Habiteo Site Content API — Settings API

Site settings. Anonymous calls return HTTP 403 rest_forbidden — recorded as a gated route, not a readable one. DERIVED by API Evangelist from the WordPress REST route index at https://www.habiteo.com/wp-json/ — this is the CMS content API behind the marketing site, NOT a Habiteo product API. Habiteo publishes no contract for myHabiteo, the configurator or the MegaWidget.

OpenAPI Specification

habiteo-settings-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Habiteo Site Content API (WordPress REST wp-json) Settings API
  version: wp-json
  summary: Anonymous read surface of the WordPress REST API that www.habiteo.com serves.
  description: 'Habiteo publishes www.habiteo.com on WordPress, which exposes the WordPress REST API at https://www.habiteo.com/wp-json/.
    The wp/v2 namespace is anonymously readable and returns the company''s news posts, marketing pages, portfolio
    entries, media library, taxonomies and users as JSON.


    This document was DERIVED mechanically by API Evangelist from the route-discovery document served at https://www.habiteo.com/wp-json/
    on 2026-08-17 — every path, method and parameter below is taken verbatim from that descriptor. Habiteo publishes
    no OpenAPI, no developer portal and no API documentation of its own, and THIS IS NOT A HABITEO PRODUCT API:
    it is the content API the CMS exposes. Habiteo''s actual products (myHabiteo, the 3D configurator, the MegaWidget)
    have no published contract. Write operations exist on these routes but require WordPress authentication (Application
    Passwords over HTTP Basic, or a cookie + nonce).'
  contact:
    name: Habiteo
    url: https://www.habiteo.com/
  x-derived-by: API Evangelist enrichment pipeline
  x-derived-from: https://www.habiteo.com/wp-json/
  x-derived-on: '2026-08-17'
  x-provider-published: false
servers:
- url: https://www.habiteo.com/wp-json
  description: Production
tags:
- name: Settings
paths:
  /wp/v2/settings:
    get:
      operationId: getWpV2Settings
      summary: GET /wp/v2/settings
      tags:
      - Settings
      responses:
        '200':
          description: Successful response.
          content:
            application/json:
              schema:
                type: object
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Not authenticated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '403':
          description: rest_forbidden — the anonymous caller may not perform this action.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
    post:
      operationId: postWpV2Settings
      summary: POST /wp/v2/settings
      tags:
      - Settings
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                title:
                  type: string
                  description: Titre du site.
                description:
                  type: string
                  description: Slogan du site.
                url:
                  type: string
                  description: URL du site.
                email:
                  type: string
                  description: Cette adresse est utilisée à des fins d’administration, comme les notifications d’utilisateur.
                timezone:
                  type: string
                  description: Une ville dans le même fuseau horaire que le vôtre.
                date_format:
                  type: string
                  description: Un format de date commun pour tous les réglages de dates.
                time_format:
                  type: string
                  description: Un format d’heure commun pour tous les réglages d’heures.
                start_of_week:
                  type: integer
                  description: Le numéro du jour de la semaine à laquelle la semaine devrait commencer.
                language:
                  type: string
                  description: Code local de l’installation WordPress.
                use_smilies:
                  type: boolean
                  description: Convertir les émoticônes, comme :-) et :-P, en images lors de l’affichage.
                default_category:
                  type: integer
                  description: Catégorie d’article par défaut.
                default_post_format:
                  type: string
                  description: Format d’article par défaut.
                posts_per_page:
                  type: integer
                  description: Les pages de blog affichent au maximum.
                default_ping_status:
                  type: string
                  enum:
                  - open
                  - closed
                  description: Autoriser les liens de notification d’autres blogs (pings et rétroliens) sur les
                    nouveaux articles.
                default_comment_status:
                  type: string
                  enum:
                  - open
                  - closed
                  description: Autoriser les lecteurs à publier des commentaires sur les nouveaux articles.
      responses:
        '200':
          description: Successful response.
          content:
            application/json:
              schema:
                type: object
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Not authenticated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '403':
          description: rest_forbidden — the anonymous caller may not perform this action.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
      security:
      - basicAuth: []
      - cookieNonce: []
components:
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
      description: WordPress Application Passwords over HTTP Basic. Required for every write operation.
    cookieNonce:
      type: apiKey
      in: header
      name: X-WP-Nonce
      description: WordPress logged-in cookie plus an X-WP-Nonce header, used by first-party admin clients.
  schemas:
    WPError:
      type: object
      description: The WordPress REST error envelope. Not RFC 9457 problem+json.
      properties:
        code:
          type: string
          description: Machine-readable error code, e.g. rest_post_invalid_id.
        message:
          type: string
          description: Human-readable message. Localized — this install answers in French.
        data:
          type: object
          properties:
            status:
              type: integer
              description: HTTP status repeated in the body.