Lish Media API

Media library items (images, attachments).

OpenAPI Specification

lish-media-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Lish WordPress REST Categories Media API
  version: wp/v2
  summary: Public read surface of the WordPress REST API behind lishfood.com.
  description: 'Lish (lishfood.com) is a corporate catering and workplace food service company serving Seattle and the Bellevue/Eastside area. Lish does not publish a product API for its catering platform. This document describes the one genuinely public, self-describing HTTP API the company does expose: the WordPress REST API that backs its marketing site and blog, reachable at https://www.lishfood.com/wp-json/ (the WordPress install reports its home as https://wordpress.lishfood.com).


    This specification was DERIVED by the API Evangelist enrichment pipeline from the live route index — every path, method, parameter name, type, default and enum is taken from `routes[].endpoints[].args` as served on 2026-07-19. It is scoped to the publicly readable `wp/v2` core content surface (posts, pages, categories, tags, comments, media, users, search, types, taxonomies, statuses). The live index also advertises 348 routes across 21 namespaces, most of which belong to plugins (Elementor, Yoast, Wordfence, Contact Form 7, JupiterX, Redirection, WP Smush, Salesforce, WP Engine) and require authentication.


    Write methods (POST/PUT/PATCH/DELETE) are advertised by the index but require authentication and are intentionally not documented here.'
  contact:
    name: Lish
    email: catering@lishfood.com
    url: https://www.lishfood.com/pages/contact-us
  license:
    name: GPL-2.0-or-later
    url: https://www.gnu.org/licenses/old-licenses/gpl-2.0.html
  x-derived-by: api-evangelist enrichment pipeline
  x-derived-from: https://www.lishfood.com/wp-json/
  x-derived-on: '2026-07-19'
  x-upstream-project: https://developer.wordpress.org/rest-api/
servers:
- url: https://www.lishfood.com/wp-json
  description: Production WordPress REST API
security: []
tags:
- name: Media
  description: Media library items (images, attachments).
paths:
  /wp/v2/media:
    get:
      operationId: listMedia
      summary: List media
      description: Retrieve a paginated collection of media. Parameters are taken verbatim from the live route index.
      tags:
      - Media
      parameters:
      - name: after
        in: query
        required: false
        schema:
          type: string
          format: date-time
        description: Limit response to posts published after a given ISO8601 compliant date.
      - name: author
        in: query
        required: false
        schema:
          type: array
          items:
            type: integer
          default: []
        description: Limit result set to posts assigned to specific authors.
      - name: author_exclude
        in: query
        required: false
        schema:
          type: array
          items:
            type: integer
          default: []
        description: Ensure result set excludes posts assigned to specific authors.
      - name: before
        in: query
        required: false
        schema:
          type: string
          format: date-time
        description: Limit response to posts published before a given ISO8601 compliant date.
      - name: context
        in: query
        required: false
        schema:
          type: string
          enum:
          - view
          - embed
          - edit
          default: view
        description: Scope under which the request is made; determines fields present in response.
      - name: exclude
        in: query
        required: false
        schema:
          type: array
          items:
            type: integer
          default: []
        description: Ensure result set excludes specific IDs.
      - name: include
        in: query
        required: false
        schema:
          type: array
          items:
            type: integer
          default: []
        description: Limit result set to specific IDs.
      - name: media_type
        in: query
        required: false
        schema:
          type: array
          items:
            type: string
            enum:
            - image
            - video
            - text
            - application
            - audio
        description: Limit result set to attachments of a particular media type or media types.
      - name: mime_type
        in: query
        required: false
        schema:
          type: array
          items:
            type: string
        description: Limit result set to attachments of a particular MIME type or MIME types.
      - name: modified_after
        in: query
        required: false
        schema:
          type: string
          format: date-time
        description: Limit response to posts modified after a given ISO8601 compliant date.
      - name: modified_before
        in: query
        required: false
        schema:
          type: string
          format: date-time
        description: Limit response to posts modified before a given ISO8601 compliant date.
      - name: offset
        in: query
        required: false
        schema:
          type: integer
        description: Offset the result set by a specific number of items.
      - name: order
        in: query
        required: false
        schema:
          type: string
          enum:
          - asc
          - desc
          default: desc
        description: Order sort attribute ascending or descending.
      - name: orderby
        in: query
        required: false
        schema:
          type: string
          enum:
          - author
          - date
          - id
          - include
          - modified
          - parent
          - relevance
          - slug
          - include_slugs
          - title
          default: date
        description: Sort collection by post attribute.
      - name: page
        in: query
        required: false
        schema:
          type: integer
          default: 1
          minimum: 1
        description: Current page of the collection.
      - name: parent
        in: query
        required: false
        schema:
          type: array
          items:
            type: integer
          default: []
        description: Limit result set to items with particular parent IDs.
      - name: parent_exclude
        in: query
        required: false
        schema:
          type: array
          items:
            type: integer
          default: []
        description: Limit result set to all items except those of a particular parent ID.
      - name: per_page
        in: query
        required: false
        schema:
          type: integer
          default: 10
          minimum: 1
          maximum: 100
        description: Maximum number of items to be returned in result set.
      - name: search
        in: query
        required: false
        schema:
          type: string
        description: Limit results to those matching a string.
      - name: search_columns
        in: query
        required: false
        schema:
          type: array
          items:
            type: string
            enum:
            - post_title
            - post_content
            - post_excerpt
          default: []
        description: Array of column names to be searched.
      - name: search_semantics
        in: query
        required: false
        schema:
          type: string
          enum:
          - exact
        description: How to interpret the search input.
      - name: slug
        in: query
        required: false
        schema:
          type: array
          items:
            type: string
        description: Limit result set to posts with one or more specific slugs.
      - name: status
        in: query
        required: false
        schema:
          type: array
          items:
            type: string
            enum:
            - inherit
            - private
            - trash
          default: inherit
        description: Limit result set to posts assigned one or more statuses.
      responses:
        '200':
          description: A page of media.
          headers:
            X-WP-Total:
              $ref: '#/components/headers/X-WP-Total'
            X-WP-TotalPages:
              $ref: '#/components/headers/X-WP-TotalPages'
            Link:
              $ref: '#/components/headers/Link'
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/Object'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /wp/v2/media/{id}:
    get:
      operationId: getMediaItem
      summary: Retrieve a single media item
      description: Retrieve one media item by its numeric id.
      tags:
      - Media
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: integer
        description: Unique numeric identifier for the media item.
      - name: context
        in: query
        required: false
        schema:
          type: string
          enum:
          - view
          - embed
          - edit
          default: view
        description: Scope under which the request is made; determines fields present in response.
      responses:
        '200':
          description: The requested media item.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Object'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/NotFound'
components:
  headers:
    X-WP-Total:
      description: Total number of items in the collection. Verified live.
      schema:
        type: integer
    X-WP-TotalPages:
      description: Total number of pages available. Verified live.
      schema:
        type: integer
    Link:
      description: RFC 8288 pagination links (rel="next" / rel="prev"). Verified live.
      schema:
        type: string
  responses:
    NotFound:
      description: Resource not found (WordPress error envelope). Verified live on /wp/v2/posts/999999999.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    BadRequest:
      description: Invalid parameter (WordPress error envelope).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Unauthorized:
      description: Authentication required (WordPress error envelope). Verified live on /wp/v2/settings.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  schemas:
    Error:
      type: object
      description: 'WordPress REST error envelope. Verified live: GET /wp/v2/posts/999999999 -> 404 {"code":"rest_post_invalid_id","message":"Invalid post ID.","data":{"status":404}} ; GET /wp/v2/settings -> 401 {"code":"rest_forbidden","message":"Sorry, you are not allowed to do that.","data":{"status":401}}'
      required:
      - code
      - message
      - data
      properties:
        code:
          type: string
          description: Machine-readable WordPress error code, e.g. rest_post_invalid_id.
        message:
          type: string
          description: Human-readable error message.
        data:
          type: object
          properties:
            status:
              type: integer
              description: HTTP status code, repeated in the body.
            params:
              type: object
              description: 'Present on rest_invalid_param: offending parameters.'
            details:
              type: object
              description: 'Present on rest_invalid_param: per-parameter detail.'
    Object:
      type: object
      description: A WordPress REST resource. Field-level schemas are served per-resource by the OPTIONS method on each route and are not reproduced here — this document does not invent field definitions the index does not publish.
      additionalProperties: true
  securitySchemes:
    anonymous:
      type: apiKey
      in: header
      name: X-WP-Nonce
      description: The public read surface documented here requires NO credentials — the live index reports an empty `authentication` object. Authenticated operations use a cookie plus an `X-WP-Nonce` header (same-origin), or HTTP Basic with a WordPress Application Password (`/wp/v2/users/<id>/application-passwords` is present in the live index).
externalDocs:
  description: WordPress REST API Handbook
  url: https://developer.wordpress.org/rest-api/