generated: '2026-08-04' method: searched source: >- Live response headers and payloads probed against https://harbinger-health.com/wp-json/ on 2026-08-04, the wp-json route-discovery document, and openapi/harbinger-health-wordpress-wp-v2-openapi.yml scope: >- Cross-cutting request/response semantics for the only publicly callable Harbinger Health API. Every convention below was observed on the wire. Harbinger Health documents none of them; the semantics are those of WordPress core and of the MCP/OAuth plugins installed on the site, not an API design guide the company authored. authentication: styles: - Anonymous read (no credential) for wp/v2 view and embed context - HTTP Basic with a WordPress application password for edit context and writes - OAuth 2.1 bearer with scope mcp for the Model Context Protocol server detail: authentication/harbinger-health-authentication.yml cors: access_control_allow_headers: [Authorization, X-WP-Nonce, Content-Disposition, Content-MD5, Content-Type] access_control_expose_headers: [X-WP-Total, X-WP-TotalPages, Link] idempotency: supported: false note: >- No Idempotency-Key header, no idempotent-retry contract and no request-replay window is advertised on any Harbinger Health surface. GET, PUT and DELETE are idempotent only by HTTP method semantics; POST is not. NO Idempotency pointer is emitted in apis.yml for this provider, because emitting one would credit an idempotency contract that does not exist. pagination: style: page-number with limit parameters: page: {type: integer, default: 1, minimum: 1, description: Current page of the collection.} per_page: {type: integer, default: 10, minimum: 1, maximum: 100, description: Maximum items per page.} offset: {type: integer, description: Offset the result set by a specific number of items.} response_headers: X-WP-Total: Total number of items in the collection. X-WP-TotalPages: Total number of pages at the current per_page. Link: 'RFC 8288 link header carrying rel="next" and rel="prev".' observed: request: GET https://harbinger-health.com/wp-json/wp/v2/posts?per_page=2 x_wp_total: 51 x_wp_totalpages: 26 link: '; rel="next"' over_limit_behaviour: >- per_page above 100 returns HTTP 400 rest_invalid_param with a nested details.per_page.code of rest_out_of_bounds. Observed verbatim at examples/harbinger-health-error-400.json. filtering_and_sorting: search: 'search (string), search_columns, search_semantics' ordering: 'order (asc|desc), orderby (date, id, include, relevance, slug, include_slugs, title, modified, ...)' date_windows: [after, before, modified_after, modified_before] set_membership: [include, exclude, author, author_exclude, categories, categories_exclude, tags, tags_exclude, slug, status] field_selection: sparse_fieldsets: parameter: _fields note: >- WordPress core supports _fields on any route to limit the returned properties. Used to capture examples/harbinger-health-posts-response.json. context: parameter: context values: [view, embed, edit] default: view note: >- context=edit requires an authenticated user; anonymous callers are limited to view and embed, which is why edit-context fields never appear in the captured examples. embedding: parameter: _embed note: 'Expands _links into an _embedded object (author, featured media, terms).' hateoas: Every resource carries an _links object of RFC 8288 relations. error_envelope: shape: WordPress REST error object, NOT RFC 9457 problem+json content_type: application/json fields: code: Machine-readable error slug, e.g. rest_forbidden, rest_no_route, rest_invalid_param. message: Human-readable message. data.status: HTTP status code, repeated inside the body. data.params: Per-parameter message map, present on rest_invalid_param. data.details: Per-parameter nested error object with its own code/message, present on rest_invalid_param. catalog: errors/harbinger-health-problem-types.yml note: >- No application/problem+json is served anywhere on this host, so the RFC 9457 conformance assertion is false for this provider. versioning: style: URI path namespace current: wp/v2 other_namespaces: [wp-abilities/v1, mcp, oembed/1.0, yoast/v1, redirection/v1, leadin/v1, wp-rocket/v1, wp-smush/v1, wpe/cache-plugin/v1, wpe_sign_on_plugin/v1, hub-connector/v1, wp-site-health/v1, wp-block-editor/v1, duplicate-post/v1] detail: lifecycle/harbinger-health-lifecycle.yml note: >- Version is set by the upstream WordPress release and by the installed plugins, not by a Harbinger Health versioning policy. No version header, no date-based version and no version negotiation exist. request_tracing: request_id_header: null note: No request-id, trace-id or correlation-id header is returned on any probed response. rate_limit_signaling: headers: [] note: >- No X-RateLimit-*, RateLimit-* (RFC 9239 draft), Retry-After or quota header was observed on any response. Any throttling is applied silently by the Cloudflare edge in front of the origin. robots.txt asks crawlers for a Crawl-delay of 10 seconds, which is guidance to crawlers, not a machine-enforced API rate limit. caching: cache_control: 'max-age=600, must-revalidate on wp/v2 collection reads' edge: Cloudflare x_robots_tag: 'noindex on /wp-json/ responses' batching: endpoint: /batch/v1 note: WordPress core batch endpoint is registered on this host; it requires authentication.