# Medium > Medium is an online publishing platform. Its REST API (api.medium.com/v1) lets an existing > integration publish posts to a user's profile or publication, upload images, and read basic > profile and publication data. IMPORTANT: Medium states the API is no longer supported and does not > accept new integrations; existing tokens continue to work. This file was GENERATED by API Evangelist from the public artifacts in the api-evangelist/medium profile. Medium does not publish an llms.txt: /llms.txt returns HTTP 403 (Cloudflare bot challenge) on medium.com and HTTP 404 on api.medium.com, probed 2026-09-17. ## Status - The Medium API is no longer supported: https://github.com/Medium/medium-api-docs - No new integrations are accepted; browser-based OAuth is for existing integrations only. - The documentation repository was archived by Medium on GitHub (last push 2023-03-02). - Every first-party SDK carries a "no longer supported or maintained" banner. - medium.com/robots.txt disallows ClaudeBot, GPTBot, Bytespider, Amazonbot, Applebot-Extended, FacebookBot, GoogleOther and meta-externalagent from the whole site except a handful of marketing pages. Respect it. ## Documentation - API documentation (archived): https://github.com/Medium/medium-api-docs - Authentication: https://github.com/Medium/medium-api-docs#2-authentication - Resources reference: https://github.com/Medium/medium-api-docs#3-resources - Testing: https://github.com/Medium/medium-api-docs#4-testing - Status page: https://status.medium.com/ - GitHub organisation: https://github.com/Medium ## API Base URL: https://api.medium.com/v1 Authorization server: https://medium.com/m/oauth Auth: `Authorization: Bearer ` — a self-issued integration token, or an OAuth2 access token valid for 60 days refreshed at POST /v1/tokens. OAuth scopes: basicProfile, listPublications, publishPost, uploadImage (uploadImage is extended and requires Medium's prior permission). Operations (8): - GET /v1/me getAuthenticatedUser - GET /v1/users/{userId}/publications listUserPublications - GET /v1/publications/{publicationId}/contributors listPublicationContributors - POST /v1/users/{authorId}/posts createUserPost - POST /v1/publications/{publicationId}/posts createPublicationPost - POST /v1/images uploadImage - POST /v1/tokens exchangeAuthorizationCode - POST /v1/tokens/refresh refreshAccessToken ## Runtime semantics an agent must know before calling - NO SANDBOX. Medium's own docs: "We do not have a sandbox environment yet ... These endpoints will perform actions on production data on medium.com. Please test with care." - NO IDEMPOTENCY KEY. Retrying createUserPost publishes a duplicate post. - NO REVERSAL. There is no delete, unpublish, update or archive operation anywhere in the contract. A published post can only be removed by a human in the web UI. Default publishStatus to `draft`. - NO PAGINATION. listUserPublications is capped at 200 non-authored publications with no cursor. - NO RATE LIMITS PUBLISHED, and no RateLimit-*/Retry-After headers documented. - Errors are NOT RFC 9457. The envelope is {"errors":[{"message":"...","code":}]}; the numeric codes are undocumented. Successes are wrapped in {"data": ...}. ## Machine-readable artifacts in this profile - OpenAPI (6 specs, one per resource): openapi/ - Authentication: authentication/medium-authentication.yml - OAuth scopes: scopes/medium-scopes.yml - Conventions (idempotency, reversibility, pagination): conventions/medium-conventions.yml - Error catalog: errors/medium-problem-types.yml - Lifecycle and deprecation evidence: lifecycle/medium-lifecycle.yml - Data model: data-model/medium-data-model.yml - Packages / SDKs with dated registry evidence: packages/medium-packages.yml - Conformance: conformance/medium-conformance.yml - Well-known probe results (all misses): well-known/medium-well-known.yml - Agent skills: skills/ ## Not published by Medium No llms.txt, no AsyncAPI, no webhooks, no GraphQL, no gRPC/protobuf, no WSDL, no MCP server, no A2A agent card, no security.txt, no OpenID/OAuth discovery metadata, no api-catalog, no CLI, no published API pricing or plans, no API changelog, no trust centre and no bug bounty programme.