_for_posts: type: integer description: The ID of the page that should display the latest posts default_ping_status: type: string enum: - open - closed description: Allow link notifications from other blogs (pingbacks and trackbacks) on new articles. default_comment_status: type: string enum: - open - closed description: Allow people to submit comments on new posts. site_logo: type: integer description: Site logo. site_icon: type: integer description: Site icon. security: - applicationPassword: [] responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' put: operationId: replaceSettings summary: PUT /wp/v2/settings tags: - Settings requestBody: required: false content: application/json: schema: type: object properties: title: type: string description: Site title. description: type: string description: Site tagline. url: type: string format: uri description: Site URL. email: type: string format: email description: This address is used for admin purposes, like new user notification. timezone: type: string description: A city in the same timezone as you. date_format: type: string description: A date format for all date strings. time_format: type: string description: A time format for all time strings. start_of_week: type: integer description: A day number of the week that the week should start on. language: type: string description: WordPress locale code. use_smilies: type: boolean description: Convert emoticons like :-) and :-P to graphics on display. default_category: type: integer description: Default post category. default_post_format: type: string description: Default post format. posts_per_page: type: integer description: Blog pages show at most. show_on_front: type: string description: What to show on the front page page_on_front: type: integer description: The ID of the page that should be displayed on the front page page_for_posts: type: integer description: The ID of the page that should display the latest posts default_ping_status: type: string enum: - open - closed description: Allow link notifications from other blogs (pingbacks and trackbacks) on new articles. default_comment_status: type: string enum: - open - closed description: Allow people to submit comments on new posts. site_logo: type: integer description: Site logo. site_icon: type: integer description: Site icon. security: - applicationPassword: [] responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' patch: operationId: updateSettings summary: PATCH /wp/v2/settings tags: - Settings requestBody: required: false content: application/json: schema: type: object properties: title: type: string description: Site title. description: type: string description: Site tagline. url: type: string format: uri description: Site URL. email: type: string format: email description: This address is used for admin purposes, like new user notification. timezone: type: string description: A city in the same timezone as you. date_format: type: string description: A date format for all date strings. time_format: type: string description: A time format for all time strings. start_of_week: type: integer description: A day number of the week that the week should start on. language: type: string description: WordPress locale code. use_smilies: type: boolean description: Convert emoticons like :-) and :-P to graphics on display. default_category: type: integer description: Default post category. default_post_format: type: string description: Default post format. posts_per_page: type: integer description: Blog pages show at most. show_on_front: type: string description: What to show on the front page page_on_front: type: integer description: The ID of the page that should be displayed on the front page page_for_posts: type: integer description: The ID of the page that should display the latest posts default_ping_status: type: string enum: - open - closed description: Allow link notifications from other blogs (pingbacks and trackbacks) on new articles. default_comment_status: type: string enum: - open - closed description: Allow people to submit comments on new posts. site_logo: type: integer description: Site logo. site_icon: type: integer description: Site icon. security: - applicationPassword: [] responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' components: responses: BadRequest: description: Invalid parameter (rest_invalid_param). content: application/json: schema: $ref: '#/components/schemas/WpError' NotFound: description: No route or resource matched (rest_no_route / rest_post_invalid_id). content: application/json: schema: $ref: '#/components/schemas/WpError' Forbidden: description: Authenticated but not permitted (rest_cannot_view / rest_forbidden). content: application/json: schema: $ref: '#/components/schemas/WpError' Unauthorized: description: Authentication required or rejected (rest_forbidden / rest_not_logged_in). content: application/json: schema: $ref: '#/components/schemas/WpError' schemas: WpError: type: object description: The WordPress REST API error envelope (WP_Error serialized to JSON). properties: code: type: string description: Machine-readable error code, e.g. rest_forbidden. message: type: string description: Human-readable error message. data: type: object properties: status: type: integer securitySchemes: applicationPassword: type: http scheme: basic description: WordPress Application Passwords, advertised by the site at https://colossal.com/wp-json/ under authentication.application-passwords; authorization endpoint https://colossal.com/wp-admin/authorize-application.php. Read operations on wp/v2 are anonymous.