Allay Therapeutics Media API

Media library. `X-WP-Total` reports 161 attachments, but only one attachment (id 1503) is returned to an anonymous caller; the remainder are attached to non-public parents.

OpenAPI Specification

allay-therapeutics-media-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Allay Therapeutics Content Media API
  version: wp/v2
  summary: Anonymously readable WordPress REST content API behind www.allaytx.com.
  description: The read-only content surface Allay Therapeutics exposes at https://www.allaytx.com/wp-json. Allay Therapeutics is a clinical-stage biopharmaceutical company in San Jose, California and Singapore developing ultra-sustained, non-opioid analgesic products for post-surgical pain management, led by the bupivacaine-based ATX-101 implant for total knee replacement. It runs no developer program and markets no product API. This document is an API Evangelist derivation of the WordPress `wp/v2` and `oembed/1.0` route index the site publishes at /wp-json/, restricted to the operations verified to return data anonymously on 2026-08-06. Every write route, the entire plugin-administration surface, and `/wp/v2/users` are deliberately excluded — see x-api-evangelist-provenance.
  contact:
    name: Allay Therapeutics
    url: https://www.allaytx.com/
    email: contact@allaytx.com
  x-api-evangelist-provenance: 'Derived by the API Evangelist enrichment pipeline from the live WordPress REST route index at https://www.allaytx.com/wp-json/ (196 routes across 10 namespaces: oembed/1.0, wpe/cache-plugin/v1, wpe_sign_on_plugin/v1, yoast/v1, duplicate-post/v1, monsterinsights/v1, wp/v2, wp-site-health/v1, wp-block-editor/v1 and wp-abilities/v1) and verified against live anonymous responses on 2026-08-06. Every parameter below appears verbatim in the route index `args` for that endpoint, and every collection count in a description was read from the `X-WP-Total` response header on that date. Only operations that returned data without credentials are modelled. Anonymous 401s recorded at harvest: /wp/v2/settings (rest_forbidden), /wp/v2/menus (rest_cannot_view), /wp/v2/themes (rest_cannot_view_themes), /wp/v2/plugins (rest_cannot_view_plugins), /wp/v2/block-types (rest_block_type_cannot_view), /wp/v2/font-collections (rest_cannot_read), /wp/v2/icons (rest_cannot_view) and the whole wp-abilities/v1 namespace (rest_forbidden) — so no agent-capability, MCP or AgentCard surface is claimed for this provider. DELIBERATE EXCLUSION: /wp/v2/users answers anonymously with 7 author records (WordPress default author enumeration). The exposure is recorded here as a factual observation, but the endpoint is NOT modelled as an operation, NOT packaged as an agent skill, and no individual is named anywhere in this repository. Allay Therapeutics publishes no OpenAPI, no developer documentation and no API reference for this surface; the humanURL in apis.yml points at the upstream WordPress REST handbook that defines the wp/v2 contract. The deployment is served by WP Engine behind nginx, responses carry `x-robots-tag: noindex` and `cache-control: max-age=600, must-revalidate`. Nothing here was obtained with credentials.'
servers:
- url: https://www.allaytx.com/wp-json
  description: Production content API
tags:
- name: media
  description: Media library. `X-WP-Total` reports 161 attachments, but only one attachment (id 1503) is returned to an anonymous caller; the remainder are attached to non-public parents.
paths:
  /wp/v2/media:
    get:
      tags:
      - media
      operationId: listMedia
      summary: List media attachments
      description: Lists media library attachments. `X-WP-Total` reports 161, but an anonymous caller receives a single attachment (id 1503); the rest are attached to non-public parents and are filtered out of the anonymous view.
      parameters:
      - $ref: '#/components/parameters/Context'
      - $ref: '#/components/parameters/Page'
      - $ref: '#/components/parameters/PerPage'
      - $ref: '#/components/parameters/Search'
      - $ref: '#/components/parameters/Order'
      - $ref: '#/components/parameters/Fields'
      - name: media_type
        in: query
        description: Limit result set to attachments of a particular media type.
        schema:
          type: string
          enum:
          - image
          - video
          - text
          - application
          - audio
      - name: mime_type
        in: query
        description: Limit result set to attachments of a particular MIME type.
        schema:
          type: string
      responses:
        '200':
          description: A page of attachments
          headers:
            X-WP-Total:
              schema:
                type: integer
            X-WP-TotalPages:
              schema:
                type: integer
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/Attachment'
  /wp/v2/media/{id}:
    get:
      tags:
      - media
      operationId: getMedia
      summary: Get a single media attachment
      description: Retrieves one attachment by numeric ID.
      parameters:
      - $ref: '#/components/parameters/PathId'
      - $ref: '#/components/parameters/Context'
      responses:
        '200':
          description: An attachment
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Attachment'
        '404':
          $ref: '#/components/responses/PostNotFound'
components:
  parameters:
    Order:
      name: order
      in: query
      description: Order sort attribute ascending or descending.
      schema:
        type: string
        enum:
        - asc
        - desc
        default: desc
    Page:
      name: page
      in: query
      description: Current page of the collection.
      schema:
        type: integer
        minimum: 1
        default: 1
    Fields:
      name: _fields
      in: query
      description: Sparse fieldset — comma-separated list of fields to include in the response.
      schema:
        type: string
        examples:
        - id,date,slug,title,link
    PathId:
      name: id
      in: path
      required: true
      description: Unique identifier for the object.
      schema:
        type: integer
    Context:
      name: context
      in: query
      description: Scope under which the request is made; determines fields present in the response.
      schema:
        type: string
        enum:
        - view
        - embed
        - edit
        default: view
    Search:
      name: search
      in: query
      description: Limit results to those matching a string.
      schema:
        type: string
    PerPage:
      name: per_page
      in: query
      description: Maximum number of items to be returned in the result set.
      schema:
        type: integer
        minimum: 1
        maximum: 100
        default: 10
  schemas:
    Attachment:
      type: object
      description: A media library attachment.
      properties:
        id:
          type: integer
        date:
          type: string
          format: date-time
        slug:
          type: string
        type:
          type: string
          const: attachment
        link:
          type: string
          format: uri
        title:
          $ref: '#/components/schemas/RenderedText'
        media_type:
          type: string
          enum:
          - image
          - file
        mime_type:
          type: string
        source_url:
          type: string
          format: uri
        media_details:
          type: object
        post:
          type: integer
          description: The parent object ID this attachment is attached to.
        _links:
          type: object
    Error:
      type: object
      description: The WordPress REST error envelope. Not RFC 9457 — the media type is application/json, and the shape is {code, message, data:{status}} with an optional data.params / data.details map on validation failures.
      required:
      - code
      - message
      - data
      properties:
        code:
          type: string
          description: Machine-readable error code.
        message:
          type: string
          description: Human-readable error message.
        data:
          type: object
          properties:
            status:
              type: integer
              description: HTTP status code.
            params:
              type: object
              description: Per-parameter validation messages.
            details:
              type: object
              description: Per-parameter structured validation detail.
    RenderedText:
      type: object
      properties:
        rendered:
          type: string
          description: HTML for the field, transformed for display.
        protected:
          type: boolean
  responses:
    PostNotFound:
      description: No object exists with the supplied ID.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            invalidPostId:
              value:
                code: rest_post_invalid_id
                message: Invalid post ID.
                data:
                  status: 404