openapi: 3.2.0 info: title: Virtual Incision People API (WordPress REST wp/v2) version: wp/v2 summary: Site authors — the leadership and communications bylines behind newsroom posts. description: 'Virtual Incision publishes virtualincision.com on WordPress (WP Engine), which exposes the WordPress REST API at https://virtualincision.com/wp-json/. The `wp/v2` namespace is anonymously readable and returns the company newsroom, MIRA and miniRAS marketing pages, leadership profiles, events, job postings and the media library as JSON. This document was DERIVED mechanically by API Evangelist from the route-discovery document served at https://virtualincision.com/wp-json/ and the per-collection `OPTIONS` item schemas, both fetched on 2026-09-04 — every path, method, parameter and schema below is taken verbatim from what the host served. Virtual Incision does not publish an OpenAPI definition of its own, and this is NOT a product API: MIRA, the miniaturized robotic-assisted surgery system, has no public API. This is the content API the site CMS exposes. Write operations exist on these routes but require WordPress authentication.' contact: name: Virtual Incision url: https://virtualincision.com/ x-derived-by: API Evangelist enrichment pipeline x-derived-from: https://virtualincision.com/wp-json/ x-derived-on: '2026-09-04' x-provider-published: false servers: - url: https://virtualincision.com/wp-json description: Production tags: - name: People description: Site authors — the leadership and communications bylines behind newsroom posts. security: - {} paths: /wp/v2/users: get: operationId: getUsers summary: GET /wp/v2/users description: Anonymous read — observed HTTP 200 without credentials on 2026-09-04. tags: - People responses: '200': description: Success. content: application/json: schema: type: array items: $ref: '#/components/schemas/Users' '400': description: Invalid parameter. content: application/json: schema: $ref: '#/components/schemas/WPError' '401': description: Authentication required or insufficient capability (`rest_forbidden`). content: application/json: schema: $ref: '#/components/schemas/WPError' '404': description: No route or resource matched (`rest_no_route` / `rest_post_invalid_id`). content: application/json: schema: $ref: '#/components/schemas/WPError' security: - {} - applicationPassword: [] parameters: - name: context in: query required: false schema: type: string enum: - view - embed - edit default: view description: Scope under which the request is made; determines fields present in response. - name: page in: query required: false schema: type: integer default: 1 minimum: 1 description: Current page of the collection. - name: per_page in: query required: false schema: type: integer default: 10 minimum: 1 maximum: 100 description: Maximum number of items to be returned in result set. - name: search in: query required: false schema: type: string description: Limit results to those matching a string. - name: exclude in: query required: false schema: type: array default: [] items: type: integer description: Ensure result set excludes specific IDs. - name: include in: query required: false schema: type: array default: [] items: type: integer description: Limit result set to specific IDs. - name: offset in: query required: false schema: type: integer description: Offset the result set by a specific number of items. - name: order in: query required: false schema: type: string enum: - asc - desc default: asc description: Order sort attribute ascending or descending. - name: orderby in: query required: false schema: type: string enum: - id - include - name - registered_date - slug - include_slugs - email - url default: name description: Sort collection by user attribute. - name: slug in: query required: false schema: type: array items: type: string description: Limit result set to users with one or more specific slugs. - name: roles in: query required: false schema: type: array items: type: string description: Limit result set to users matching at least one specific role provided. Accepts csv list or single role. - name: capabilities in: query required: false schema: type: array items: type: string description: Limit result set to users matching at least one specific capability provided. Accepts csv list or single capability. - name: who in: query required: false schema: type: string enum: - authors description: Limit result set to users who are considered authors. - name: has_published_posts in: query required: false schema: type: - boolean - array items: type: string enum: post: post page: page attachment: attachment nav_menu_item: nav_menu_item wp_block: wp_block wp_template: wp_template wp_template_part: wp_template_part wp_global_styles: wp_global_styles wp_navigation: wp_navigation wp_font_family: wp_font_family wp_font_face: wp_font_face event: event jobpost: jobpost portfolio: portfolio rank_math_schema: rank_math_schema description: Limit result set to users who have published posts. - name: search_columns in: query required: false schema: type: array default: [] items: type: string enum: - email - name - id - username - slug description: Array of column names to be searched. post: operationId: createUsers summary: POST /wp/v2/users description: Write operation. Requires WordPress authentication (Application Password over HTTP Basic, or a logged-in cookie plus X-WP-Nonce); anonymous callers receive HTTP 401. tags: - People responses: '200': description: Success. content: application/json: schema: type: object '400': description: Invalid parameter. content: application/json: schema: $ref: '#/components/schemas/WPError' '401': description: Authentication required or insufficient capability (`rest_forbidden`). content: application/json: schema: $ref: '#/components/schemas/WPError' '404': description: No route or resource matched (`rest_no_route` / `rest_post_invalid_id`). content: application/json: schema: $ref: '#/components/schemas/WPError' security: - applicationPassword: [] - cookieNonce: [] requestBody: required: false content: application/json: schema: type: object properties: username: type: string description: Login name for the user. name: type: string description: Display name for the user. first_name: type: string description: First name for the user. last_name: type: string description: Last name for the user. email: type: string format: email description: The email address for the user. url: type: string format: uri description: URL of the user. description: type: string description: Description of the user. locale: type: string enum: - '' - en_US description: Locale for the user. nickname: type: string description: The nickname for the user. slug: type: string description: An alphanumeric identifier for the user. roles: type: array items: type: string description: Roles assigned to the user. password: type: string description: Password for the user (never included). meta: type: object description: Meta fields. required: - username - email - password /wp/v2/users/{id}: get: operationId: getUsersById summary: GET /wp/v2/users/{id} description: Anonymous read — observed HTTP 200 without credentials on 2026-09-04. tags: - People responses: '200': description: Success. content: application/json: schema: type: object '400': description: Invalid parameter. content: application/json: schema: $ref: '#/components/schemas/WPError' '401': description: Authentication required or insufficient capability (`rest_forbidden`). content: application/json: schema: $ref: '#/components/schemas/WPError' '404': description: No route or resource matched (`rest_no_route` / `rest_post_invalid_id`). content: application/json: schema: $ref: '#/components/schemas/WPError' security: - {} - applicationPassword: [] parameters: - &id001 name: id in: path required: true schema: type: integer description: WordPress identifier for the id segment. - name: context in: query required: false schema: type: string enum: - view - embed - edit default: view description: Scope under which the request is made; determines fields present in response. post: operationId: createUsersById summary: POST /wp/v2/users/{id} description: Write operation. Requires WordPress authentication (Application Password over HTTP Basic, or a logged-in cookie plus X-WP-Nonce); anonymous callers receive HTTP 401. tags: - People responses: '200': description: Success. content: application/json: schema: type: object '400': description: Invalid parameter. content: application/json: schema: $ref: '#/components/schemas/WPError' '401': description: Authentication required or insufficient capability (`rest_forbidden`). content: application/json: schema: $ref: '#/components/schemas/WPError' '404': description: No route or resource matched (`rest_no_route` / `rest_post_invalid_id`). content: application/json: schema: $ref: '#/components/schemas/WPError' security: - applicationPassword: [] - cookieNonce: [] parameters: - *id001 requestBody: required: false content: application/json: schema: type: object properties: username: type: string description: Login name for the user. name: type: string description: Display name for the user. first_name: type: string description: First name for the user. last_name: type: string description: Last name for the user. email: type: string format: email description: The email address for the user. url: type: string format: uri description: URL of the user. description: type: string description: Description of the user. locale: type: string enum: &id002 - '' - en_US description: Locale for the user. nickname: type: string description: The nickname for the user. slug: type: string description: An alphanumeric identifier for the user. roles: type: array items: type: string description: Roles assigned to the user. password: type: string description: Password for the user (never included). meta: type: object description: Meta fields. patch: operationId: updateUsersById summary: PATCH /wp/v2/users/{id} description: Write operation. Requires WordPress authentication (Application Password over HTTP Basic, or a logged-in cookie plus X-WP-Nonce); anonymous callers receive HTTP 401. tags: - People responses: '200': description: Success. content: application/json: schema: type: object '400': description: Invalid parameter. content: application/json: schema: $ref: '#/components/schemas/WPError' '401': description: Authentication required or insufficient capability (`rest_forbidden`). content: application/json: schema: $ref: '#/components/schemas/WPError' '404': description: No route or resource matched (`rest_no_route` / `rest_post_invalid_id`). content: application/json: schema: $ref: '#/components/schemas/WPError' security: - applicationPassword: [] - cookieNonce: [] parameters: - *id001 requestBody: required: false content: application/json: schema: type: object properties: username: type: string description: Login name for the user. name: type: string description: Display name for the user. first_name: type: string description: First name for the user. last_name: type: string description: Last name for the user. email: type: string format: email description: The email address for the user. url: type: string format: uri description: URL of the user. description: type: string description: Description of the user. locale: type: string enum: *id002 description: Locale for the user. nickname: type: string description: The nickname for the user. slug: type: string description: An alphanumeric identifier for the user. roles: type: array items: type: string description: Roles assigned to the user. password: type: string description: Password for the user (never included). meta: type: object description: Meta fields. delete: operationId: deleteUsersById summary: DELETE /wp/v2/users/{id} description: Write operation. Requires WordPress authentication (Application Password over HTTP Basic, or a logged-in cookie plus X-WP-Nonce); anonymous callers receive HTTP 401. tags: - People responses: '200': description: Success. content: application/json: schema: type: object '400': description: Invalid parameter. content: application/json: schema: $ref: '#/components/schemas/WPError' '401': description: Authentication required or insufficient capability (`rest_forbidden`). content: application/json: schema: $ref: '#/components/schemas/WPError' '404': description: No route or resource matched (`rest_no_route` / `rest_post_invalid_id`). content: application/json: schema: $ref: '#/components/schemas/WPError' security: - applicationPassword: [] - cookieNonce: [] parameters: - *id001 - name: force in: query required: false schema: type: boolean default: false description: Required to be true, as users do not support trashing. - name: reassign in: query required: true schema: type: integer description: Reassign the deleted user's posts and links to this user ID. components: schemas: WPError: type: object description: The WordPress REST API error envelope, returned on every 4xx/5xx. properties: code: type: string description: Machine-readable error slug, e.g. rest_no_route, rest_forbidden. message: type: string description: Human-readable message. data: type: object properties: status: type: integer description: HTTP status code. params: type: object description: Per-parameter validation messages, when present. required: - code - message - data Users: title: user type: object properties: id: description: Unique identifier for the user. type: integer context: - embed - view - edit readonly: true username: description: Login name for the user. type: string context: - edit required: true name: description: Display name for the user. type: string context: - embed - view - edit first_name: description: First name for the user. type: string context: - edit last_name: description: Last name for the user. type: string context: - edit email: description: The email address for the user. type: string format: email context: - edit required: true url: description: URL of the user. type: string format: uri context: - embed - view - edit description: description: Description of the user. type: string context: - embed - view - edit link: description: Author URL of the user. type: string format: uri context: - embed - view - edit readonly: true locale: description: Locale for the user. type: string enum: - '' - en_US context: - edit nickname: description: The nickname for the user. type: string context: - edit slug: description: An alphanumeric identifier for the user. type: string context: - embed - view - edit registered_date: description: Registration date for the user. type: string format: date-time context: - edit readonly: true roles: description: Roles assigned to the user. type: array items: type: string context: - edit password: description: Password for the user (never included). type: string context: [] required: true capabilities: description: All capabilities assigned to the user. type: object context: - edit readonly: true extra_capabilities: description: Any extra capabilities assigned to the user. type: object context: - edit readonly: true avatar_urls: description: Avatar URLs for the user. type: object context: - embed - view - edit readonly: true properties: '24': description: Avatar URL with image size of 24 pixels. type: string format: uri context: - embed - view - edit '48': description: Avatar URL with image size of 48 pixels. type: string format: uri context: - embed - view - edit '96': description: Avatar URL with image size of 96 pixels. type: string format: uri context: - embed - view - edit meta: description: Meta fields. type: object context: - view - edit properties: persisted_preferences: type: object title: '' description: '' default: [] context: - edit properties: _modified: description: The date and time the preferences were updated. type: string format: date-time readonly: false additionalProperties: true acf: description: ACF field data type: object properties: [] securitySchemes: applicationPassword: type: http scheme: basic description: WordPress Application Passwords over HTTP Basic. Issued at https://virtualincision.com/wp-admin/authorize-application.php (advertised by the wp-json root `authentication` block). cookieNonce: type: apiKey in: header name: X-WP-Nonce description: Logged-in WordPress cookie plus an X-WP-Nonce header — first-party browser context only.