openapi: 3.2.0 info: title: Ethyreal Bio Content API (WordPress REST wp/v2) Users API version: wp/v2 summary: 'Public read surface of ethyrealbio.com content: press releases and news, corporate pages including the Expanded Access Policy and Terms of Use, leadership and board-of-directors profiles, the media library, taxonomies and site-wide search.' description: 'Ethyreal Bio publishes www.ethyrealbio.com on WordPress (Avada theme, WP Engine hosting), which exposes the WordPress REST API at https://www.ethyrealbio.com/wp-json/. The wp/v2 namespace is anonymously readable and returns the company''s press releases (`posts`), corporate pages (`pages`), leadership and board profiles (`team_member`, grouped by `team_group`), the media library, FAQ and portfolio custom post types, taxonomies and a site-wide search endpoint as JSON. This document was DERIVED mechanically by API Evangelist from the route-discovery document served at https://www.ethyrealbio.com/wp-json/ on 2026-08-12 — every path, method and parameter below is taken verbatim from that descriptor. Ethyreal Bio does not publish an OpenAPI definition of its own, and this is not a product API: it is the content API the CMS exposes. Ethyreal Bio is a clinical-stage biotechnology company and ships no developer program, no API product and no SDKs. Write operations exist on these routes but require authentication (WordPress Application Passwords over HTTP Basic); `/wp/v2/users` returns 403 and `/wp/v2/settings` returns 401 anonymously.' contact: name: Ethyreal Bio url: https://www.ethyrealbio.com/ x-derived-by: API Evangelist enrichment pipeline x-derived-from: https://www.ethyrealbio.com/wp-json/ x-derived-on: '2026-08-12' x-provider-published: false servers: - url: https://www.ethyrealbio.com/wp-json description: Production tags: - name: Users paths: /wp/v2/users: get: operationId: getUsers summary: GET /wp/v2/users tags: - Users parameters: - name: context in: query required: false schema: type: string enum: - view - embed - edit default: view description: Scope under which the request is made; determines fields present in response. - name: page in: query required: false schema: type: integer default: 1 minimum: 1 description: Current page of the collection. - name: per_page in: query required: false schema: type: integer default: 10 minimum: 1 maximum: 100 description: Maximum number of items to be returned in result set. - name: search in: query required: false schema: type: string description: Limit results to those matching a string. - name: exclude in: query required: false schema: type: array items: type: integer default: [] description: Ensure result set excludes specific IDs. - name: include in: query required: false schema: type: array items: type: integer default: [] description: Limit result set to specific IDs. - name: offset in: query required: false schema: type: integer description: Offset the result set by a specific number of items. - name: order in: query required: false schema: type: string enum: - asc - desc default: asc description: Order sort attribute ascending or descending. - name: orderby in: query required: false schema: type: string enum: - id - include - name - registered_date - slug - include_slugs - email - url default: name description: Sort collection by user attribute. - name: slug in: query required: false schema: type: array items: type: string description: Limit result set to users with one or more specific slugs. - name: roles in: query required: false schema: type: array items: type: string description: Limit result set to users matching at least one specific role provided. Accepts csv list or single role. - name: capabilities in: query required: false schema: type: array items: type: string description: Limit result set to users matching at least one specific capability provided. Accepts csv list or single capability. - name: who in: query required: false schema: type: string enum: - authors description: Limit result set to users who are considered authors. - name: has_published_posts in: query required: false schema: type: - boolean - array items: type: string enum: post: post page: page attachment: attachment nav_menu_item: nav_menu_item wp_block: wp_block wp_template: wp_template wp_template_part: wp_template_part wp_global_styles: wp_global_styles wp_navigation: wp_navigation wp_font_family: wp_font_family wp_font_face: wp_font_face team_member: team_member avada_portfolio: avada_portfolio avada_faq: avada_faq description: Limit result set to users who have published posts. - name: search_columns in: query required: false schema: type: array items: type: string enum: - email - name - id - username - slug default: [] description: Array of column names to be searched. responses: '200': description: Successful response content: application/json: schema: type: array items: type: object headers: X-WP-Total: description: Total number of records in the collection schema: type: integer X-WP-TotalPages: description: Total number of pages available schema: type: integer '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' security: - applicationPassword: [] post: operationId: createUsers summary: POST /wp/v2/users tags: - Users requestBody: required: true content: application/json: schema: type: object properties: username: type: string description: Login name for the user. name: type: string description: Display name for the user. first_name: type: string description: First name for the user. last_name: type: string description: Last name for the user. email: type: string format: email description: The email address for the user. url: type: string format: uri description: URL of the user. description: type: string description: Description of the user. locale: type: string enum: - '' - en_US - es_ES description: Locale for the user. nickname: type: string description: The nickname for the user. slug: type: string description: An alphanumeric identifier for the user. roles: type: array items: type: string description: Roles assigned to the user. password: type: string description: Password for the user (never included). meta: type: object description: Meta fields. required: - email - password - username responses: '201': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' security: - applicationPassword: [] /wp/v2/users/me: get: operationId: getUsersMe summary: GET /wp/v2/users/me tags: - Users parameters: - name: context in: query required: false schema: type: string enum: - view - embed - edit default: view description: Scope under which the request is made; determines fields present in response. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' post: operationId: createUsersMe summary: POST /wp/v2/users/me tags: - Users requestBody: required: true content: application/json: schema: type: object properties: username: type: string description: Login name for the user. name: type: string description: Display name for the user. first_name: type: string description: First name for the user. last_name: type: string description: Last name for the user. email: type: string format: email description: The email address for the user. url: type: string format: uri description: URL of the user. description: type: string description: Description of the user. locale: type: string enum: &id001 - '' - en_US - es_ES description: Locale for the user. nickname: type: string description: The nickname for the user. slug: type: string description: An alphanumeric identifier for the user. roles: type: array items: type: string description: Roles assigned to the user. password: type: string description: Password for the user (never included). meta: type: object description: Meta fields. responses: '201': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' security: - applicationPassword: [] put: operationId: updateUsersMe summary: PUT /wp/v2/users/me tags: - Users requestBody: required: true content: application/json: schema: type: object properties: username: type: string description: Login name for the user. name: type: string description: Display name for the user. first_name: type: string description: First name for the user. last_name: type: string description: Last name for the user. email: type: string format: email description: The email address for the user. url: type: string format: uri description: URL of the user. description: type: string description: Description of the user. locale: type: string enum: *id001 description: Locale for the user. nickname: type: string description: The nickname for the user. slug: type: string description: An alphanumeric identifier for the user. roles: type: array items: type: string description: Roles assigned to the user. password: type: string description: Password for the user (never included). meta: type: object description: Meta fields. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' security: - applicationPassword: [] patch: operationId: patchUsersMe summary: PATCH /wp/v2/users/me tags: - Users requestBody: required: false content: application/json: schema: type: object properties: username: type: string description: Login name for the user. name: type: string description: Display name for the user. first_name: type: string description: First name for the user. last_name: type: string description: Last name for the user. email: type: string format: email description: The email address for the user. url: type: string format: uri description: URL of the user. description: type: string description: Description of the user. locale: type: string enum: *id001 description: Locale for the user. nickname: type: string description: The nickname for the user. slug: type: string description: An alphanumeric identifier for the user. roles: type: array items: type: string description: Roles assigned to the user. password: type: string description: Password for the user (never included). meta: type: object description: Meta fields. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' security: - applicationPassword: [] delete: operationId: deleteUsersMe summary: DELETE /wp/v2/users/me tags: - Users parameters: - name: force in: query required: false schema: type: boolean default: false description: Required to be true, as users do not support trashing. - name: reassign in: query required: true schema: type: integer description: Reassign the deleted user's posts and links to this user ID. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' security: - applicationPassword: [] /wp/v2/users/{id}: get: operationId: getUsersById summary: GET /wp/v2/users/{id} tags: - Users parameters: - name: id in: path required: true schema: type: integer description: Identifier for the users resource. - name: context in: query required: false schema: type: string enum: - view - embed - edit default: view description: Scope under which the request is made; determines fields present in response. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' post: operationId: createUsersById summary: POST /wp/v2/users/{id} tags: - Users parameters: - name: id in: path required: true schema: type: integer description: Identifier for the users resource. requestBody: required: true content: application/json: schema: type: object properties: username: type: string description: Login name for the user. name: type: string description: Display name for the user. first_name: type: string description: First name for the user. last_name: type: string description: Last name for the user. email: type: string format: email description: The email address for the user. url: type: string format: uri description: URL of the user. description: type: string description: Description of the user. locale: type: string enum: &id002 - '' - en_US - es_ES description: Locale for the user. nickname: type: string description: The nickname for the user. slug: type: string description: An alphanumeric identifier for the user. roles: type: array items: type: string description: Roles assigned to the user. password: type: string description: Password for the user (never included). meta: type: object description: Meta fields. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' security: - applicationPassword: [] put: operationId: updateUsersById summary: PUT /wp/v2/users/{id} tags: - Users parameters: - name: id in: path required: true schema: type: integer description: Identifier for the users resource. requestBody: required: true content: application/json: schema: type: object properties: username: type: string description: Login name for the user. name: type: string description: Display name for the user. first_name: type: string description: First name for the user. last_name: type: string description: Last name for the user. email: type: string format: email description: The email address for the user. url: type: string format: uri description: URL of the user. description: type: string description: Description of the user. locale: type: string enum: *id002 description: Locale for the user. nickname: type: string description: The nickname for the user. slug: type: string description: An alphanumeric identifier for the user. roles: type: array items: type: string description: Roles assigned to the user. password: type: string description: Password for the user (never included). meta: type: object description: Meta fields. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' security: - applicationPassword: [] patch: operationId: patchUsersById summary: PATCH /wp/v2/users/{id} tags: - Users parameters: - name: id in: path required: true schema: type: integer description: Identifier for the users resource. requestBody: required: false content: application/json: schema: type: object properties: username: type: string description: Login name for the user. name: type: string description: Display name for the user. first_name: type: string description: First name for the user. last_name: type: string description: Last name for the user. email: type: string format: email description: The email address for the user. url: type: string format: uri description: URL of the user. description: type: string description: Description of the user. locale: type: string enum: *id002 description: Locale for the user. nickname: type: string description: The nickname for the user. slug: type: string description: An alphanumeric identifier for the user. roles: type: array items: type: string description: Roles assigned to the user. password: type: string description: Password for the user (never included). meta: type: object description: Meta fields. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' security: - applicationPassword: [] delete: operationId: deleteUsersById summary: DELETE /wp/v2/users/{id} tags: - Users parameters: - name: id in: path required: true schema: type: integer description: Identifier for the users resource. - name: force in: query required: false schema: type: boolean default: false description: Required to be true, as users do not support trashing. - name: reassign in: query required: true schema: type: integer description: Reassign the deleted user's posts and links to this user ID. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' security: - applicationPassword: [] /wp/v2/users/{user_id}/application-passwords: get: operationId: getUsersByUserIdApplicationPasswords summary: GET /wp/v2/users/{user_id}/application-passwords tags: - Users parameters: - name: user_id in: path required: true schema: type: string description: Identifier for the users resource. - name: context in: query required: false schema: type: string enum: - view - embed - edit default: view description: Scope under which the request is made; determines fields present in response. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' post: operationId: createUsersByUserIdApplicationPasswords summary: POST /wp/v2/users/{user_id}/application-passwords tags: - Users parameters: - name: user_id in: path required: true schema: type: string description: Identifier for the users resource. requestBody: required: true content: application/json: schema: type: object properties: app_id: type: string description: A UUID provided by the application to uniquely identify it. It is recommended to use an UUID v5 with the URL or DNS namespace. name: type: string description: The name of the application password. required: - name responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' security: - applicationPassword: [] delete: operationId: deleteUsersByUserIdApplicationPasswords summary: DELETE /wp/v2/users/{user_id}/application-passwords tags: - Users parameters: - name: user_id in: path required: true schema: type: string description: Identifier for the users resource. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' security: - applicationPassword: [] /wp/v2/users/{user_id}/application-passwords/introspect: get: operationId: getUsersByUserIdApplicationPasswordsIntrospect summary: GET /wp/v2/users/{user_id}/application-passwords/introspect tags: - Users parameters: - name: user_id in: path required: true schema: type: string description: Identifier for the users resource. - name: context in: query required: false schema: type: string enum: - view - embed - edit default: view description: Scope under which the request is made; determines fields present in response. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' /wp/v2/users/{user_id}/application-passwords/{uuid}: get: operationId: getUsersByUserIdApplicationPasswordsByUuid summary: GET /wp/v2/users/{user_id}/application-passwords/{uuid} tags: - Users parameters: - name: user_id in: path required: true schema: type: string description: Identifier for the users resource. - name: uuid in: path required: true schema: type: string description: Identifier for the users resource. - name: context in: query required: false schema: type: string enum: - view - embed - edit default: view description: Scope under which the request is made; determines fields present in response. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' post: operationId: createUsersByUserIdApplicationPasswordsByUuid summary: POST /wp/v2/users/{user_id}/application-passwords/{uuid} tags: - Users parameters: - name: user_id in: path required: true schema: type: string description: Identifier for the users resource. - name: uuid in: path required: true schema: type: string description: Identifier for the users resource. requestBody: required: true content: application/json: schema: type: object properties: app_id: type: string description: A UUID provided by the application to uniquely identify it. It is recommended to use an UUID v5 with the URL or DNS namespace. name: type: string description: The name of the application password. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' security: - applicationPassword: [] put: operationId: updateUsersByUserIdApplicationPasswordsByUuid summary: PUT /wp/v2/users/{user_id}/application-passwords/{uuid} tags: - Users parameters: - name: user_id in: path required: true schema: type: string description: Identifier for the users resource. - name: uuid in: path required: true schema: type: string description: Identifier for the users resource. requestBody: required: true content: application/json: schema: type: object properties: app_id: type: string description: A UUID provided by the application to uniquely identify it. It is recommended to use an UUID v5 with the URL or DNS namespace. name: type: string description: The name of the application password. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' security: - applicationPassword: [] patch: operationId: patchUsersByUserIdApplicationPasswordsByUuid summary: PATCH /wp/v2/users/{user_id}/application-passwords/{uuid} tags: - Users parameters: - name: user_id in: path required: true schema: type: string description: Identifier for the users resource. - name: uuid in: path required: true schema: type: string description: Identifier for the users resource. requestBody: required: false content: application/json: schema: type: object properties: app_id: type: string description: A UUID provided by the application to uniquely identify it. It is recommended to use an UUID v5 with the URL or DNS namespace. name: type: string description: The name of the application password. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' security: - applicationPassword: [] delete: operationId: deleteUsersByUserIdApplicationPasswordsByUuid summary: DELETE /wp/v2/users/{user_id}/application-passwords/{uuid} tags: - Users parameters: - name: user_id in: path required: true schema: type: string description: Identifier for the users resource. - name: uuid in: path required: true schema: type: string description: Identifier for the users resource. responses: '200': description: Successful response content: application/json: schema: type: object '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' security: - applicationPassword: [] components: securitySchemes: applicationPassword: type: http scheme: basic description: WordPress Application Passwords, advertised by the site at https://www.ethyrealbio.com/wp-json/ under authentication.application-passwords; authorization endpoint https://www.ethyrealbio.com/wp-admin/authorize-application.php. Read operations on wp/v2 content routes are anonymous. responses: BadRequest: description: Invalid parameter (rest_invalid_param). content: application/json: schema: $ref: '#/components/schemas/WpError' Unauthorized: description: Authentication required or rejected (rest_forbidden / rest_not_logged_in). content: application/json: schema: $ref: '#/components/schemas/WpError' Forbidden: description: Authenticated but not permitted (rest_cannot_view / rest_user_cannot_view). content: application/json: schema: $ref: '#/components/schemas/WpError' NotFound: description: No route or resource matched (rest_no_route / rest_post_invalid_id). content: application/json: schema: $ref: '#/components/schemas/WpError' schemas: WpError: type: object description: The WordPress REST API error envelope (WP_Error serialized to JSON). properties: code: type: string description: Machine-readable error code, e.g. rest_forbidden. message: type: string description: Human-readable error message. data: type: object properties: status: type: integer