Bluejay Therapeutics Embed API

oEmbed 1.0 provider endpoint.

OpenAPI Specification

bluejay-therapeutics-embed-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Bluejay Therapeutics Content Embed API
  version: '1.0'
  x-generated: '2026-08-07'
  x-method: derived
  x-source: https://bluejaytx.com/wp-json/
  description: 'The anonymously readable WordPress REST API behind bluejaytx.com, the corporate site of Bluejay Therapeutics — a Redwood City, California clinical-stage biopharmaceutical company developing brelovitug (BJT-778) and a hepatitis B/D portfolio, acquired by Mirum Pharmaceuticals on 26 January 2026.


    This is not a developer product Bluejay Therapeutics markets. It is the site''s own WordPress content surface, registered at /wp-json/ and verified to return data without credentials on 2026-08-07. This document is DERIVED by the API Evangelist enrichment pipeline from the route index the site itself publishes at https://bluejaytx.com/wp-json/ — 372 routes across 17 namespaces (oembed/1.0, wpe/cache-plugin/v1, wpe_sign_on_plugin/v1, aioseo/v1, code-snippets/v1, contact-form-7/v1, jupiterx-license, elementor/v1, monsterinsights/v1, elementor/v1/documents, elementor-ai/v1, elementor-pro/v1, omapp/v1, wp/v2, wp-site-health/v1, wp-block-editor/v1, wp-abilities/v1). Only the 26 operations that were individually called and returned data anonymously are modelled here; every other route returned 401, 403 or 404 and is deliberately absent.


    WHAT A CONSUMER MUST KNOW. First, the human web site no longer exists. Following the acquisition the page tree was collapsed to a SINGLE page (id 606, "New home page", served at the site root) carrying a two-sentence acquisition notice that redirects readers to mirumpharma.com; /about/, /science/, /pipeline/, /news/, /contact/ and /privacy-policy/ all return 404. The machine-readable surface, however, survived the teardown intact: the REST API still serves all 35 press releases and publication notices from 2021-08-12 through 2025-12-08 with FULL `content.rendered` bodies (up to ~15 KB of press-release prose each), plus the 99-item media library. For this company the API is now a strictly richer record of the corporate history than the web site it belongs to.


    Second, the content is Elementor-authored, so `content.rendered` on newer posts is wrapped in `div[data-elementor-type]` scaffolding around the prose; older posts render as clean `wp-block-*` markup. Third, the `pages` collection holds exactly one item and the `portfolio`, `portfolio_category`, `portfolio_tag`, `blocks` and `navigation` collections are registered but return empty arrays — they are modelled here because they answer 200 anonymously, not because they carry data.


    OMITTED ON PURPOSE. `/wp/v2/users` returns 200 anonymously with five named individuals (site administrator plus outside investor-relations and communications agency staff). Under the API Evangelist enrichment PII guardrail that collection is documented as an exposure but is NOT modelled as an operation here, and no agent skill or MCP tool is emitted for it. The exposure itself is recorded in conventions/bluejay-therapeutics-conventions.yml. The site also registers the WordPress Abilities API (`wp-abilities/v1`), an agent-facing capability registry, but every endpoint under it returns 401 rest_forbidden anonymously, so no agent surface is claimed.'
  contact:
    name: API Evangelist
    email: kin@apievangelist.com
    url: https://apievangelist.com
  x-upstream-contract: https://developer.wordpress.org/rest-api/
servers:
- url: https://bluejaytx.com/wp-json
  description: Production WordPress REST API for bluejaytx.com (WP Engine, nginx)
tags:
- name: embed
  description: oEmbed 1.0 provider endpoint.
paths:
  /oembed/1.0/embed:
    get:
      operationId: getOEmbed
      tags:
      - embed
      summary: Get the oEmbed representation of a URL on this site
      description: The oEmbed 1.0 provider endpoint. Returns provider name, author, title, thumbnail and the iframe embed HTML for any bluejaytx.com URL. Note the sibling `/oembed/1.0/proxy` endpoint returns 401 rest_forbidden anonymously.
      parameters:
      - name: url
        in: query
        required: true
        description: The URL of the post or page to embed.
        schema:
          type: string
          format: uri
      - name: format
        in: query
        description: Response format.
        schema:
          type: string
          enum:
          - json
          - xml
          default: json
      - name: maxwidth
        in: query
        description: Maximum embed width in pixels.
        schema:
          type: integer
          default: 600
      responses:
        '200':
          description: The oEmbed document.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OEmbed'
        '404':
          $ref: '#/components/responses/NotFound'
components:
  schemas:
    OEmbed:
      type: object
      properties:
        version:
          type: string
        provider_name:
          type: string
        provider_url:
          type: string
          format: uri
        author_name:
          type: string
        author_url:
          type: string
          format: uri
        title:
          type: string
        type:
          type: string
        width:
          type: integer
        height:
          type: integer
        html:
          type: string
          description: The iframe embed markup.
        thumbnail_url:
          type: string
          format: uri
    Error:
      type: object
      description: The WordPress REST error envelope. NOT RFC 9457 — the media type is application/json, not application/problem+json, and the field names are WordPress-specific.
      properties:
        code:
          type: string
          description: Machine-readable error slug, e.g. `rest_post_invalid_id`, `rest_forbidden`.
        message:
          type: string
          description: Human-readable message.
        data:
          type: object
          properties:
            status:
              type: integer
              description: The HTTP status code, repeated inside the body.
            params:
              type: object
              description: Present on validation errors; maps parameter name to the failure reason.
      required:
      - code
      - message
  responses:
    NotFound:
      description: No object matched the identifier.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'