Boundless Bio Comments API

The Comments API from Boundless Bio — 2 operation(s) for comments.

OpenAPI Specification

boundless-bio-comments-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Boundless Bio Content API (WordPress REST wp/v2) Comments API
  version: wp/v2
  summary: 'Public read surface of boundlessbio.com content: corporate pages, the Leadership directory (board of directors, executive leadership and scientific founders), the media library, taxonomies and site search.'
  description: 'Boundless Bio publishes boundlessbio.com on WordPress (hosted on WP Engine), which exposes the WordPress REST API at https://boundlessbio.com/wp-json/. The wp/v2 namespace is anonymously readable and returns the company''s corporate pages (9 published), its `who-we-are` Leadership custom post type (27 published, categorized as board-of-directors, leadership and scientific-founders), the media library (255 items), taxonomies and a site-wide search endpoint as JSON.


    This document was DERIVED mechanically by API Evangelist from the route-discovery document served at https://boundlessbio.com/wp-json/ on 2026-08-08 - every path, method and parameter below is taken verbatim from that descriptor. Boundless Bio does not publish an OpenAPI definition of its own, and this is not a product API: it is the content API the CMS exposes. Boundless Bio is a clinical-stage oncology company and ships no developer program, no product API and no SDKs. Write operations exist on these routes but require authentication (WordPress Application Passwords over HTTP Basic).


    Observed anonymously on 2026-08-08: /wp/v2/posts returns 0 items (the company publishes no blog on this host; investor news is served from investors.boundlessbio.com, a Q4/gcs-web investor site). /wp/v2/settings and the wp-abilities/v1 registry return 401 rest_forbidden. There is no MCP namespace on this host.'
  contact:
    name: Boundless Bio
    url: https://boundlessbio.com/
  x-derived-by: API Evangelist enrichment pipeline
  x-derived-from: https://boundlessbio.com/wp-json/
  x-derived-on: '2026-08-08'
  x-provider-published: false
servers:
- url: https://boundlessbio.com/wp-json
  description: Production
tags:
- name: Comments
paths:
  /wp/v2/comments:
    get:
      operationId: getComments
      summary: GET /wp/v2/comments
      tags:
      - Comments
      parameters:
      - name: context
        in: query
        required: false
        schema:
          type: string
          enum:
          - view
          - embed
          - edit
          default: view
        description: Scope under which the request is made; determines fields present in response.
      - name: page
        in: query
        required: false
        schema:
          type: integer
          default: 1
          minimum: 1
        description: Current page of the collection.
      - name: per_page
        in: query
        required: false
        schema:
          type: integer
          default: 10
          minimum: 1
          maximum: 100
        description: Maximum number of items to be returned in result set.
      - name: search
        in: query
        required: false
        schema:
          type: string
        description: Limit results to those matching a string.
      - name: after
        in: query
        required: false
        schema:
          type: string
          format: date-time
        description: Limit response to comments published after a given ISO8601 compliant date.
      - name: author
        in: query
        required: false
        schema:
          type: array
          items:
            type: integer
        description: Limit result set to comments assigned to specific user IDs. Requires authorization.
      - name: author_exclude
        in: query
        required: false
        schema:
          type: array
          items:
            type: integer
        description: Ensure result set excludes comments assigned to specific user IDs. Requires authorization.
      - name: author_email
        in: query
        required: false
        schema:
          type: string
          format: email
          default: null
        description: Limit result set to that from a specific author email. Requires authorization.
      - name: before
        in: query
        required: false
        schema:
          type: string
          format: date-time
        description: Limit response to comments published before a given ISO8601 compliant date.
      - name: exclude
        in: query
        required: false
        schema:
          type: array
          items:
            type: integer
          default: []
        description: Ensure result set excludes specific IDs.
      - name: include
        in: query
        required: false
        schema:
          type: array
          items:
            type: integer
          default: []
        description: Limit result set to specific IDs.
      - name: offset
        in: query
        required: false
        schema:
          type: integer
        description: Offset the result set by a specific number of items.
      - name: order
        in: query
        required: false
        schema:
          type: string
          enum:
          - asc
          - desc
          default: desc
        description: Order sort attribute ascending or descending.
      - name: orderby
        in: query
        required: false
        schema:
          type: string
          enum:
          - date
          - date_gmt
          - id
          - include
          - post
          - parent
          - type
          default: date_gmt
        description: Sort collection by comment attribute.
      - name: parent
        in: query
        required: false
        schema:
          type: array
          items:
            type: integer
          default: []
        description: Limit result set to comments of specific parent IDs.
      - name: parent_exclude
        in: query
        required: false
        schema:
          type: array
          items:
            type: integer
          default: []
        description: Ensure result set excludes specific parent IDs.
      - name: post
        in: query
        required: false
        schema:
          type: array
          items:
            type: integer
          default: []
        description: Limit result set to comments assigned to specific post IDs.
      - name: status
        in: query
        required: false
        schema:
          type: string
          default: approve
        description: Limit result set to comments assigned a specific status. Requires authorization.
      - name: type
        in: query
        required: false
        schema:
          type: string
          default: comment
        description: Limit result set to comments assigned a specific type. Requires authorization.
      - name: password
        in: query
        required: false
        schema:
          type: string
        description: The password for the post if it is password protected.
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: array
                items:
                  type: object
          headers:
            X-WP-Total:
              description: Total number of records in the collection
              schema:
                type: integer
            X-WP-TotalPages:
              description: Total number of pages available
              schema:
                type: integer
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
    post:
      operationId: createComments
      summary: POST /wp/v2/comments
      tags:
      - Comments
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                author:
                  type: integer
                  description: The ID of the user object, if author was a user.
                author_email:
                  type: string
                  format: email
                  description: Email address for the comment author.
                author_ip:
                  type: string
                  format: ip
                  description: IP address for the comment author.
                author_name:
                  type: string
                  description: Display name for the comment author.
                author_url:
                  type: string
                  format: uri
                  description: URL for the comment author.
                author_user_agent:
                  type: string
                  description: User agent for the comment author.
                content:
                  type: object
                  description: The content for the comment.
                date:
                  type: string
                  format: date-time
                  description: The date the comment was published, in the site's timezone.
                date_gmt:
                  type: string
                  format: date-time
                  description: The date the comment was published, as GMT.
                parent:
                  type: integer
                  description: The ID for the parent of the comment.
                post:
                  type: integer
                  description: The ID of the associated post object.
                status:
                  type: string
                  description: State of the comment.
                meta:
                  type: object
                  description: Meta fields.
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      security:
      - applicationPassword: []
  /wp/v2/comments/{id}:
    parameters:
    - name: id
      in: path
      required: true
      schema:
        type: string
    get:
      operationId: getCommentsById
      summary: GET /wp/v2/comments/{id}
      tags:
      - Comments
      parameters:
      - name: id
        in: query
        required: false
        schema:
          type: integer
        description: Unique identifier for the comment.
      - name: context
        in: query
        required: false
        schema:
          type: string
          enum:
          - view
          - embed
          - edit
          default: view
        description: Scope under which the request is made; determines fields present in response.
      - name: password
        in: query
        required: false
        schema:
          type: string
        description: The password for the parent post of the comment (if the post is password protected).
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
    post:
      operationId: createCommentsById
      summary: POST /wp/v2/comments/{id}
      tags:
      - Comments
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                id:
                  type: integer
                  description: Unique identifier for the comment.
                author:
                  type: integer
                  description: The ID of the user object, if author was a user.
                author_email:
                  type: string
                  format: email
                  description: Email address for the comment author.
                author_ip:
                  type: string
                  format: ip
                  description: IP address for the comment author.
                author_name:
                  type: string
                  description: Display name for the comment author.
                author_url:
                  type: string
                  format: uri
                  description: URL for the comment author.
                author_user_agent:
                  type: string
                  description: User agent for the comment author.
                content:
                  type: object
                  description: The content for the comment.
                date:
                  type: string
                  format: date-time
                  description: The date the comment was published, in the site's timezone.
                date_gmt:
                  type: string
                  format: date-time
                  description: The date the comment was published, as GMT.
                parent:
                  type: integer
                  description: The ID for the parent of the comment.
                post:
                  type: integer
                  description: The ID of the associated post object.
                status:
                  type: string
                  description: State of the comment.
                meta:
                  type: object
                  description: Meta fields.
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      security:
      - applicationPassword: []
    put:
      operationId: updateCommentsById
      summary: PUT /wp/v2/comments/{id}
      tags:
      - Comments
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                id:
                  type: integer
                  description: Unique identifier for the comment.
                author:
                  type: integer
                  description: The ID of the user object, if author was a user.
                author_email:
                  type: string
                  format: email
                  description: Email address for the comment author.
                author_ip:
                  type: string
                  format: ip
                  description: IP address for the comment author.
                author_name:
                  type: string
                  description: Display name for the comment author.
                author_url:
                  type: string
                  format: uri
                  description: URL for the comment author.
                author_user_agent:
                  type: string
                  description: User agent for the comment author.
                content:
                  type: object
                  description: The content for the comment.
                date:
                  type: string
                  format: date-time
                  description: The date the comment was published, in the site's timezone.
                date_gmt:
                  type: string
                  format: date-time
                  description: The date the comment was published, as GMT.
                parent:
                  type: integer
                  description: The ID for the parent of the comment.
                post:
                  type: integer
                  description: The ID of the associated post object.
                status:
                  type: string
                  description: State of the comment.
                meta:
                  type: object
                  description: Meta fields.
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      security:
      - applicationPassword: []
    patch:
      operationId: patchCommentsById
      summary: PATCH /wp/v2/comments/{id}
      tags:
      - Comments
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                id:
                  type: integer
                  description: Unique identifier for the comment.
                author:
                  type: integer
                  description: The ID of the user object, if author was a user.
                author_email:
                  type: string
                  format: email
                  description: Email address for the comment author.
                author_ip:
                  type: string
                  format: ip
                  description: IP address for the comment author.
                author_name:
                  type: string
                  description: Display name for the comment author.
                author_url:
                  type: string
                  format: uri
                  description: URL for the comment author.
                author_user_agent:
                  type: string
                  description: User agent for the comment author.
                content:
                  type: object
                  description: The content for the comment.
                date:
                  type: string
                  format: date-time
                  description: The date the comment was published, in the site's timezone.
                date_gmt:
                  type: string
                  format: date-time
                  description: The date the comment was published, as GMT.
                parent:
                  type: integer
                  description: The ID for the parent of the comment.
                post:
                  type: integer
                  description: The ID of the associated post object.
                status:
                  type: string
                  description: State of the comment.
                meta:
                  type: object
                  description: Meta fields.
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      security:
      - applicationPassword: []
    delete:
      operationId: deleteCommentsById
      summary: DELETE /wp/v2/comments/{id}
      tags:
      - Comments
      parameters:
      - name: id
        in: query
        required: false
        schema:
          type: integer
        description: Unique identifier for the comment.
      - name: force
        in: query
        required: false
        schema:
          type: boolean
          default: false
        description: Whether to bypass Trash and force deletion.
      - name: password
        in: query
        required: false
        schema:
          type: string
        description: The password for the parent post of the comment (if the post is password protected).
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      security:
      - applicationPassword: []
components:
  responses:
    NotFound:
      description: No route or resource matched (rest_no_route / rest_post_invalid_id).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/WpError'
    BadRequest:
      description: Invalid parameter (rest_invalid_param).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/WpError'
    Unauthorized:
      description: Authentication required or rejected (rest_forbidden / rest_not_logged_in).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/WpError'
    Forbidden:
      description: Authenticated but not permitted (rest_cannot_view / rest_forbidden).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/WpError'
  schemas:
    WpError:
      type: object
      description: The WordPress REST API error envelope (WP_Error serialized to JSON).
      properties:
        code:
          type: string
          description: Machine-readable error code, e.g. rest_forbidden.
        message:
          type: string
          description: Human-readable error message.
        data:
          type: object
          properties:
            status:
              type: integer
  securitySchemes:
    applicationPassword:
      type: http
      scheme: basic
      description: WordPress Application Passwords, advertised by the site at https://boundlessbio.com/wp-json/ under authentication.application-passwords; authorization endpoint https://boundlessbio.com/wp-admin/authorize-application.php. Read operations on wp/v2 are anonymous.