OpenAPI Specification
openapi: 3.1.0
info:
title: Lish WordPress REST Categories Users API
version: wp/v2
summary: Public read surface of the WordPress REST API behind lishfood.com.
description: 'Lish (lishfood.com) is a corporate catering and workplace food service company serving Seattle and the Bellevue/Eastside area. Lish does not publish a product API for its catering platform. This document describes the one genuinely public, self-describing HTTP API the company does expose: the WordPress REST API that backs its marketing site and blog, reachable at https://www.lishfood.com/wp-json/ (the WordPress install reports its home as https://wordpress.lishfood.com).
This specification was DERIVED by the API Evangelist enrichment pipeline from the live route index — every path, method, parameter name, type, default and enum is taken from `routes[].endpoints[].args` as served on 2026-07-19. It is scoped to the publicly readable `wp/v2` core content surface (posts, pages, categories, tags, comments, media, users, search, types, taxonomies, statuses). The live index also advertises 348 routes across 21 namespaces, most of which belong to plugins (Elementor, Yoast, Wordfence, Contact Form 7, JupiterX, Redirection, WP Smush, Salesforce, WP Engine) and require authentication.
Write methods (POST/PUT/PATCH/DELETE) are advertised by the index but require authentication and are intentionally not documented here.'
contact:
name: Lish
email: catering@lishfood.com
url: https://www.lishfood.com/pages/contact-us
license:
name: GPL-2.0-or-later
url: https://www.gnu.org/licenses/old-licenses/gpl-2.0.html
x-derived-by: api-evangelist enrichment pipeline
x-derived-from: https://www.lishfood.com/wp-json/
x-derived-on: '2026-07-19'
x-upstream-project: https://developer.wordpress.org/rest-api/
servers:
- url: https://www.lishfood.com/wp-json
description: Production WordPress REST API
security: []
tags:
- name: Users
description: Post authors exposed by the site.
paths:
/wp/v2/users:
get:
operationId: listUsers
summary: List users
description: Retrieve a paginated collection of users. Parameters are taken verbatim from the live route index.
tags:
- Users
parameters:
- name: capabilities
in: query
required: false
schema:
type: array
items:
type: string
description: Limit result set to users matching at least one specific capability provided. Accepts csv list or single capability.
- name: context
in: query
required: false
schema:
type: string
enum:
- view
- embed
- edit
default: view
description: Scope under which the request is made; determines fields present in response.
- name: exclude
in: query
required: false
schema:
type: array
items:
type: integer
default: []
description: Ensure result set excludes specific IDs.
- name: has_published_posts
in: query
required: false
schema:
type: boolean
description: Limit result set to users who have published posts.
- name: include
in: query
required: false
schema:
type: array
items:
type: integer
default: []
description: Limit result set to specific IDs.
- name: offset
in: query
required: false
schema:
type: integer
description: Offset the result set by a specific number of items.
- name: order
in: query
required: false
schema:
type: string
enum:
- asc
- desc
default: asc
description: Order sort attribute ascending or descending.
- name: orderby
in: query
required: false
schema:
type: string
enum:
- id
- include
- name
- registered_date
- slug
- include_slugs
- email
- url
default: name
description: Sort collection by user attribute.
- name: page
in: query
required: false
schema:
type: integer
default: 1
minimum: 1
description: Current page of the collection.
- name: per_page
in: query
required: false
schema:
type: integer
default: 10
minimum: 1
maximum: 100
description: Maximum number of items to be returned in result set.
- name: roles
in: query
required: false
schema:
type: array
items:
type: string
description: Limit result set to users matching at least one specific role provided. Accepts csv list or single role.
- name: search
in: query
required: false
schema:
type: string
description: Limit results to those matching a string.
- name: search_columns
in: query
required: false
schema:
type: array
items:
type: string
enum:
- email
- name
- id
- username
- slug
default: []
description: Array of column names to be searched.
- name: slug
in: query
required: false
schema:
type: array
items:
type: string
description: Limit result set to users with one or more specific slugs.
- name: who
in: query
required: false
schema:
type: string
enum:
- authors
description: Limit result set to users who are considered authors.
responses:
'200':
description: A page of users.
headers:
X-WP-Total:
$ref: '#/components/headers/X-WP-Total'
X-WP-TotalPages:
$ref: '#/components/headers/X-WP-TotalPages'
Link:
$ref: '#/components/headers/Link'
content:
application/json:
schema:
type: array
items:
$ref: '#/components/schemas/Object'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
/wp/v2/users/{id}:
get:
operationId: getUser
summary: Retrieve a single user
description: Retrieve one user by its numeric id.
tags:
- Users
parameters:
- name: id
in: path
required: true
schema:
type: integer
description: Unique numeric identifier for the user.
- name: context
in: query
required: false
schema:
type: string
enum:
- view
- embed
- edit
default: view
description: Scope under which the request is made; determines fields present in response.
responses:
'200':
description: The requested user.
content:
application/json:
schema:
$ref: '#/components/schemas/Object'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
components:
headers:
X-WP-Total:
description: Total number of items in the collection. Verified live.
schema:
type: integer
X-WP-TotalPages:
description: Total number of pages available. Verified live.
schema:
type: integer
Link:
description: RFC 8288 pagination links (rel="next" / rel="prev"). Verified live.
schema:
type: string
responses:
NotFound:
description: Resource not found (WordPress error envelope). Verified live on /wp/v2/posts/999999999.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
BadRequest:
description: Invalid parameter (WordPress error envelope).
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
Unauthorized:
description: Authentication required (WordPress error envelope). Verified live on /wp/v2/settings.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
schemas:
Error:
type: object
description: 'WordPress REST error envelope. Verified live: GET /wp/v2/posts/999999999 -> 404 {"code":"rest_post_invalid_id","message":"Invalid post ID.","data":{"status":404}} ; GET /wp/v2/settings -> 401 {"code":"rest_forbidden","message":"Sorry, you are not allowed to do that.","data":{"status":401}}'
required:
- code
- message
- data
properties:
code:
type: string
description: Machine-readable WordPress error code, e.g. rest_post_invalid_id.
message:
type: string
description: Human-readable error message.
data:
type: object
properties:
status:
type: integer
description: HTTP status code, repeated in the body.
params:
type: object
description: 'Present on rest_invalid_param: offending parameters.'
details:
type: object
description: 'Present on rest_invalid_param: per-parameter detail.'
Object:
type: object
description: A WordPress REST resource. Field-level schemas are served per-resource by the OPTIONS method on each route and are not reproduced here — this document does not invent field definitions the index does not publish.
additionalProperties: true
securitySchemes:
anonymous:
type: apiKey
in: header
name: X-WP-Nonce
description: The public read surface documented here requires NO credentials — the live index reports an empty `authentication` object. Authenticated operations use a cookie plus an `X-WP-Nonce` header (same-origin), or HTTP Basic with a WordPress Application Password (`/wp/v2/users/<id>/application-passwords` is present in the live index).
externalDocs:
description: WordPress REST API Handbook
url: https://developer.wordpress.org/rest-api/