openapi: 3.2.0 info: title: IgGenix Content API (WordPress REST wp/v2) Users API version: wp/v2 summary: 'Public read surface of iggenix.com content: press releases, peer-reviewed publications, conference abstracts, careers postings, pages, media, taxonomies and site search.' description: 'IgGenix publishes iggenix.com on WordPress (hosted on WP Engine as iggenix.wpengine.com), which exposes the WordPress REST API at https://iggenix.com/wp-json/. The wp/v2 namespace is anonymously readable and returns the company''s press releases, peer-reviewed publications, conference abstracts, a careers post type, pages, media library, taxonomies and a site-wide search endpoint as JSON. This document was DERIVED mechanically by API Evangelist from the route-discovery document served at https://iggenix.com/wp-json/ on 2026-08-22 — every path, method, parameter, type, enum and default below is taken verbatim from that descriptor, and each collection was confirmed with an anonymous GET. IgGenix does not publish an OpenAPI definition of its own, and this is not a product API: it is the content API the CMS exposes. Write operations exist on these routes but require authentication (WordPress Application Passwords over HTTP Basic); GET /wp/v2/settings and the wp-abilities/v1 registry return 401 rest_forbidden anonymously. NOTE ON THE SITE ITSELF: on the date of derivation the HTML front end at iggenix.com served another company''s home page (iECURE, canonical https://iecure.com/) for the site root and for every unmatched path, including /privacy-policy/ and /the-iggenix-team/. The REST API and the custom-post-type archives (/publications/, /abstracts/, /pressreleases/) are unambiguously IgGenix''s — the route index reports name "IgGenix" and returns IGNX001 peanut-allergy content — so this contract is attributed to IgGenix. The HTML routing defect is recorded in review.yml.' contact: name: IgGenix url: https://iggenix.com/ email: info@IgGenix.com x-derived-by: API Evangelist enrichment pipeline x-derived-from: https://iggenix.com/wp-json/ x-derived-on: '2026-08-22' x-provider-published: false servers: - url: https://iggenix.com/wp-json description: Production tags: - name: Users paths: /wp/v2/users: get: operationId: getUsers summary: GET /wp/v2/users tags: - Users parameters: - name: capabilities in: query required: false schema: type: array items: type: string description: Limit result set to users matching at least one specific capability provided. Accepts csv list or single capability. - name: context in: query required: false schema: type: string enum: - view - embed - edit default: view description: Scope under which the request is made; determines fields present in response. - name: exclude in: query required: false schema: type: array default: [] items: type: integer description: Ensure result set excludes specific IDs. - name: has_published_posts in: query required: false schema: type: boolean description: Limit result set to users who have published posts. - name: include in: query required: false schema: type: array default: [] items: type: integer description: Limit result set to specific IDs. - name: offset in: query required: false schema: type: integer description: Offset the result set by a specific number of items. - name: order in: query required: false schema: type: string enum: - asc - desc default: asc description: Order sort attribute ascending or descending. - name: orderby in: query required: false schema: type: string enum: - id - include - name - registered_date - slug - include_slugs - email - url default: name description: Sort collection by user attribute. - name: page in: query required: false schema: type: integer default: 1 minimum: 1 description: Current page of the collection. - name: per_page in: query required: false schema: type: integer default: 10 minimum: 1 maximum: 100 description: Maximum number of items to be returned in result set. - name: roles in: query required: false schema: type: array items: type: string description: Limit result set to users matching at least one specific role provided. Accepts csv list or single role. - name: search in: query required: false schema: type: string description: Limit results to those matching a string. - name: search_columns in: query required: false schema: type: array default: [] items: type: string enum: - email - name - id - username - slug description: Array of column names to be searched. - name: slug in: query required: false schema: type: array items: type: string description: Limit result set to users with one or more specific slugs. - name: who in: query required: false schema: type: string enum: - authors description: Limit result set to users who are considered authors. responses: '200': description: Success. Collection responses also carry X-WP-Total and X-WP-TotalPages headers and an RFC 8288 Link header for pagination. headers: X-WP-Total: description: Total number of items in the unpaginated collection. schema: type: integer X-WP-TotalPages: description: Total number of pages available at the current per_page. schema: type: integer Link: description: RFC 8288 next/prev pagination links. schema: type: string content: application/json: schema: type: object additionalProperties: true '400': &id001 $ref: '#/components/responses/BadRequest' '404': &id002 $ref: '#/components/responses/NotFound' security: - {} - applicationPassword: [] post: operationId: postUsers summary: POST /wp/v2/users tags: - Users requestBody: required: true content: application/json: schema: type: object properties: description: type: string description: Description of the user. email: type: string format: email description: The email address for the user. first_name: type: string description: First name for the user. last_name: type: string description: Last name for the user. locale: type: string enum: - '' - en_US description: Locale for the user. meta: type: object additionalProperties: true description: Meta fields. name: type: string description: Display name for the user. nickname: type: string description: The nickname for the user. password: type: string description: Password for the user (never included). roles: type: array items: type: string description: Roles assigned to the user. slug: type: string description: An alphanumeric identifier for the user. url: type: string format: uri description: URL of the user. username: type: string description: Login name for the user. required: - email - password - username responses: '200': description: Success. Collection responses also carry X-WP-Total and X-WP-TotalPages headers and an RFC 8288 Link header for pagination. headers: X-WP-Total: description: Total number of items in the unpaginated collection. schema: type: integer X-WP-TotalPages: description: Total number of pages available at the current per_page. schema: type: integer Link: description: RFC 8288 next/prev pagination links. schema: type: string content: application/json: schema: type: object additionalProperties: true '400': *id001 '401': &id003 $ref: '#/components/responses/Unauthorized' '403': &id004 $ref: '#/components/responses/Forbidden' '404': *id002 security: - applicationPassword: [] /wp/v2/users/{id}: get: operationId: getUsersId summary: GET /wp/v2/users/{id} tags: - Users parameters: - name: id in: path required: true schema: type: integer x-wp-pattern: '[\d]+' - name: context in: query required: false schema: type: string enum: - view - embed - edit default: view description: Scope under which the request is made; determines fields present in response. - name: id in: query required: false schema: type: integer description: Unique identifier for the user. responses: '200': description: Success. Collection responses also carry X-WP-Total and X-WP-TotalPages headers and an RFC 8288 Link header for pagination. headers: X-WP-Total: description: Total number of items in the unpaginated collection. schema: type: integer X-WP-TotalPages: description: Total number of pages available at the current per_page. schema: type: integer Link: description: RFC 8288 next/prev pagination links. schema: type: string content: application/json: schema: type: object additionalProperties: true '400': *id001 '404': *id002 security: - {} - applicationPassword: [] post: operationId: postUsersId summary: POST /wp/v2/users/{id} tags: - Users parameters: - name: id in: path required: true schema: type: integer x-wp-pattern: '[\d]+' requestBody: required: true content: application/json: schema: type: object properties: description: type: string description: Description of the user. email: type: string format: email description: The email address for the user. first_name: type: string description: First name for the user. id: type: integer description: Unique identifier for the user. last_name: type: string description: Last name for the user. locale: type: string enum: &id005 - '' - en_US description: Locale for the user. meta: type: object additionalProperties: true description: Meta fields. name: type: string description: Display name for the user. nickname: type: string description: The nickname for the user. password: type: string description: Password for the user (never included). roles: type: array items: type: string description: Roles assigned to the user. slug: type: string description: An alphanumeric identifier for the user. url: type: string format: uri description: URL of the user. username: type: string description: Login name for the user. responses: '200': description: Success. Collection responses also carry X-WP-Total and X-WP-TotalPages headers and an RFC 8288 Link header for pagination. headers: X-WP-Total: description: Total number of items in the unpaginated collection. schema: type: integer X-WP-TotalPages: description: Total number of pages available at the current per_page. schema: type: integer Link: description: RFC 8288 next/prev pagination links. schema: type: string content: application/json: schema: type: object additionalProperties: true '400': *id001 '401': *id003 '403': *id004 '404': *id002 security: - applicationPassword: [] put: operationId: putUsersId summary: PUT /wp/v2/users/{id} tags: - Users parameters: - name: id in: path required: true schema: type: integer x-wp-pattern: '[\d]+' requestBody: required: true content: application/json: schema: type: object properties: description: type: string description: Description of the user. email: type: string format: email description: The email address for the user. first_name: type: string description: First name for the user. id: type: integer description: Unique identifier for the user. last_name: type: string description: Last name for the user. locale: type: string enum: *id005 description: Locale for the user. meta: type: object additionalProperties: true description: Meta fields. name: type: string description: Display name for the user. nickname: type: string description: The nickname for the user. password: type: string description: Password for the user (never included). roles: type: array items: type: string description: Roles assigned to the user. slug: type: string description: An alphanumeric identifier for the user. url: type: string format: uri description: URL of the user. username: type: string description: Login name for the user. responses: '200': description: Success. Collection responses also carry X-WP-Total and X-WP-TotalPages headers and an RFC 8288 Link header for pagination. headers: X-WP-Total: description: Total number of items in the unpaginated collection. schema: type: integer X-WP-TotalPages: description: Total number of pages available at the current per_page. schema: type: integer Link: description: RFC 8288 next/prev pagination links. schema: type: string content: application/json: schema: type: object additionalProperties: true '400': *id001 '401': *id003 '403': *id004 '404': *id002 security: - applicationPassword: [] patch: operationId: patchUsersId summary: PATCH /wp/v2/users/{id} tags: - Users parameters: - name: id in: path required: true schema: type: integer x-wp-pattern: '[\d]+' requestBody: required: true content: application/json: schema: type: object properties: description: type: string description: Description of the user. email: type: string format: email description: The email address for the user. first_name: type: string description: First name for the user. id: type: integer description: Unique identifier for the user. last_name: type: string description: Last name for the user. locale: type: string enum: *id005 description: Locale for the user. meta: type: object additionalProperties: true description: Meta fields. name: type: string description: Display name for the user. nickname: type: string description: The nickname for the user. password: type: string description: Password for the user (never included). roles: type: array items: type: string description: Roles assigned to the user. slug: type: string description: An alphanumeric identifier for the user. url: type: string format: uri description: URL of the user. username: type: string description: Login name for the user. responses: '200': description: Success. Collection responses also carry X-WP-Total and X-WP-TotalPages headers and an RFC 8288 Link header for pagination. headers: X-WP-Total: description: Total number of items in the unpaginated collection. schema: type: integer X-WP-TotalPages: description: Total number of pages available at the current per_page. schema: type: integer Link: description: RFC 8288 next/prev pagination links. schema: type: string content: application/json: schema: type: object additionalProperties: true '400': *id001 '401': *id003 '403': *id004 '404': *id002 security: - applicationPassword: [] delete: operationId: deleteUsersId summary: DELETE /wp/v2/users/{id} tags: - Users parameters: - name: id in: path required: true schema: type: integer x-wp-pattern: '[\d]+' - name: force in: query required: false schema: type: boolean default: false description: Required to be true, as users do not support trashing. - name: id in: query required: false schema: type: integer description: Unique identifier for the user. - name: reassign in: query required: true schema: type: integer description: Reassign the deleted user's posts and links to this user ID. responses: '200': description: Success. Collection responses also carry X-WP-Total and X-WP-TotalPages headers and an RFC 8288 Link header for pagination. headers: X-WP-Total: description: Total number of items in the unpaginated collection. schema: type: integer X-WP-TotalPages: description: Total number of pages available at the current per_page. schema: type: integer Link: description: RFC 8288 next/prev pagination links. schema: type: string content: application/json: schema: type: object additionalProperties: true '400': *id001 '401': *id003 '403': *id004 '404': *id002 security: - applicationPassword: [] /wp/v2/users/me: get: operationId: getUsersMe summary: GET /wp/v2/users/me tags: - Users parameters: - name: context in: query required: false schema: type: string enum: - view - embed - edit default: view description: Scope under which the request is made; determines fields present in response. responses: '200': description: Success. Collection responses also carry X-WP-Total and X-WP-TotalPages headers and an RFC 8288 Link header for pagination. headers: X-WP-Total: description: Total number of items in the unpaginated collection. schema: type: integer X-WP-TotalPages: description: Total number of pages available at the current per_page. schema: type: integer Link: description: RFC 8288 next/prev pagination links. schema: type: string content: application/json: schema: type: object additionalProperties: true '400': *id001 '404': *id002 security: - {} - applicationPassword: [] post: operationId: postUsersMe summary: POST /wp/v2/users/me tags: - Users requestBody: required: true content: application/json: schema: type: object properties: description: type: string description: Description of the user. email: type: string format: email description: The email address for the user. first_name: type: string description: First name for the user. last_name: type: string description: Last name for the user. locale: type: string enum: &id006 - '' - en_US description: Locale for the user. meta: type: object additionalProperties: true description: Meta fields. name: type: string description: Display name for the user. nickname: type: string description: The nickname for the user. password: type: string description: Password for the user (never included). roles: type: array items: type: string description: Roles assigned to the user. slug: type: string description: An alphanumeric identifier for the user. url: type: string format: uri description: URL of the user. username: type: string description: Login name for the user. responses: '200': description: Success. Collection responses also carry X-WP-Total and X-WP-TotalPages headers and an RFC 8288 Link header for pagination. headers: X-WP-Total: description: Total number of items in the unpaginated collection. schema: type: integer X-WP-TotalPages: description: Total number of pages available at the current per_page. schema: type: integer Link: description: RFC 8288 next/prev pagination links. schema: type: string content: application/json: schema: type: object additionalProperties: true '400': *id001 '401': *id003 '403': *id004 '404': *id002 security: - applicationPassword: [] put: operationId: putUsersMe summary: PUT /wp/v2/users/me tags: - Users requestBody: required: true content: application/json: schema: type: object properties: description: type: string description: Description of the user. email: type: string format: email description: The email address for the user. first_name: type: string description: First name for the user. last_name: type: string description: Last name for the user. locale: type: string enum: *id006 description: Locale for the user. meta: type: object additionalProperties: true description: Meta fields. name: type: string description: Display name for the user. nickname: type: string description: The nickname for the user. password: type: string description: Password for the user (never included). roles: type: array items: type: string description: Roles assigned to the user. slug: type: string description: An alphanumeric identifier for the user. url: type: string format: uri description: URL of the user. username: type: string description: Login name for the user. responses: '200': description: Success. Collection responses also carry X-WP-Total and X-WP-TotalPages headers and an RFC 8288 Link header for pagination. headers: X-WP-Total: description: Total number of items in the unpaginated collection. schema: type: integer X-WP-TotalPages: description: Total number of pages available at the current per_page. schema: type: integer Link: description: RFC 8288 next/prev pagination links. schema: type: string content: application/json: schema: type: object additionalProperties: true '400': *id001 '401': *id003 '403': *id004 '404': *id002 security: - applicationPassword: [] patch: operationId: patchUsersMe summary: PATCH /wp/v2/users/me tags: - Users requestBody: required: true content: application/json: schema: type: object properties: description: type: string description: Description of the user. email: type: string format: email description: The email address for the user. first_name: type: string description: First name for the user. last_name: type: string description: Last name for the user. locale: type: string enum: *id006 description: Locale for the user. meta: type: object additionalProperties: true description: Meta fields. name: type: string description: Display name for the user. nickname: type: string description: The nickname for the user. password: type: string description: Password for the user (never included). roles: type: array items: type: string description: Roles assigned to the user. slug: type: string description: An alphanumeric identifier for the user. url: type: string format: uri description: URL of the user. username: type: string description: Login name for the user. responses: '200': description: Success. Collection responses also carry X-WP-Total and X-WP-TotalPages headers and an RFC 8288 Link header for pagination. headers: X-WP-Total: description: Total number of items in the unpaginated collection. schema: type: integer X-WP-TotalPages: description: Total number of pages available at the current per_page. schema: type: integer Link: description: RFC 8288 next/prev pagination links. schema: type: string content: application/json: schema: type: object additionalProperties: true '400': *id001 '401': *id003 '403': *id004 '404': *id002 security: - applicationPassword: [] delete: operationId: deleteUsersMe summary: DELETE /wp/v2/users/me tags: - Users parameters: - name: force in: query required: false schema: type: boolean default: false description: Required to be true, as users do not support trashing. - name: reassign in: query required: true schema: type: integer description: Reassign the deleted user's posts and links to this user ID. responses: '200': description: Success. Collection responses also carry X-WP-Total and X-WP-TotalPages headers and an RFC 8288 Link header for pagination. headers: X-WP-Total: description: Total number of items in the unpaginated collection. schema: type: integer X-WP-TotalPages: description: Total number of pages available at the current per_page. schema: type: integer Link: description: RFC 8288 next/prev pagination links. schema: type: string content: application/json: schema: type: object additionalProperties: true '400': *id001 '401': *id003 '403': *id004 '404': *id002 security: - applicationPassword: [] components: securitySchemes: applicationPassword: type: http scheme: basic description: WordPress Application Passwords over HTTP Basic. Advertised by the site's own route index at https://iggenix.com/wp-json/ under authentication.application-passwords, with the authorization endpoint at https://iggenix.com/wp-admin/authorize-application.php. Required only for write operations and for the authenticated-read routes (/wp/v2/settings, /wp-abilities/v1/*); the content read surface is anonymous. responses: BadRequest: description: Invalid parameter (rest_invalid_param). content: application/json: schema: $ref: '#/components/schemas/WpError' Unauthorized: description: Authentication required or rejected (rest_forbidden / rest_not_logged_in). Observed verbatim on GET /wp/v2/settings and GET /wp-abilities/v1/abilities. content: application/json: schema: $ref: '#/components/schemas/WpError' Forbidden: description: Authenticated but not permitted (rest_cannot_view / rest_forbidden). content: application/json: schema: $ref: '#/components/schemas/WpError' NotFound: description: No route or resource matched (rest_no_route / rest_post_invalid_id). content: application/json: schema: $ref: '#/components/schemas/WpError' schemas: WpError: type: object description: The WordPress REST API error envelope (WP_Error serialized to JSON). Observed verbatim from this host. properties: code: type: string description: Machine-readable error slug, e.g. rest_post_invalid_id. message: type: string description: Human-readable message. data: type: object properties: status: type: integer description: HTTP status code, repeated in the body. params: type: object additionalProperties: true details: type: object additionalProperties: true additionalProperties: true required: - code - message - data example: code: rest_post_invalid_id message: Invalid post ID. data: status: 404 RenderedText: type: object description: WordPress renders text fields as an object with a rendered HTML string. properties: rendered: type: string description: HTML-rendered value. raw: type: string description: Unrendered source; present only for authenticated context=edit. Links: type: object description: HAL-style _links hypermedia block returned on every resource. additionalProperties: true