Boundless Bio Media API

The Media API from Boundless Bio — 3 operation(s) for media.

OpenAPI Specification

boundless-bio-media-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Boundless Bio Content API (WordPress REST wp/v2) Media API
  version: wp/v2
  summary: 'Public read surface of boundlessbio.com content: corporate pages, the Leadership directory (board of directors, executive leadership and scientific founders), the media library, taxonomies and site search.'
  description: 'Boundless Bio publishes boundlessbio.com on WordPress (hosted on WP Engine), which exposes the WordPress REST API at https://boundlessbio.com/wp-json/. The wp/v2 namespace is anonymously readable and returns the company''s corporate pages (9 published), its `who-we-are` Leadership custom post type (27 published, categorized as board-of-directors, leadership and scientific-founders), the media library (255 items), taxonomies and a site-wide search endpoint as JSON.


    This document was DERIVED mechanically by API Evangelist from the route-discovery document served at https://boundlessbio.com/wp-json/ on 2026-08-08 - every path, method and parameter below is taken verbatim from that descriptor. Boundless Bio does not publish an OpenAPI definition of its own, and this is not a product API: it is the content API the CMS exposes. Boundless Bio is a clinical-stage oncology company and ships no developer program, no product API and no SDKs. Write operations exist on these routes but require authentication (WordPress Application Passwords over HTTP Basic).


    Observed anonymously on 2026-08-08: /wp/v2/posts returns 0 items (the company publishes no blog on this host; investor news is served from investors.boundlessbio.com, a Q4/gcs-web investor site). /wp/v2/settings and the wp-abilities/v1 registry return 401 rest_forbidden. There is no MCP namespace on this host.'
  contact:
    name: Boundless Bio
    url: https://boundlessbio.com/
  x-derived-by: API Evangelist enrichment pipeline
  x-derived-from: https://boundlessbio.com/wp-json/
  x-derived-on: '2026-08-08'
  x-provider-published: false
servers:
- url: https://boundlessbio.com/wp-json
  description: Production
tags:
- name: Media
paths:
  /wp/v2/media:
    get:
      operationId: getMedia
      summary: GET /wp/v2/media
      tags:
      - Media
      parameters:
      - name: context
        in: query
        required: false
        schema:
          type: string
          enum:
          - view
          - embed
          - edit
          default: view
        description: Scope under which the request is made; determines fields present in response.
      - name: page
        in: query
        required: false
        schema:
          type: integer
          default: 1
          minimum: 1
        description: Current page of the collection.
      - name: per_page
        in: query
        required: false
        schema:
          type: integer
          default: 10
          minimum: 1
          maximum: 100
        description: Maximum number of items to be returned in result set.
      - name: search
        in: query
        required: false
        schema:
          type: string
        description: Limit results to those matching a string.
      - name: after
        in: query
        required: false
        schema:
          type: string
          format: date-time
        description: Limit response to posts published after a given ISO8601 compliant date.
      - name: modified_after
        in: query
        required: false
        schema:
          type: string
          format: date-time
        description: Limit response to posts modified after a given ISO8601 compliant date.
      - name: author
        in: query
        required: false
        schema:
          type: array
          items:
            type: integer
          default: []
        description: Limit result set to posts assigned to specific authors.
      - name: author_exclude
        in: query
        required: false
        schema:
          type: array
          items:
            type: integer
          default: []
        description: Ensure result set excludes posts assigned to specific authors.
      - name: before
        in: query
        required: false
        schema:
          type: string
          format: date-time
        description: Limit response to posts published before a given ISO8601 compliant date.
      - name: modified_before
        in: query
        required: false
        schema:
          type: string
          format: date-time
        description: Limit response to posts modified before a given ISO8601 compliant date.
      - name: exclude
        in: query
        required: false
        schema:
          type: array
          items:
            type: integer
          default: []
        description: Ensure result set excludes specific IDs.
      - name: include
        in: query
        required: false
        schema:
          type: array
          items:
            type: integer
          default: []
        description: Limit result set to specific IDs.
      - name: search_semantics
        in: query
        required: false
        schema:
          type: string
          enum:
          - exact
        description: How to interpret the search input.
      - name: offset
        in: query
        required: false
        schema:
          type: integer
        description: Offset the result set by a specific number of items.
      - name: order
        in: query
        required: false
        schema:
          type: string
          enum:
          - asc
          - desc
          default: desc
        description: Order sort attribute ascending or descending.
      - name: orderby
        in: query
        required: false
        schema:
          type: string
          enum:
          - author
          - date
          - id
          - include
          - modified
          - parent
          - relevance
          - slug
          - include_slugs
          - title
          default: date
        description: Sort collection by post attribute.
      - name: parent
        in: query
        required: false
        schema:
          type: array
          items:
            type: integer
          default: []
        description: Limit result set to items with particular parent IDs.
      - name: parent_exclude
        in: query
        required: false
        schema:
          type: array
          items:
            type: integer
          default: []
        description: Limit result set to all items except those of a particular parent ID.
      - name: search_columns
        in: query
        required: false
        schema:
          type: array
          items:
            type: string
            enum:
            - post_title
            - post_content
            - post_excerpt
          default: []
        description: Array of column names to be searched.
      - name: slug
        in: query
        required: false
        schema:
          type: array
          items:
            type: string
        description: Limit result set to posts with one or more specific slugs.
      - name: status
        in: query
        required: false
        schema:
          type: array
          items:
            type: string
            enum:
            - inherit
            - private
            - trash
          default: inherit
        description: Limit result set to posts assigned one or more statuses.
      - name: media_type
        in: query
        required: false
        schema:
          type: array
          items:
            type: string
            enum:
            - image
            - video
            - text
            - application
            - audio
          default: null
        description: Limit result set to attachments of a particular media type or media types.
      - name: mime_type
        in: query
        required: false
        schema:
          type: array
          items:
            type: string
          default: null
        description: Limit result set to attachments of a particular MIME type or MIME types.
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: array
                items:
                  type: object
          headers:
            X-WP-Total:
              description: Total number of records in the collection
              schema:
                type: integer
            X-WP-TotalPages:
              description: Total number of pages available
              schema:
                type: integer
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
    post:
      operationId: createMedia
      summary: POST /wp/v2/media
      tags:
      - Media
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                date:
                  type: string
                  format: date-time
                  description: The date the post was published, in the site's timezone.
                date_gmt:
                  type: string
                  format: date-time
                  description: The date the post was published, as GMT.
                slug:
                  type: string
                  description: An alphanumeric identifier for the post unique to its type.
                status:
                  type: string
                  enum:
                  - publish
                  - future
                  - draft
                  - pending
                  - private
                  - acf-disabled
                  description: A named status for the post.
                title:
                  type: object
                  description: The title for the post.
                author:
                  type: integer
                  description: The ID for the author of the post.
                featured_media:
                  type: integer
                  description: The ID of the featured media for the post.
                comment_status:
                  type: string
                  enum:
                  - open
                  - closed
                  description: Whether or not comments are open on the post.
                ping_status:
                  type: string
                  enum:
                  - open
                  - closed
                  description: Whether or not the post can be pinged.
                meta:
                  type: object
                  description: Meta fields.
                template:
                  type: string
                  description: The theme file to use to display the post.
                alt_text:
                  type: string
                  description: Alternative text to display when attachment is not displayed.
                caption:
                  type: object
                  description: The attachment caption.
                description:
                  type: object
                  description: The attachment description.
                post:
                  type: integer
                  description: The ID for the associated post of the attachment.
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      security:
      - applicationPassword: []
  /wp/v2/media/{id}:
    parameters:
    - name: id
      in: path
      required: true
      schema:
        type: string
    get:
      operationId: getMediaById
      summary: GET /wp/v2/media/{id}
      tags:
      - Media
      parameters:
      - name: id
        in: query
        required: false
        schema:
          type: integer
        description: Unique identifier for the post.
      - name: context
        in: query
        required: false
        schema:
          type: string
          enum:
          - view
          - embed
          - edit
          default: view
        description: Scope under which the request is made; determines fields present in response.
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
    post:
      operationId: createMediaById
      summary: POST /wp/v2/media/{id}
      tags:
      - Media
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                id:
                  type: integer
                  description: Unique identifier for the post.
                date:
                  type: string
                  format: date-time
                  description: The date the post was published, in the site's timezone.
                date_gmt:
                  type: string
                  format: date-time
                  description: The date the post was published, as GMT.
                slug:
                  type: string
                  description: An alphanumeric identifier for the post unique to its type.
                status:
                  type: string
                  enum:
                  - publish
                  - future
                  - draft
                  - pending
                  - private
                  - acf-disabled
                  description: A named status for the post.
                title:
                  type: object
                  description: The title for the post.
                author:
                  type: integer
                  description: The ID for the author of the post.
                featured_media:
                  type: integer
                  description: The ID of the featured media for the post.
                comment_status:
                  type: string
                  enum:
                  - open
                  - closed
                  description: Whether or not comments are open on the post.
                ping_status:
                  type: string
                  enum:
                  - open
                  - closed
                  description: Whether or not the post can be pinged.
                meta:
                  type: object
                  description: Meta fields.
                template:
                  type: string
                  description: The theme file to use to display the post.
                alt_text:
                  type: string
                  description: Alternative text to display when attachment is not displayed.
                caption:
                  type: object
                  description: The attachment caption.
                description:
                  type: object
                  description: The attachment description.
                post:
                  type: integer
                  description: The ID for the associated post of the attachment.
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      security:
      - applicationPassword: []
    put:
      operationId: updateMediaById
      summary: PUT /wp/v2/media/{id}
      tags:
      - Media
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                id:
                  type: integer
                  description: Unique identifier for the post.
                date:
                  type: string
                  format: date-time
                  description: The date the post was published, in the site's timezone.
                date_gmt:
                  type: string
                  format: date-time
                  description: The date the post was published, as GMT.
                slug:
                  type: string
                  description: An alphanumeric identifier for the post unique to its type.
                status:
                  type: string
                  enum:
                  - publish
                  - future
                  - draft
                  - pending
                  - private
                  - acf-disabled
                  description: A named status for the post.
                title:
                  type: object
                  description: The title for the post.
                author:
                  type: integer
                  description: The ID for the author of the post.
                featured_media:
                  type: integer
                  description: The ID of the featured media for the post.
                comment_status:
                  type: string
                  enum:
                  - open
                  - closed
                  description: Whether or not comments are open on the post.
                ping_status:
                  type: string
                  enum:
                  - open
                  - closed
                  description: Whether or not the post can be pinged.
                meta:
                  type: object
                  description: Meta fields.
                template:
                  type: string
                  description: The theme file to use to display the post.
                alt_text:
                  type: string
                  description: Alternative text to display when attachment is not displayed.
                caption:
                  type: object
                  description: The attachment caption.
                description:
                  type: object
                  description: The attachment description.
                post:
                  type: integer
                  description: The ID for the associated post of the attachment.
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      security:
      - applicationPassword: []
    patch:
      operationId: patchMediaById
      summary: PATCH /wp/v2/media/{id}
      tags:
      - Media
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                id:
                  type: integer
                  description: Unique identifier for the post.
                date:
                  type: string
                  format: date-time
                  description: The date the post was published, in the site's timezone.
                date_gmt:
                  type: string
                  format: date-time
                  description: The date the post was published, as GMT.
                slug:
                  type: string
                  description: An alphanumeric identifier for the post unique to its type.
                status:
                  type: string
                  enum:
                  - publish
                  - future
                  - draft
                  - pending
                  - private
                  - acf-disabled
                  description: A named status for the post.
                title:
                  type: object
                  description: The title for the post.
                author:
                  type: integer
                  description: The ID for the author of the post.
                featured_media:
                  type: integer
                  description: The ID of the featured media for the post.
                comment_status:
                  type: string
                  enum:
                  - open
                  - closed
                  description: Whether or not comments are open on the post.
                ping_status:
                  type: string
                  enum:
                  - open
                  - closed
                  description: Whether or not the post can be pinged.
                meta:
                  type: object
                  description: Meta fields.
                template:
                  type: string
                  description: The theme file to use to display the post.
                alt_text:
                  type: string
                  description: Alternative text to display when attachment is not displayed.
                caption:
                  type: object
                  description: The attachment caption.
                description:
                  type: object
                  description: The attachment description.
                post:
                  type: integer
                  description: The ID for the associated post of the attachment.
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      security:
      - applicationPassword: []
    delete:
      operationId: deleteMediaById
      summary: DELETE /wp/v2/media/{id}
      tags:
      - Media
      parameters:
      - name: id
        in: query
        required: false
        schema:
          type: integer
        description: Unique identifier for the post.
      - name: force
        in: query
        required: false
        schema:
          type: boolean
          default: false
        description: Whether to bypass Trash and force deletion.
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      security:
      - applicationPassword: []
  /wp/v2/media/{id}/edit:
    parameters:
    - name: id
      in: path
      required: true
      schema:
        type: string
    post:
      operationId: createMediaByIdEdit
      summary: POST /wp/v2/media/{id}/edit
      tags:
      - Media
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                src:
                  type: string
                  format: uri
                  description: URL to the edited image file.
                modifiers:
                  type: array
                  items:
                    type: object
                  description: Array of image edits.
                rotation:
                  type: integer
                  minimum: 0
                  maximum: 360
                  description: 'The amount to rotate the image clockwise in degrees. DEPRECATED: Use `modifiers` instead.'
                x:
                  type: number
                  minimum: 0
                  maximum: 100
                  description: 'As a percentage of the image, the x position to start the crop from. DEPRECATED: Use `modifiers` instead.'
                y:
                  type: number
                  minimum: 0
                  maximum: 100
                  description: 'As a percentage of the image, the y position to start the crop from. DEPRECATED: Use `modifiers` instead.'
                width:
                  type: number
                  minimum: 0
                  maximum: 100
                  description: 'As a percentage of the image, the width to crop the image to. DEPRECATED: Use `modifiers` instead.'
                height:
                  type: number
                  minimum: 0
                  maximum: 100
                  description: 'As a percentage of the image, the height to crop the image to. DEPRECATED: Use `modifiers` instead.'
                caption:
                  type: object
                  description: The attachment caption.
                description:
                  type: object
                  description: The attachment description.
                title:
                  type: object
                  description: The title for the post.
                post:
                  type: integer
                  description: The ID for the associated post of the attachment.
                alt_text:
                  type: string
                  description: Alternative text to display when attachment is not displayed.
              required:
              - src
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      security:
      - applicationPassword: []
components:
  responses:
    NotFound:
      description: No route or resource matched (rest_no_route / rest_post_invalid_id).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/WpError'
    BadRequest:
      description: Invalid parameter (rest_invalid_param).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/WpError'
    Unauthorized:
      description: Authentication required or rejected (rest_forbidden / rest_not_logged_in).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/WpError'
    Forbidden:
      description: Authenticated but not permitted (rest_cannot_view / rest_forbidden).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/WpError'
  schemas:
    WpError:
      type: object
      description: The WordPress REST API error envelope (WP_Error serialized to JSON).
      properties:
        code:
          type: string
          description: Machine-readable error code, e.g. rest_forbidden.
        message:
          type: string
          description: Human-readable error message.
        data:
          type: object
          properties:
            status:
              type: integer
  securitySchemes:
    applicationPassword:
      type: http
      scheme: basic
      description: WordPress Application Passwords, advertised by the site at https://boundlessbio.com/wp-json/ under authentication.application-passwords; authorization endpoint https://boundlessbio.com/wp-admin/authorize-application.php. Read operations on wp/v2 are anonymous.