openapi: 3.2.0 info: title: Habiteo Site Content API (WordPress REST wp-json) oEmbed API version: wp-json summary: Anonymous read surface of the WordPress REST API that www.habiteo.com serves. description: 'Habiteo publishes www.habiteo.com on WordPress, which exposes the WordPress REST API at https://www.habiteo.com/wp-json/. The wp/v2 namespace is anonymously readable and returns the company''s news posts, marketing pages, portfolio entries, media library, taxonomies and users as JSON. This document was DERIVED mechanically by API Evangelist from the route-discovery document served at https://www.habiteo.com/wp-json/ on 2026-08-17 — every path, method and parameter below is taken verbatim from that descriptor. Habiteo publishes no OpenAPI, no developer portal and no API documentation of its own, and THIS IS NOT A HABITEO PRODUCT API: it is the content API the CMS exposes. Habiteo''s actual products (myHabiteo, the 3D configurator, the MegaWidget) have no published contract. Write operations exist on these routes but require WordPress authentication (Application Passwords over HTTP Basic, or a cookie + nonce).' contact: name: Habiteo url: https://www.habiteo.com/ x-derived-by: API Evangelist enrichment pipeline x-derived-from: https://www.habiteo.com/wp-json/ x-derived-on: '2026-08-17' x-provider-published: false servers: - url: https://www.habiteo.com/wp-json description: Production tags: - name: oEmbed paths: /oembed/1.0: get: operationId: getOembed10 summary: GET /oembed/1.0 tags: - oEmbed parameters: - name: namespace in: query required: false schema: type: string default: oembed/1.0 - name: context in: query required: false schema: type: string default: view responses: '200': description: Successful response. content: application/json: schema: type: object '400': description: Invalid parameter. content: application/json: schema: $ref: '#/components/schemas/WPError' '401': description: Not authenticated. content: application/json: schema: $ref: '#/components/schemas/WPError' '403': description: rest_forbidden — the anonymous caller may not perform this action. content: application/json: schema: $ref: '#/components/schemas/WPError' '404': description: No route or resource matched. content: application/json: schema: $ref: '#/components/schemas/WPError' /oembed/1.0/embed: get: operationId: getOembed10Embed summary: GET /oembed/1.0/embed tags: - oEmbed parameters: - name: url in: query required: true schema: type: string - name: format in: query required: false schema: type: string default: json - name: maxwidth in: query required: false schema: type: string default: 600 responses: '200': description: Successful response. content: application/json: schema: type: object '400': description: Invalid parameter. content: application/json: schema: $ref: '#/components/schemas/WPError' '401': description: Not authenticated. content: application/json: schema: $ref: '#/components/schemas/WPError' '403': description: rest_forbidden — the anonymous caller may not perform this action. content: application/json: schema: $ref: '#/components/schemas/WPError' '404': description: No route or resource matched. content: application/json: schema: $ref: '#/components/schemas/WPError' components: securitySchemes: basicAuth: type: http scheme: basic description: WordPress Application Passwords over HTTP Basic. Required for every write operation. cookieNonce: type: apiKey in: header name: X-WP-Nonce description: WordPress logged-in cookie plus an X-WP-Nonce header, used by first-party admin clients. schemas: WPError: type: object description: The WordPress REST error envelope. Not RFC 9457 problem+json. properties: code: type: string description: Machine-readable error code, e.g. rest_post_invalid_id. message: type: string description: Human-readable message. Localized — this install answers in French. data: type: object properties: status: type: integer description: HTTP status repeated in the body.