WashU WordPress REST APIs (CampusPress)
Every WashU departmental site probed exposes a live, unauthenticated WordPress REST API with a complete route discovery document — data.wustl.edu ("Data at WashU", 467 routes), source.washu.edu ("The Source", 429 routes), ris.wustl.edu ("Research Infrastructure Services", 327 routes), registrar.washu.edu (310), ai.washu.edu ("Artificial Intelligence", 318), it.washu.edu (257) and washu.edu itself (337). These are content APIs the CMS ships rather than APIs WashU designed, which is worth saying plainly, but they are unauthenticated, machine-readable, self-describing and served from hosts the institution controls, and they are in practice the only way to read WashU's public content programmatically. Operator is tenant, not institution: data.wustl.edu CNAMEs to data.wustl.edu.c13858.campuspress.com, so the estate runs on CampusPress managed hosting, and the REST contract itself is WordPress core's. The sites, the content and the editorial are Washington University's; the engineering behind the interface is not, and crediting the institution for it would be the same error this pipeline exists to prevent. The relationship is recorded rather than dropped, because it is real and it is the institution's most readable public surface.