Harbinger Health Users API

WordPress users resource routes.

OpenAPI Specification

harbinger-health-users-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Harbinger Health WordPress REST API (wp/v2) Users API
  version: 2.0.0
  summary: The wp/v2 namespace of the WordPress REST API served by Harbinger Health's website.
  description: DERIVED, NOT PUBLISHED BY HARBINGER HEALTH. Harbinger Health publishes no OpenAPI definition and does not document or support this surface as a developer product. This document was derived mechanically by API Evangelist from the live WordPress route-discovery document fetched from https://harbinger-health.com/wp-json/ on 2026-08-04 (268 routes across 15 namespaces; the wp/v2 namespace is captured here). Every path, method, parameter name, type, enum, default and description is copied verbatim from that discovery document. Response bodies are intentionally left as generic objects because the discovery document does not publish response schemas; error responses are grounded in payloads probed live against this host. This is a content-management surface for the corporate website - it is NOT a clinical, laboratory, diagnostic, genomic or patient-data API, and no Harbinger HX or RESOLVE test data is reachable through it.
  contact:
    name: Harbinger Health
    url: https://harbinger-health.com/contact/
    email: info@harbinger-health.com
  x-apievangelist-method: derived
  x-apievangelist-source: openapi/harbinger-health-wp-json-discovery.json
  x-apievangelist-derived: '2026-08-04'
  x-upstream-documentation: https://developer.wordpress.org/rest-api/
servers:
- url: https://harbinger-health.com/wp-json
  description: Harbinger Health corporate site (WP Engine, fronted by Cloudflare)
tags:
- name: users
  description: WordPress users resource routes.
paths:
  /wp/v2/users:
    get:
      operationId: listUsers
      summary: GET /wp/v2/users
      tags:
      - users
      parameters:
      - name: context
        in: query
        required: false
        schema:
          type: string
          enum:
          - view
          - embed
          - edit
          default: view
        description: Scope under which the request is made; determines fields present in response.
      - name: page
        in: query
        required: false
        schema:
          type: integer
          default: 1
          minimum: 1
        description: Current page of the collection.
      - name: per_page
        in: query
        required: false
        schema:
          type: integer
          default: 10
          minimum: 1
          maximum: 100
        description: Maximum number of items to be returned in result set.
      - name: search
        in: query
        required: false
        schema:
          type: string
        description: Limit results to those matching a string.
      - name: exclude
        in: query
        required: false
        schema:
          type: array
          default: []
          items:
            type: integer
        description: Ensure result set excludes specific IDs.
      - name: include
        in: query
        required: false
        schema:
          type: array
          default: []
          items:
            type: integer
        description: Limit result set to specific IDs.
      - name: offset
        in: query
        required: false
        schema:
          type: integer
        description: Offset the result set by a specific number of items.
      - name: order
        in: query
        required: false
        schema:
          type: string
          enum:
          - asc
          - desc
          default: asc
        description: Order sort attribute ascending or descending.
      - name: orderby
        in: query
        required: false
        schema:
          type: string
          enum:
          - id
          - include
          - name
          - registered_date
          - slug
          - include_slugs
          - email
          - url
          default: name
        description: Sort collection by user attribute.
      - name: slug
        in: query
        required: false
        schema:
          type: array
          items:
            type: string
        description: Limit result set to users with one or more specific slugs.
      - name: roles
        in: query
        required: false
        schema:
          type: array
          items:
            type: string
        description: Limit result set to users matching at least one specific role provided. Accepts csv list or single role.
      - name: capabilities
        in: query
        required: false
        schema:
          type: array
          items:
            type: string
        description: Limit result set to users matching at least one specific capability provided. Accepts csv list or single capability.
      - name: who
        in: query
        required: false
        schema:
          type: string
          enum:
          - authors
        description: Limit result set to users who are considered authors.
      - name: has_published_posts
        in: query
        required: false
        schema:
          type: boolean
        description: Limit result set to users who have published posts.
      - name: search_columns
        in: query
        required: false
        schema:
          type: array
          default: []
          items:
            type: string
            enum:
            - email
            - name
            - id
            - username
            - slug
        description: Array of column names to be searched.
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
    post:
      operationId: createUsers
      summary: POST /wp/v2/users
      tags:
      - users
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                username:
                  type: string
                  description: Login name for the user.
                name:
                  type: string
                  description: Display name for the user.
                first_name:
                  type: string
                  description: First name for the user.
                last_name:
                  type: string
                  description: Last name for the user.
                email:
                  type: string
                  format: email
                  description: The email address for the user.
                url:
                  type: string
                  format: uri
                  description: URL of the user.
                description:
                  type: string
                  description: Description of the user.
                locale:
                  type: string
                  enum:
                  - ''
                  - en_US
                  description: Locale for the user.
                nickname:
                  type: string
                  description: The nickname for the user.
                slug:
                  type: string
                  description: An alphanumeric identifier for the user.
                roles:
                  type: array
                  items:
                    type: string
                  description: Roles assigned to the user.
                password:
                  type: string
                  description: Password for the user (never included).
                meta:
                  type: object
                  description: Meta fields.
              required:
              - username
              - email
              - password
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
  /wp/v2/users/{id}:
    get:
      operationId: getUsersById
      summary: GET /wp/v2/users/{id}
      tags:
      - users
      parameters:
      - name: id
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      - name: context
        in: query
        required: false
        schema:
          type: string
          enum:
          - view
          - embed
          - edit
          default: view
        description: Scope under which the request is made; determines fields present in response.
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
    post:
      operationId: createUsersById
      summary: POST /wp/v2/users/{id}
      tags:
      - users
      parameters:
      - name: id
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                username:
                  type: string
                  description: Login name for the user.
                name:
                  type: string
                  description: Display name for the user.
                first_name:
                  type: string
                  description: First name for the user.
                last_name:
                  type: string
                  description: Last name for the user.
                email:
                  type: string
                  format: email
                  description: The email address for the user.
                url:
                  type: string
                  format: uri
                  description: URL of the user.
                description:
                  type: string
                  description: Description of the user.
                locale:
                  type: string
                  enum:
                  - ''
                  - en_US
                  description: Locale for the user.
                nickname:
                  type: string
                  description: The nickname for the user.
                slug:
                  type: string
                  description: An alphanumeric identifier for the user.
                roles:
                  type: array
                  items:
                    type: string
                  description: Roles assigned to the user.
                password:
                  type: string
                  description: Password for the user (never included).
                meta:
                  type: object
                  description: Meta fields.
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
    put:
      operationId: replaceUsersById
      summary: PUT /wp/v2/users/{id}
      tags:
      - users
      parameters:
      - name: id
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                username:
                  type: string
                  description: Login name for the user.
                name:
                  type: string
                  description: Display name for the user.
                first_name:
                  type: string
                  description: First name for the user.
                last_name:
                  type: string
                  description: Last name for the user.
                email:
                  type: string
                  format: email
                  description: The email address for the user.
                url:
                  type: string
                  format: uri
                  description: URL of the user.
                description:
                  type: string
                  description: Description of the user.
                locale:
                  type: string
                  enum:
                  - ''
                  - en_US
                  description: Locale for the user.
                nickname:
                  type: string
                  description: The nickname for the user.
                slug:
                  type: string
                  description: An alphanumeric identifier for the user.
                roles:
                  type: array
                  items:
                    type: string
                  description: Roles assigned to the user.
                password:
                  type: string
                  description: Password for the user (never included).
                meta:
                  type: object
                  description: Meta fields.
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
    patch:
      operationId: updateUsersById
      summary: PATCH /wp/v2/users/{id}
      tags:
      - users
      parameters:
      - name: id
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                username:
                  type: string
                  description: Login name for the user.
                name:
                  type: string
                  description: Display name for the user.
                first_name:
                  type: string
                  description: First name for the user.
                last_name:
                  type: string
                  description: Last name for the user.
                email:
                  type: string
                  format: email
                  description: The email address for the user.
                url:
                  type: string
                  format: uri
                  description: URL of the user.
                description:
                  type: string
                  description: Description of the user.
                locale:
                  type: string
                  enum:
                  - ''
                  - en_US
                  description: Locale for the user.
                nickname:
                  type: string
                  description: The nickname for the user.
                slug:
                  type: string
                  description: An alphanumeric identifier for the user.
                roles:
                  type: array
                  items:
                    type: string
                  description: Roles assigned to the user.
                password:
                  type: string
                  description: Password for the user (never included).
                meta:
                  type: object
                  description: Meta fields.
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
    delete:
      operationId: deleteUsersById
      summary: DELETE /wp/v2/users/{id}
      tags:
      - users
      parameters:
      - name: id
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      - name: force
        in: query
        required: false
        schema:
          type: boolean
          default: false
        description: Required to be true, as users do not support trashing.
      - name: reassign
        in: query
        required: true
        schema:
          type: integer
        description: Reassign the deleted user's posts and links to this user ID.
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
  /wp/v2/users/{user_id}/application-passwords:
    get:
      operationId: getUsersByUserIdApplicationPasswords
      summary: GET /wp/v2/users/{user_id}/application-passwords
      tags:
      - users
      parameters:
      - name: user_id
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      - name: context
        in: query
        required: false
        schema:
          type: string
          enum:
          - view
          - embed
          - edit
          default: view
        description: Scope under which the request is made; determines fields present in response.
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
    post:
      operationId: createUsersByUserIdApplicationPasswords
      summary: POST /wp/v2/users/{user_id}/application-passwords
      tags:
      - users
      parameters:
      - name: user_id
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                app_id:
                  type: string
                  description: A UUID provided by the application to uniquely identify it. It is recommended to use an UUID v5 with the URL or DNS namespace.
                name:
                  type: string
                  description: The name of the application password.
              required:
              - name
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
    delete:
      operationId: deleteUsersByUserIdApplicationPasswords
      summary: DELETE /wp/v2/users/{user_id}/application-passwords
      tags:
      - users
      parameters:
      - name: user_id
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
  /wp/v2/users/{user_id}/application-passwords/{uuid}:
    get:
      operationId: getUsersByUserIdApplicationPasswordsByUuid
      summary: GET /wp/v2/users/{user_id}/application-passwords/{uuid}
      tags:
      - users
      parameters:
      - name: user_id
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      - name: uuid
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      - name: context
        in: query
        required: false
        schema:
          type: string
          enum:
          - view
          - embed
          - edit
          default: view
        description: Scope under which the request is made; determines fields present in response.
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
    post:
      operationId: createUsersByUserIdApplicationPasswordsByUuid
      summary: POST /wp/v2/users/{user_id}/application-passwords/{uuid}
      tags:
      - users
      parameters:
      - name: user_id
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      - name: uuid
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                app_id:
                  type: string
                  description: A UUID provided by the application to uniquely identify it. It is recommended to use an UUID v5 with the URL or DNS namespace.
                name:
                  type: string
                  description: The name of the application password.
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
    put:
      operationId: replaceUsersByUserIdApplicationPasswordsByUuid
      summary: PUT /wp/v2/users/{user_id}/application-passwords/{uuid}
      tags:
      - users
      parameters:
      - name: user_id
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      - name: uuid
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                app_id:
                  type: string
                  description: A UUID provided by the application to uniquely identify it. It is recommended to use an UUID v5 with the URL or DNS namespace.
                name:
                  type: string
                  description: The name of the application password.
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish response schemas, so the body is described generically.
          content:
            application/json:
              schema: {}
        '400':
          description: Invalid parameter.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '401':
          description: Authentication required or insufficient capability (rest_forbidden).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
        '404':
          description: No route or resource matched (rest_no_route / rest_post_invalid_id).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WPError'
    patch:
      operationId: updateUsersByUserIdApplicationPasswordsByUuid
      summary: PATCH /wp/v2/users/{user_id}/application-passwords/{uuid}
      tags:
      - users
      parameters:
      - name: user_id
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      - name: uuid
        in: path
        required: true
        description: Path segment captured by the WordPress route regex.
        schema:
          type: string
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                app_id:
                  type: string
                  description: A UUID provided by the application to uniquely identify it. It is recommended to use an UUID v5 with the URL or DNS namespace.
                name:
                  type: string
                  description: The name of the application password.
      responses:
        '200':
          description: Successful response. WordPress route discovery does not publish

# --- truncated at 32 KB (47 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/harbinger-health/refs/heads/main/openapi/harbinger-health-users-api-openapi.yml