generated: '2026-09-05'
method: generated
source: openapi/ + authentication/ + conventions/
description: >-
Recommended x-agentic-access contracts for the 3Bar Biologics public content API, classified per
operation. This is a RECOMMENDATION authored by API Evangelist, not a contract the provider
publishes — 3Bar Biologics makes no statement about agent access at all. The classification is
unusually simple here because the entire anonymously reachable surface is read-only.
posture:
overall: safe-read-only
detail: >-
All 19 documented operations are GET. Every mutating route on the underlying WordPress install
returns 401 without a WordPress application password, and that credential has no public issuance
path, so no agent operating anonymously can change anything. An agent needs no consent gate, no
spend cap, no escalation path and no reversal plan for this surface.
robots_signal:
x_robots_tag: noindex
detail: >-
Every API response carries `X-Robots-Tag: noindex`. This is an indexing directive rather than an
access prohibition, and it is served on the API responses rather than in robots.txt, but it is
the only signal the provider gives about machine consumption of this data. An agent should read
freely and refrain from republishing the content as indexable material.
robots_txt:
url: https://www.3barbiologics.com/robots.txt
http_status: 200
detail: A Yoast-generated robots.txt is served. No /wp-json/ disallow was present.
default_contract:
action_class: read
consequence: none
scope: public-content
token: none
escalation: not-required
reversible: na
rate_guidance: >-
No published limits and no rate-limit response headers. Self-throttle. Responses are cached for 7
days at the edge, so a cache-respecting agent generates almost no origin load.
operations:
- {operationId: listPosts, action_class: read, consequence: none, token: none, escalation: not-required}
- {operationId: getPost, action_class: read, consequence: none, token: none, escalation: not-required}
- {operationId: listPages, action_class: read, consequence: none, token: none, escalation: not-required}
- {operationId: getPage, action_class: read, consequence: none, token: none, escalation: not-required}
- {operationId: listCategories, action_class: read, consequence: none, token: none, escalation: not-required}
- {operationId: getCategory, action_class: read, consequence: none, token: none, escalation: not-required}
- {operationId: listTags, action_class: read, consequence: none, token: none, escalation: not-required}
- {operationId: getTag, action_class: read, consequence: none, token: none, escalation: not-required}
- {operationId: listUsers, action_class: read, consequence: none, token: none, escalation: not-required,
note: 'Returns named individuals (3 public authors). Personal data in the sense that it is attributable to a person, though it is published deliberately as bylines. Do not aggregate it into a contact dataset.'}
- {operationId: getUser, action_class: read, consequence: none, token: none, escalation: not-required}
- {operationId: searchContent, action_class: read, consequence: none, token: none, escalation: not-required}
- {operationId: listMediaItems, action_class: read, consequence: none, token: none, escalation: not-required,
reliability: degraded,
note: 'Two reproducible defects — HTTP 500 on ascending numeric/date sorts, and an advertised total that does not match retrievable records. An agent must not treat an empty 200 here as collection-exhausted. See errors/3bar-biologics-problem-types.yml.'}
- {operationId: getMediaItem, action_class: read, consequence: none, token: none, escalation: not-required}
- {operationId: getApiRoot, action_class: read, consequence: none, token: none, escalation: not-required,
note: 'Roughly 340KB. Fetch once and cache; do not poll.'}
- {operationId: listTypes, action_class: read, consequence: none, token: none, escalation: not-required}
- {operationId: listTaxonomies, action_class: read, consequence: none, token: none, escalation: not-required}
- {operationId: listStatuses, action_class: read, consequence: none, token: none, escalation: not-required}
- {operationId: getOembed, action_class: read, consequence: none, token: none, escalation: not-required}
- {operationId: getSeoHead, action_class: read, consequence: none, token: none, escalation: not-required,
note: 'Returns 404 with a populated, parseable body. Branch on status, not body shape.'}
unreachable_write_surface:
detail: >-
The underlying WordPress install registers POST/PUT/PATCH/DELETE on posts, pages, media,
taxonomies, users, blocks, menus, widgets, templates and settings. None is reachable
anonymously — all return 401. They are listed here only so that a future re-profile does not
mistake their absence from the operations list above for an incomplete harvest.
credential_required: WordPress application password (Basic over TLS)
public_issuance_path: false
Every access contract here is available over the APIs.io API and to AI agents over MCP. Agentic Access is not yet its own endpoint on the v1 API. Reach it through catalog search and the tag graph, or the MCP server.