Vestaron Users API

The Users API from Vestaron — 6 operation(s) for users.

OpenAPI Specification

vestaron-users-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Vestaron Content API (WordPress REST wp/v2) Users API
  version: wp/v2
  summary: 'Public read surface of vestaron.com content: news releases, articles, recognitions and video/podcast posts, product and company pages, the media library (product labels, safety data sheets, technical bulletins), taxonomies and a site-wide search endpoint.'
  description: 'Vestaron publishes vestaron.com on WordPress, which exposes the WordPress REST API at https://vestaron.com/wp-json/. The wp/v2 namespace is anonymously readable and returns the company newsroom (94 posts across the News, Articles, Recognitions and Video/Podcasts categories), 34 product and company pages, an 829-item media library and a site-wide search endpoint as JSON.


    This document was DERIVED mechanically by API Evangelist from the route-discovery document served at https://vestaron.com/wp-json/ on 2026-08-05 — every path, method, parameter, enum, default and description below is taken verbatim from that descriptor. Vestaron does not publish an OpenAPI definition of its own, and this is not a product API: it is the content API the CMS exposes. Write operations exist on these routes but require authentication; the /wp/v2/users and /wp/v2/settings collections return 401 to anonymous callers.'
  contact:
    name: Vestaron
    url: https://vestaron.com/contact/
  x-derived-by: API Evangelist enrichment pipeline
  x-derived-from: https://vestaron.com/wp-json/
  x-derived-on: '2026-08-05'
  x-provider-published: false
servers:
- url: https://vestaron.com/wp-json
  description: Production
security:
- {}
- applicationPassword: []
tags:
- name: Users
paths:
  /wp/v2/users:
    get:
      operationId: getUsers
      summary: GET /wp/v2/users
      tags:
      - Users
      parameters:
      - name: context
        in: query
        required: false
        schema:
          type: string
          enum:
          - view
          - embed
          - edit
          default: view
        description: Scope under which the request is made; determines fields present in response.
      - name: page
        in: query
        required: false
        schema:
          type: integer
          default: 1
          minimum: 1
        description: Current page of the collection.
      - name: per_page
        in: query
        required: false
        schema:
          type: integer
          default: 10
          minimum: 1
          maximum: 100
        description: Maximum number of items to be returned in result set.
      - name: search
        in: query
        required: false
        schema:
          type: string
        description: Limit results to those matching a string.
      - name: exclude
        in: query
        required: false
        schema:
          type: array
          default: []
          items:
            type: integer
        description: Ensure result set excludes specific IDs.
      - name: include
        in: query
        required: false
        schema:
          type: array
          default: []
          items:
            type: integer
        description: Limit result set to specific IDs.
      - name: offset
        in: query
        required: false
        schema:
          type: integer
        description: Offset the result set by a specific number of items.
      - name: order
        in: query
        required: false
        schema:
          type: string
          enum:
          - asc
          - desc
          default: asc
        description: Order sort attribute ascending or descending.
      - name: orderby
        in: query
        required: false
        schema:
          type: string
          enum:
          - id
          - include
          - name
          - registered_date
          - slug
          - include_slugs
          - email
          - url
          default: name
        description: Sort collection by user attribute.
      - name: slug
        in: query
        required: false
        schema:
          type: array
          items:
            type: string
        description: Limit result set to users with one or more specific slugs.
      - name: roles
        in: query
        required: false
        schema:
          type: array
          items:
            type: string
        description: Limit result set to users matching at least one specific role provided. Accepts csv list or single role.
      - name: capabilities
        in: query
        required: false
        schema:
          type: array
          items:
            type: string
        description: Limit result set to users matching at least one specific capability provided. Accepts csv list or single capability.
      - name: who
        in: query
        required: false
        schema:
          type: string
          enum:
          - authors
        description: Limit result set to users who are considered authors.
      - name: has_published_posts
        in: query
        required: false
        schema:
          type:
          - boolean
          - array
        description: Limit result set to users who have published posts.
      - name: search_columns
        in: query
        required: false
        schema:
          type: array
          default: []
          items:
            type: string
            enum:
            - email
            - name
            - id
            - username
            - slug
        description: Array of column names to be searched.
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema: {}
        '404':
          $ref: '#/components/responses/NotFound'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
      x-evidence:
        fetched: '2026-08-05'
        http_status: 401
        anonymous_read: false
    post:
      operationId: createUsers
      summary: POST /wp/v2/users
      tags:
      - Users
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                username:
                  type: string
                  description: Login name for the user.
                name:
                  type: string
                  description: Display name for the user.
                first_name:
                  type: string
                  description: First name for the user.
                last_name:
                  type: string
                  description: Last name for the user.
                email:
                  type: string
                  format: email
                  description: The email address for the user.
                url:
                  type: string
                  format: uri
                  description: URL of the user.
                description:
                  type: string
                  description: Description of the user.
                locale:
                  type: string
                  enum:
                  - ''
                  - en_US
                  - cy
                  - el
                  - es_ES
                  - es_MX
                  - fr_CA
                  - fr_FR
                  - it_IT
                  - pt_PT
                  description: Locale for the user.
                nickname:
                  type: string
                  description: The nickname for the user.
                slug:
                  type: string
                  description: An alphanumeric identifier for the user.
                roles:
                  type: array
                  items:
                    type: string
                  description: Roles assigned to the user.
                password:
                  type: string
                  description: Password for the user (never included).
                meta:
                  type: object
                  description: Meta fields.
              required:
              - username
              - email
              - password
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema: {}
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
  /wp/v2/users/{id}:
    parameters:
    - name: id
      in: path
      required: true
      schema:
        type: integer
      description: Unique identifier from the route pattern /wp/v2/users/(?P<id>[\d]+).
    get:
      operationId: getUsersById
      summary: GET /wp/v2/users/{id}
      tags:
      - Users
      parameters:
      - name: context
        in: query
        required: false
        schema:
          type: string
          enum:
          - view
          - embed
          - edit
          default: view
        description: Scope under which the request is made; determines fields present in response.
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema: {}
        '404':
          $ref: '#/components/responses/NotFound'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
    post:
      operationId: createUsersById
      summary: POST /wp/v2/users/{id}
      tags:
      - Users
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                username:
                  type: string
                  description: Login name for the user.
                name:
                  type: string
                  description: Display name for the user.
                first_name:
                  type: string
                  description: First name for the user.
                last_name:
                  type: string
                  description: Last name for the user.
                email:
                  type: string
                  format: email
                  description: The email address for the user.
                url:
                  type: string
                  format: uri
                  description: URL of the user.
                description:
                  type: string
                  description: Description of the user.
                locale:
                  type: string
                  enum:
                  - ''
                  - en_US
                  - cy
                  - el
                  - es_ES
                  - es_MX
                  - fr_CA
                  - fr_FR
                  - it_IT
                  - pt_PT
                  description: Locale for the user.
                nickname:
                  type: string
                  description: The nickname for the user.
                slug:
                  type: string
                  description: An alphanumeric identifier for the user.
                roles:
                  type: array
                  items:
                    type: string
                  description: Roles assigned to the user.
                password:
                  type: string
                  description: Password for the user (never included).
                meta:
                  type: object
                  description: Meta fields.
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema: {}
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
    put:
      operationId: updateUsersById
      summary: PUT /wp/v2/users/{id}
      tags:
      - Users
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                username:
                  type: string
                  description: Login name for the user.
                name:
                  type: string
                  description: Display name for the user.
                first_name:
                  type: string
                  description: First name for the user.
                last_name:
                  type: string
                  description: Last name for the user.
                email:
                  type: string
                  format: email
                  description: The email address for the user.
                url:
                  type: string
                  format: uri
                  description: URL of the user.
                description:
                  type: string
                  description: Description of the user.
                locale:
                  type: string
                  enum:
                  - ''
                  - en_US
                  - cy
                  - el
                  - es_ES
                  - es_MX
                  - fr_CA
                  - fr_FR
                  - it_IT
                  - pt_PT
                  description: Locale for the user.
                nickname:
                  type: string
                  description: The nickname for the user.
                slug:
                  type: string
                  description: An alphanumeric identifier for the user.
                roles:
                  type: array
                  items:
                    type: string
                  description: Roles assigned to the user.
                password:
                  type: string
                  description: Password for the user (never included).
                meta:
                  type: object
                  description: Meta fields.
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema: {}
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
    patch:
      operationId: patchUsersById
      summary: PATCH /wp/v2/users/{id}
      tags:
      - Users
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                username:
                  type: string
                  description: Login name for the user.
                name:
                  type: string
                  description: Display name for the user.
                first_name:
                  type: string
                  description: First name for the user.
                last_name:
                  type: string
                  description: Last name for the user.
                email:
                  type: string
                  format: email
                  description: The email address for the user.
                url:
                  type: string
                  format: uri
                  description: URL of the user.
                description:
                  type: string
                  description: Description of the user.
                locale:
                  type: string
                  enum:
                  - ''
                  - en_US
                  - cy
                  - el
                  - es_ES
                  - es_MX
                  - fr_CA
                  - fr_FR
                  - it_IT
                  - pt_PT
                  description: Locale for the user.
                nickname:
                  type: string
                  description: The nickname for the user.
                slug:
                  type: string
                  description: An alphanumeric identifier for the user.
                roles:
                  type: array
                  items:
                    type: string
                  description: Roles assigned to the user.
                password:
                  type: string
                  description: Password for the user (never included).
                meta:
                  type: object
                  description: Meta fields.
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema: {}
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
    delete:
      operationId: deleteUsersById
      summary: DELETE /wp/v2/users/{id}
      tags:
      - Users
      parameters:
      - name: force
        in: query
        required: false
        schema:
          type: boolean
          default: false
        description: Required to be true, as users do not support trashing.
      - name: reassign
        in: query
        required: true
        schema:
          type: integer
        description: Reassign the deleted user's posts and links to this user ID.
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema: {}
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
  /wp/v2/users/{user_id}/application-passwords:
    parameters:
    - name: user_id
      in: path
      required: true
      schema:
        type: string
      description: Unique identifier from the route pattern /wp/v2/users/(?P<user_id>(?:[\d]+|me))/application-passwords.
    get:
      operationId: getUsersByUserIdApplicationPasswords
      summary: GET /wp/v2/users/{user_id}/application-passwords
      tags:
      - Users
      parameters:
      - name: context
        in: query
        required: false
        schema:
          type: string
          enum:
          - view
          - embed
          - edit
          default: view
        description: Scope under which the request is made; determines fields present in response.
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema: {}
        '404':
          $ref: '#/components/responses/NotFound'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
    post:
      operationId: createUsersByUserIdApplicationPasswords
      summary: POST /wp/v2/users/{user_id}/application-passwords
      tags:
      - Users
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                app_id:
                  type: string
                  description: A UUID provided by the application to uniquely identify it. It is recommended to use an UUID v5 with the URL or DNS namespace.
                name:
                  type: string
                  description: The name of the application password.
              required:
              - name
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema: {}
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
    delete:
      operationId: deleteUsersByUserIdApplicationPasswords
      summary: DELETE /wp/v2/users/{user_id}/application-passwords
      tags:
      - Users
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema: {}
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
  /wp/v2/users/{user_id}/application-passwords/{uuid}:
    parameters:
    - name: user_id
      in: path
      required: true
      schema:
        type: string
      description: Unique identifier from the route pattern /wp/v2/users/(?P<user_id>(?:[\d]+|me))/application-passwords/(?P<uuid>[\w\-]+).
    - name: uuid
      in: path
      required: true
      schema:
        type: string
      description: Unique identifier from the route pattern /wp/v2/users/(?P<user_id>(?:[\d]+|me))/application-passwords/(?P<uuid>[\w\-]+).
    get:
      operationId: getUsersByUserIdApplicationPasswordsByUuid
      summary: GET /wp/v2/users/{user_id}/application-passwords/{uuid}
      tags:
      - Users
      parameters:
      - name: context
        in: query
        required: false
        schema:
          type: string
          enum:
          - view
          - embed
          - edit
          default: view
        description: Scope under which the request is made; determines fields present in response.
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema: {}
        '404':
          $ref: '#/components/responses/NotFound'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
    post:
      operationId: createUsersByUserIdApplicationPasswordsByUuid
      summary: POST /wp/v2/users/{user_id}/application-passwords/{uuid}
      tags:
      - Users
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                app_id:
                  type: string
                  description: A UUID provided by the application to uniquely identify it. It is recommended to use an UUID v5 with the URL or DNS namespace.
                name:
                  type: string
                  description: The name of the application password.
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema: {}
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
    put:
      operationId: updateUsersByUserIdApplicationPasswordsByUuid
      summary: PUT /wp/v2/users/{user_id}/application-passwords/{uuid}
      tags:
      - Users
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                app_id:
                  type: string
                  description: A UUID provided by the application to uniquely identify it. It is recommended to use an UUID v5 with the URL or DNS namespace.
                name:
                  type: string
                  description: The name of the application password.
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema: {}
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
    patch:
      operationId: patchUsersByUserIdApplicationPasswordsByUuid
      summary: PATCH /wp/v2/users/{user_id}/application-passwords/{uuid}
      tags:
      - Users
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                app_id:
                  type: string
                  description: A UUID provided by the application to uniquely identify it. It is recommended to use an UUID v5 with the URL or DNS namespace.
                name:
                  type: string
                  description: The name of the application password.
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema: {}
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
    delete:
      operationId: deleteUsersByUserIdApplicationPasswordsByUuid
      summary: DELETE /wp/v2/users/{user_id}/application-passwords/{uuid}
      tags:
      - Users
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema: {}
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
  /wp/v2/users/{user_id}/application-passwords/introspect:
    parameters:
    - name: user_id
      in: path
      required: true
      schema:
        type: string
      description: Unique identifier from the route pattern /wp/v2/users/(?P<user_id>(?:[\d]+|me))/application-passwords/introspect.
    get:
      operationId: getUsersByUserIdApplicationPasswordsIntrospect
      summary: GET /wp/v2/users/{user_id}/application-passwords/introspect
      tags:
      - Users
      parameters:
      - name: context
        in: query
        required: false
        schema:
          type: string
          enum:
          - view
          - embed
          - edit
          default: view
        description: Scope under which the request is made; determines fields present in response.
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema: {}
        '404':
          $ref: '#/components/responses/NotFound'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /wp/v2/users/me:
    get:
      operationId: getUsersMe
      summary: GET /wp/v2/users/me
      tags:
      - Users
      parameters:
      - name: context
        in: query
        required: false
        schema:
          type: string
          enum:
          - view
          - embed
          - edit
          default: view
        description: Scope under which the request is made; determines fields present in response.
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema: {}
        '404':
          $ref: '#/components/responses/NotFound'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
    post:
      operationId: createUsersMe
      summary: POST /wp/v2/users/me
      tags:
      - Users
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                username:
                  type: string
                  description: Login name for the user.
                name:
                  type: string
                  description: Display name for the user.
                first_name:
                  type: string
                  description: First name for the user.
                last_name:
                  type: string
                  description: Last name for the user.
                email:
                  type: string
                  format: email
                  description: The email address for the user.
                url:
                  type: string
                  format: uri
                  description: URL of the user.
                description:
                  type: string
                  description: Description of the user.
                locale:
                  type: string
                  enum:
                  - ''
                  - en_US
                  - cy
                  - el
                  - es_ES
                  - es_MX
                  - fr_CA
                  - fr_FR
                  - it_IT
                  - pt_PT
                  description: Locale for the user.
                nickname:
                  type: string
                  description: The nickname for the user.
                slug:
                  type: string
                  description: An alphanumeric identifier for the user.
                roles:
                  type: array
                  items:
                    type: string
                  description: Roles assigned to the user.
                password:
                  type: string
                  description: Password for the user (never included).
                meta:
                  type: object
                  description: Meta fields.
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema: {}
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
    put:
      operationId: updateUsersMe
      summary: PUT /wp/v2/users/me
      tags:
      - Users
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                username:
                  type: string
                  description: Login name for the user.
                name:
                  type: string
                  description: Display name for the user.
                first_name:
                  type: string
                  description: First name for the user.
                last_name:
                  type: string
                  description: Last name for the user.
                email:
                  type: string
                  format: email
                  description: The email address for the user.
                url:
                  type: string
                  format: uri
                  description: URL of the user.
                description:
                  type: string
                  description: Description of the user.
                locale:
                  type: string
                  enum:
                  - ''
                  - en_US
                  - cy
                  - el
                  - es_ES
                  - es_MX
                  - fr_CA
                  - fr_FR
                  - it_IT
                  - pt_PT
                  description: Locale for the user.
                nickname:
                  type: string
                  description: The nickname for the user.
                slug:
                  type: string
                  description: An alphanumeric identifier for the user.
                roles:
                  type: array
                  items:
                    type: string
                  description: Roles assigned to the user.
                password:
                  type: string
                  description: Password for the user (never included).
                meta:
                  type: object
                  description: Meta fields.
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema: {}
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthoriz

# --- truncated at 32 KB (37 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/vestaron/refs/heads/main/openapi/vestaron-users-api-openapi.yml