generated: '2026-08-04' method: derived source: >- openapi/orionis-biosciences-content-openapi.yml + live response headers observed on https://orionisbio.com/wp-json/ on 2026-08-04 summary: >- Orionis Biosciences publishes no API conventions documentation, because it publishes no developer program. The conventions below are those of the WordPress REST API as deployed on orionisbio.com, observed live. The upstream contract is the WordPress REST API Handbook (https://developer.wordpress.org/rest-api/), not an Orionis document. base_url: https://orionisbio.com/wp-json authentication: anonymous_read: true style: none-for-read write_schemes: - WordPress Application Passwords over HTTP Basic (RFC 7617) - cookie authentication with an X-WP-Nonce header (first-party browser context only) authorization_endpoint: https://orionisbio.com/wp-admin/authorize-application.php advertised_in: /wp-json/ root document `authentication` block detail: authentication/orionis-biosciences-authentication.yml idempotency: supported: false note: >- No idempotency key header or parameter is documented or registered. The WordPress REST API has no idempotency contract; POST retries create duplicate records. Write access is not available to the public on this host in any case. pagination: style: page-number parameters: - name: page default: 1 minimum: 1 - name: per_page default: 10 minimum: 1 maximum: 100 - name: offset note: supported on post-type collections as an alternative to page response_headers: - name: X-WP-Total description: Total number of items in the collection. Observed value 22 on /wp/v2/posts. - name: X-WP-TotalPages description: Total number of pages at the current per_page. Observed value 11 at per_page=2. link_header: supported: true rels: [prev, next] example: '; rel="next"' observed: true field_selection: sparse_fields: parameter: _fields description: Comma-separated list restricting the properties returned per record. observed: true embedding: parameter: _embed description: >- Inlines linked resources (author, featured media, terms) into an `_embedded` object using the `_links` relations present on every record. envelope: parameter: _envelope description: Wraps the response body, status and headers into a single JSON object. filtering_and_sorting: common_parameters: - search - include - exclude - slug - status - order - orderby - after - before - modified_after - modified_before - categories - tags - author note: Enumerated verbatim per route in openapi/orionis-biosciences-content-openapi.yml. metadata: supported: true field: meta note: >- Records also carry an `acf` field (Advanced Custom Fields) and `yoast_head` / `yoast_head_json` SEO blocks — plugin-added properties, not WordPress core. request_tracing: request_id_header: x-gateway-request-id note: >- Set by the Sucuri Cloudproxy gateway in front of the origin, not by WordPress. Also returns x-sucuri-id, x-gateway-cache-key and x-gateway-cache-status (HIT/MISS/BYPASS). versioning: scheme: uri-path-namespace current: wp/v2 note: >- Namespace versioning inherited from WordPress core (`/wp-json//`), not an Orionis versioning policy. No version negotiation header. See lifecycle/orionis-biosciences-lifecycle.yml. error_envelope: format: wordpress-rest-error rfc9457: false shape: '{ "code": "", "message": "", "data": { "status": } }' caveat: >- A firewall 403 from the Sucuri gateway returns an HTML page rather than the JSON envelope — clients must not assume JSON on every non-2xx. detail: errors/orionis-biosciences-problem-types.yml rate_limiting: documented: false headers_observed: [] note: >- No RateLimit / X-RateLimit / Retry-After headers were returned on any observed request. Traffic passes through a Sucuri Cloudproxy WAF which may throttle or challenge without advertising limits, so consumers should back off on 403 and 429 defensively. caching: headers_observed: [x-gateway-cache-status, x-sucuri-cache, vary] note: >- Edge caching is performed by the gateway. No ETag or Cache-Control was returned on the REST collections observed; conditional requests are not supported. cors: access_control_allow_headers: [Authorization, X-WP-Nonce, Content-Disposition, Content-MD5, Content-Type] access_control_expose_headers: [X-WP-Total, X-WP-TotalPages, Link] observed: true namespaces_on_host: content: - wp/v2 - oembed/1.0 agent: - namespace: wp-abilities/v1 status: gated anonymous_status: 401 note: >- The WordPress Abilities API — the registry a WordPress MCP adapter exposes as agent tools. Registered on this host but returns rest_forbidden anonymously, so the ability set could not be enumerated. vendor_admin_excluded_from_openapi: - yoast/v1 - wpaas/v1 - akismet/v1 - objectcache/v1 - ai1wm/v1 - two-factor - wp-site-designer/v1 - gdl/v1 - wp-site-health/v1 - wp-block-editor/v1 note: >- These are real registered namespaces but are third-party plugin and managed-hosting control planes rather than Orionis Biosciences content, so they are excluded from the derived OpenAPI. The complete verbatim route index is preserved at openapi/_original/orionis-biosciences-wp-json-index.json. cross_links: authentication: authentication/orionis-biosciences-authentication.yml errors: errors/orionis-biosciences-problem-types.yml lifecycle: lifecycle/orionis-biosciences-lifecycle.yml data_model: data-model/orionis-biosciences-data-model.yml conformance: conformance/orionis-biosciences-conformance.yml