Harbinger Health Media API

WordPress media resource routes.

OpenAPI Specification

harbinger-health-media-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Harbinger Health WordPress REST API (wp/v2) Media API
  version: 2.0.0
  summary: The wp/v2 namespace of the WordPress REST API served by Harbinger Health's website.
  description: DERIVED, NOT PUBLISHED BY HARBINGER HEALTH. Harbinger Health publishes no OpenAPI definition and does not document or support this surface as a developer product. This document was derived mechanically by API Evangelist from the live WordPress route-discovery document fetched from https://harbinger-health.com/wp-json/ on 2026-08-04 (268 routes across 15 namespaces; the wp/v2 namespace is captured here). Every path, method, parameter name, type, enum, default and description is copied verbatim from that discovery document. Response bodies are intentionally left as generic objects because the discovery document does not publish response schemas; error responses are grounded in payloads probed live against this host. This is a content-management surface for the corporate website - it is NOT a clinical, laboratory, diagnostic, genomic or patient-data API, and no Harbinger HX or RESOLVE test data is reachable through it.
  contact:
    name: Harbinger Health
    url: https://harbinger-health.com/contact/
    email: info@harbinger-health.com
  x-apievangelist-method: derived
  x-apievangelist-source: openapi/harbinger-health-wp-json-discovery.json
  x-apievangelist-derived: '2026-08-04'
  x-upstream-documentation: https://developer.wordpress.org/rest-api/
servers:
- url: https://harbinger-health.com/wp-json
  description: Harbinger Health corporate site (WP Engine, fronted by Cloudflare)
tags:
- name: media
  description: WordPress media resource routes.
paths:
  /wp/v2/media:
    get:
      operationId: listMedia
      summary: GET /wp/v2/media
      tags:
      - media
      parameters:
      - name: context
        in: query
        required: false
        schema:
          type: string
          enum:
          - view
          - embed
          - edit
          default: view
        description: Scope under which the request is made; determines fields present in response.
      - name: page
        in: query
        required: false
        schema:
          type: integer
          default: 1
          minimum: 1
        description: Current page of the collection.
      - name: per_page
        in: query
        required: false
        schema:
          type: integer
          default: 10
          minimum: 1
          maximum: 100
        description: Maximum number of items to be returned in result set.
      - name: search
        in: query
        required: false
        schema:
          type: string
        description: Limit results to those matching a string.
      - name: after
        in: query
        required: false
        schema:
          type: string
          format: date-time
        description: Limit response to posts published after a given ISO8601 compliant date.
      - name: modified_after
        in: query
        required: false
        schema:
          type: string
          format: date-time
        description: Limit response to posts modified after a given ISO8601 compliant date.
      - name: author
        in: query
        required: false
        schema:
          type: array
          default: []
          items:
            type: integer
        description: Limit result set to posts assigned to specific authors.
      - name: author_exclude
        in: query
        required: false
        schema:
          type: array
          default: []
          items:
            type: integer
        description: Ensure result set excludes posts assigned to specific authors.
      - name: before
        in: query
        required: false
        schema:
          type: string
          format: date-time
        description: Limit response to posts published before a given ISO8601 compliant date.
      - name: modified_before
        in: query
        required: false
        schema:
          type: string
          format: date-time
        description: Limit response to posts modified before a given ISO8601 compliant date.
      - name: exclude
        in: query
        required: false
        schema:
          type: array
          default: []
          items:
            type: integer
        description: Ensure result set excludes specific IDs.
      - name: include
        in: query
        required: false
        schema:
          type: array
          default: []
          items:
            type: integer
        description: Limit result set to specific IDs.
      - name: search_semantics
        in: query
        required: false
        schema:
          type: string
          enum:
          - exact
        description: How to interpret the search input.
      - name: offset
        in: query
        required: false
        schema:
          type: integer
        description: Offset the result set by a specific number of items.
      - name: order
        in: query
        required: false
        schema:
          type: string
          enum:
          - asc
          - desc
          default: desc
        description: Order sort attribute ascending or descending.
      - name: orderby
        in: query
        required: false
        schema:
          type: string
          enum:
          - author
          - date
          - id
          - include
          - modified
          - parent
          - relevance
          - slug
          - include_slugs
          - title
          default: date
        description: Sort collection by post attribute.
      - name: parent
        in: query
        required: false
        schema:
          type: array
          default: []
          items:
            type: integer
        description: Limit result set to items with particular parent IDs.
      - name: parent_exclude
        in: query
        required: false
        schema:
          type: array
          default: []
          items:
            type: integer
        description: Limit result set to all items except those of a particular parent ID.
      - name: search_columns
        in: query
        required: false
        schema:
          type: array
          default: []
          items:
            type: string
            enum:
            - post_title
            - post_content
            - post_excerpt
        description: Array of column names to be searched.
      - name: slug
        in: query
        required: false
        schema:
          type: array
          items:
            type: string
        description: Limit result set to posts with one or more specific slugs.
      - name: status
        in: query
        required: false
        schema:
          type: array
          default: inherit
          items:
            type: string
            enum:
            - inherit
            - private
            - trash
        description: Limit result set to posts assigned one or more statuses.
      - name: media_type
        in: query
        required: false
        schema:
          type: array
          items:
            type: string
            enum:
            - image
            - video
            - text
            - application
            - audio
        description: Limit result set to attachments of a particular media type or media types.
      - name: mime_type
        in: query
        required: false
        schema:
          type: array
          items:
            type: string
        description: Limit result set to attachments of a particular MIME type or MIME types.
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
    post:
      operationId: createMedia
      summary: POST /wp/v2/media
      tags:
      - media
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                date:
                  type: string
                  format: date-time
                  description: The date the post was published, in the site's timezone.
                date_gmt:
                  type: string
                  format: date-time
                  description: The date the post was published, as GMT.
                slug:
                  type: string
                  description: An alphanumeric identifier for the post unique to its type.
                status:
                  type: string
                  enum:
                  - publish
                  - future
                  - draft
                  - pending
                  - private
                  - acf-disabled
                  description: A named status for the post.
                title:
                  type: object
                  description: The title for the post.
                author:
                  type: integer
                  description: The ID for the author of the post.
                featured_media:
                  type: integer
                  description: The ID of the featured media for the post.
                comment_status:
                  type: string
                  enum:
                  - open
                  - closed
                  description: Whether or not comments are open on the post.
                ping_status:
                  type: string
                  enum:
                  - open
                  - closed
                  description: Whether or not the post can be pinged.
                meta:
                  type: object
                  description: Meta fields.
                template:
                  type: string
                  description: The theme file to use to display the post.
                smush:
                  type: string
                  description: Smush data.
                alt_text:
                  type: string
                  description: Alternative text to display when attachment is not displayed.
                caption:
                  type: object
                  description: The attachment caption.
                description:
                  type: object
                  description: The attachment description.
                post:
                  type: integer
                  description: The ID for the associated post of the attachment.
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
  /wp/v2/media/{id}:
    get:
      operationId: getMediaById
      summary: GET /wp/v2/media/{id}
      tags:
      - media
      parameters:
      - name: id
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      - name: context
        in: query
        required: false
        schema:
          type: string
          enum:
          - view
          - embed
          - edit
          default: view
        description: Scope under which the request is made; determines fields present in response.
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
    post:
      operationId: createMediaById
      summary: POST /wp/v2/media/{id}
      tags:
      - media
      parameters:
      - name: id
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                date:
                  type: string
                  format: date-time
                  description: The date the post was published, in the site's timezone.
                date_gmt:
                  type: string
                  format: date-time
                  description: The date the post was published, as GMT.
                slug:
                  type: string
                  description: An alphanumeric identifier for the post unique to its type.
                status:
                  type: string
                  enum:
                  - publish
                  - future
                  - draft
                  - pending
                  - private
                  - acf-disabled
                  description: A named status for the post.
                title:
                  type: object
                  description: The title for the post.
                author:
                  type: integer
                  description: The ID for the author of the post.
                featured_media:
                  type: integer
                  description: The ID of the featured media for the post.
                comment_status:
                  type: string
                  enum:
                  - open
                  - closed
                  description: Whether or not comments are open on the post.
                ping_status:
                  type: string
                  enum:
                  - open
                  - closed
                  description: Whether or not the post can be pinged.
                meta:
                  type: object
                  description: Meta fields.
                template:
                  type: string
                  description: The theme file to use to display the post.
                smush:
                  type: string
                  description: Smush data.
                alt_text:
                  type: string
                  description: Alternative text to display when attachment is not displayed.
                caption:
                  type: object
                  description: The attachment caption.
                description:
                  type: object
                  description: The attachment description.
                post:
                  type: integer
                  description: The ID for the associated post of the attachment.
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
    put:
      operationId: replaceMediaById
      summary: PUT /wp/v2/media/{id}
      tags:
      - media
      parameters:
      - name: id
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                date:
                  type: string
                  format: date-time
                  description: The date the post was published, in the site's timezone.
                date_gmt:
                  type: string
                  format: date-time
                  description: The date the post was published, as GMT.
                slug:
                  type: string
                  description: An alphanumeric identifier for the post unique to its type.
                status:
                  type: string
                  enum:
                  - publish
                  - future
                  - draft
                  - pending
                  - private
                  - acf-disabled
                  description: A named status for the post.
                title:
                  type: object
                  description: The title for the post.
                author:
                  type: integer
                  description: The ID for the author of the post.
                featured_media:
                  type: integer
                  description: The ID of the featured media for the post.
                comment_status:
                  type: string
                  enum:
                  - open
                  - closed
                  description: Whether or not comments are open on the post.
                ping_status:
                  type: string
                  enum:
                  - open
                  - closed
                  description: Whether or not the post can be pinged.
                meta:
                  type: object
                  description: Meta fields.
                template:
                  type: string
                  description: The theme file to use to display the post.
                smush:
                  type: string
                  description: Smush data.
                alt_text:
                  type: string
                  description: Alternative text to display when attachment is not displayed.
                caption:
                  type: object
                  description: The attachment caption.
                description:
                  type: object
                  description: The attachment description.
                post:
                  type: integer
                  description: The ID for the associated post of the attachment.
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
    patch:
      operationId: updateMediaById
      summary: PATCH /wp/v2/media/{id}
      tags:
      - media
      parameters:
      - name: id
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                date:
                  type: string
                  format: date-time
                  description: The date the post was published, in the site's timezone.
                date_gmt:
                  type: string
                  format: date-time
                  description: The date the post was published, as GMT.
                slug:
                  type: string
                  description: An alphanumeric identifier for the post unique to its type.
                status:
                  type: string
                  enum:
                  - publish
                  - future
                  - draft
                  - pending
                  - private
                  - acf-disabled
                  description: A named status for the post.
                title:
                  type: object
                  description: The title for the post.
                author:
                  type: integer
                  description: The ID for the author of the post.
                featured_media:
                  type: integer
                  description: The ID of the featured media for the post.
                comment_status:
                  type: string
                  enum:
                  - open
                  - closed
                  description: Whether or not comments are open on the post.
                ping_status:
                  type: string
                  enum:
                  - open
                  - closed
                  description: Whether or not the post can be pinged.
                meta:
                  type: object
                  description: Meta fields.
                template:
                  type: string
                  description: The theme file to use to display the post.
                smush:
                  type: string
                  description: Smush data.
                alt_text:
                  type: string
                  description: Alternative text to display when attachment is not displayed.
                caption:
                  type: object
                  description: The attachment caption.
                description:
                  type: object
                  description: The attachment description.
                post:
                  type: integer
                  description: The ID for the associated post of the attachment.
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
    delete:
      operationId: deleteMediaById
      summary: DELETE /wp/v2/media/{id}
      tags:
      - media
      parameters:
      - name: id
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      - name: force
        in: query
        required: false
        schema:
          type: boolean
          default: false
        description: Whether to bypass Trash and force deletion.
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
  /wp/v2/media/{id}/edit:
    post:
      operationId: createMediaByIdEdit
      summary: POST /wp/v2/media/{id}/edit
      tags:
      - media
      parameters:
      - name: id
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                src:
                  type: string
                  format: uri
                  description: URL to the edited image file.
                modifiers:
                  type: array
                  items:
                    type: object
                  description: Array of image edits.
                rotation:
                  type: integer
                  minimum: 0
                  maximum: 360
                  description: 'The amount to rotate the image clockwise in degrees. DEPRECATED: Use `modifiers` instead.'
                x:
                  type: number
                  minimum: 0
                  maximum: 100
                  description: 'As a percentage of the image, the x position to start the crop from. DEPRECATED: Use `modifiers` instead.'
                y:
                  type: number
                  minimum: 0
                  maximum: 100
                  description: 'As a percentage of the image, the y position to start the crop from. DEPRECATED: Use `modifiers` instead.'
                width:
                  type: number
                  minimum: 0
                  maximum: 100
                  description: 'As a percentage of the image, the width to crop the image to. DEPRECATED: Use `modifiers` instead.'
                height:
                  type: number
                  minimum: 0
                  maximum: 100
                  description: 'As a percentage of the image, the height to crop the image to. DEPRECATED: Use `modifiers` instead.'
                caption:
                  type: object
                  description: The attachment caption.
                description:
                  type: object
                  description: The attachment description.
                title:
                  type: object
                  description: The title for the post.
                post:
                  type: integer
                  description: The ID for the associated post of the attachment.
                alt_text:
                  type: string
                  description: Alternative text to display when attachment is not displayed.
              required:
              - src
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
  /wp/v2/media/{id}/post-process:
    post:
      operationId: createMediaByIdPostProcess
      summary: POST /wp/v2/media/{id}/post-process
      tags:
      - media
      parameters:
      - name: id
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                action:
                  type: string
                  enum:
                  - create-image-subsizes
              required:
              - action
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
components:
  schemas:
    WPError:
      type: object
      description: The WordPress REST error envelope, observed live on this host.
      properties:
        code:
          type: string
          description: Machine-readable error code, e.g. rest_forbidden.
        message:
          type: string
          description: Human-readable error message.
        data:
          type: object
          properties:
            status:
              type: integer
              description: HTTP status code.
      required:
      - code
      - message
  securitySchemes:
    applicationPassword:
      type: http
      scheme: basic
      description: WordPress application password, advertised by the site's route-discovery document at authentication.application-passwords. Issued from https://harbinger-health.com/wp-admin/authorize-application.php. Anonymous callers may read the public view/embed context without any credential.