# Lish > Lish is a corporate catering and workplace food service company serving Seattle and the Bellevue/Eastside area, including Redmond and Kirkland, Washington. It connects employers with a curated roster of local partner chefs and handles menu curation, ordering, delivery and setup. The company reports more than 3,000,000 meals served, 100+ curated menus from dozens of partner chefs, an average meal rating of 4.6 stars, and 97.8% of catering orders delivered on time within a 20-minute window. This file was GENERATED by the API Evangelist enrichment pipeline on 2026-07-19. Lish does not publish an llms.txt of its own — https://www.lishfood.com/llms.txt returns 404. ## What Lish sells - Subscription Catering — recurring, managed workplace meal programs - PopUp Restaurants — rotating partner restaurants that employees buy from directly - Catering On-Demand — one-off orders - Occasion catering — breakfast, lunch, box lunch, happy hour, meetings and events Dietary accommodation (gluten-free, vegetarian, vegan, dairy-free) is a stated focus. Lish describes an admin dashboard, budget tracking, GPS delivery tracking, Google Calendar and Outlook menu visibility, and Slack notifications for team meal feedback. These are end-user product integrations, not a developer platform. ## API status — read this first Lish operates NO developer program. There is: - no product API for catering, ordering, menus or delivery - no developer portal, no API documentation, no SDKs, no CLI - no OpenAPI or AsyncAPI description published by Lish - no MCP server - no webhooks or event surface - no status page, no changelog, no rate-limit policy, no support channel for developers - no /.well-known/ documents of any kind (all probed paths return 404) - api.lishfood.com, developers.lishfood.com and status.lishfood.com do not resolve The ONE genuinely public, self-describing HTTP API is the WordPress REST API that backs the marketing site and blog. It exists as a byproduct of the CMS. It is useful for reading Lish content and nothing else. Treat it as a content feed with no stability contract — routes can change or be locked down with any site update. ## Public content API - Route index: https://www.lishfood.com/wp-json/ (348 routes across 21 namespaces) - Core content base: https://www.lishfood.com/wp-json/wp/v2 - Upstream reference: https://developer.wordpress.org/rest-api/ - Auth: none required for the documented read surface; the index reports an empty `authentication` object. Privileged reads and all writes return 401. Content available as of 2026-07-19: 28 blog posts, 60 pages, 4 categories. Useful operations: - GET /wp/v2/search?search={q} — cross-entity search, returns {id,title,url,type,subtype} stubs. Best entry point. - GET /wp/v2/posts — blog posts, newest first - GET /wp/v2/posts/{id} — one post - GET /wp/v2/pages?slug={slug} — fetch a known marketing page directly - GET /wp/v2/pages/{id} — one page - GET /wp/v2/categories , /wp/v2/tags — taxonomy terms with post counts - GET /wp/v2/media/{id} — media item and its source_url Where the substantive business content actually lives (pages, not posts): - /pages/about — company background - /pages/faq — frequently asked questions - /pages/lish-technology — platform and integrations description - /pages/our-chefs — partner chef roster - /pages/why-workplace-food — value proposition - /pages/subscription-catering , /pages/popups , /pages/order-catering — service lines - /pages/lunch-catering , /pages/breakfast-catering , /pages/happy-hour-catering , /pages/box-lunch-catering , /pages/meeting-event-catering — occasion pages - /pages/testimonials , /pages/lish-cares , /pages/chef-signup , /pages/catering-drivers - /pages/terms , /pages/privacy , /pages/contact-us ## Rules for calling this API 1. Paginate with page and per_page (max 100). Read X-WP-Total and X-WP-TotalPages, or follow the RFC 8288 Link rel="next" header. 2. Requesting a page past the last returns HTTP 400 rest_post_invalid_page_number — NOT an empty array. This is the most common integration mistake. Stop on the absence of rel="next". 3. Always send _fields to trim the response. Full post objects embed rendered HTML and will exhaust a context window on a list call. 4. Use _embed to inline author, featured media and terms instead of making N+1 calls. 5. Errors use the WordPress envelope {"code","message","data":{"status"}} with media type application/json. This is NOT RFC 9457 problem+json. Branch on `code`, never on `message`. 6. Verified error codes: rest_post_invalid_id (404), rest_forbidden (401), rest_forbidden_context (401), rest_invalid_param (400), rest_post_invalid_page_number (400), rest_no_route (404). 7. Do not send context=edit — it returns 401 rest_forbidden_context anonymously. 8. There is no idempotency-key mechanism and no rate-limit headers. Responses are cached (max-age=600) behind WP Engine and Amazon CloudFront; be polite. 9. Origin gotcha: requests work against www.lishfood.com, but the install reports its home as wordpress.lishfood.com and emits THAT origin in Link headers, _links relations and resource `link` fields. Rewrite the origin before showing URLs to a user, or you will surface a host that is not the public site. 10. Strip or sanitize content.rendered HTML before passing it to a model. ## Company links - Website: https://www.lishfood.com - Blog: https://www.lishfood.com/blog - About: https://www.lishfood.com/pages/about - FAQ: https://www.lishfood.com/pages/faq - Get started: https://www.lishfood.com/pages/get-started - Account login: https://www.lishfood.com/account/ - Contact: https://www.lishfood.com/pages/contact-us — catering@lishfood.com - Terms: https://www.lishfood.com/pages/terms - Privacy: https://www.lishfood.com/pages/privacy - Ordering application: https://app.lishfood.com ## Company facts - Sector: corporate catering / workplace food service / food delivery - Service area: Seattle and Bellevue/Eastside, Washington, USA (incl. Redmond, Kirkland) - Investor: 500 Global (surfaced via 500 Global portfolio) - Site stack: WordPress on WP Engine behind Amazon CloudFront; ordering app on Heroku - TLS 1.3, HSTS max-age=31536000, SPF and DMARC present (DMARC policy p=none), no DNSSEC, no CAA records, no security.txt, no published compliance program ## API Evangelist artifacts in this repo - apis.yml — APIs.json profile - openapi/lish-wordpress-openapi.json — OpenAPI 3.1 derived from the live route index - overlays/lish-wordpress-overlay.yaml — our enhancements over that spec - conventions/lish-conventions.yml — pagination, auth, errors, caching semantics - errors/lish-problem-types.yml — verified error catalog - lifecycle/lish-lifecycle.yml — versioning, deprecation, support posture - authentication/lish-authentication.yml — auth profile - conformance/lish-conformance.yml — standards conformance assessment - data-model/lish-data-model.yml — entity graph - security/lish-domain-security.yml — TLS/HSTS/DNS posture - well-known/lish-well-known.yml — probe record (all 404) - mcp/lish-mcp.yml — candidate MCP tool surface (nothing published by Lish) - skills/ — packaged Agent Skills for the content API