Gotham Greens · Authentication Profile
Gotham Greens Authentication
Authentication
Gotham Greens secures its APIs with none and cookie across 2 declared security schemes, as derived from its OpenAPI definitions.
CompanyAgricultureControlled Environment AgricultureHydroponicsFoodConsumer Packaged GoodsFresh ProduceSustainabilityUrban FarmingContent
Methods: none, cookie
Schemes: 2
OAuth flows:
API key in:
Security Schemes
public-read none
wordpress-cookie-nonce cookie
· in: cookie ()
Source
Authentication Profile
generated: '2026-08-01'
method: derived
source: live anonymous probes of https://www.gothamgreens.com/wp-json/ (2026-08-01)
summary:
types:
- none
- cookie
api_key_in: []
oauth2_flows: []
notes: >-
Gotham Greens publishes no developer program and no product API. Its only machine-readable
surface is the platform-provided WordPress REST API at /wp-json/, and the read half of that
surface is fully public: every operation documented in this repo's openapi/ specs was
verified to return HTTP 200 with JSON to an anonymous request carrying no credentials of any
kind. There is no API key, no OAuth, no signup, and no rate-limit or quota signalling
observed. The root index advertises an EMPTY `authentication` array — the site registers no
additional REST authentication scheme beyond WordPress core. Write operations (POST/PUT/
PATCH/DELETE) are registered on the same routes but reject anonymous callers with HTTP 401;
they require a logged-in WordPress session cookie plus an X-WP-Nonce header, or an
Application Password over HTTP Basic — both administrative credentials, not a public
developer credential. Those write operations are deliberately NOT documented in the openapi/
specs, which describe only the anonymously reachable read surface.
schemes:
- name: public-read
type: none
description: >-
Anonymous public read access to the WordPress content API — posts, pages, media, categories,
tags, search, oEmbed, the Yoast SEO head endpoint, and the type/taxonomy/status registries.
evidence: >-
GET /wp-json/wp/v2/posts?per_page=1 returned 200 with post JSON and X-WP-Total: 132; the same
anonymous request pattern returned 200 on pages, media, categories, tags, comments, search,
types, taxonomies, statuses, oembed/1.0/embed and yoast/v1/get_head.
- name: wordpress-cookie-nonce
type: cookie
description: >-
WordPress core cookie authentication paired with an X-WP-Nonce request header, required for
the write half of the same routes and for the administrative read routes. Not a public
developer credential — it belongs to a logged-in site user.
in: cookie
evidence: >-
Access-Control-Allow-Headers on /wp-json/wp/v2/posts advertises `Authorization, X-WP-Nonce,
Content-Disposition, Content-MD5, Content-Type`. Anonymous GETs against the administrative
routes returned 401: /wp/v2/users (rest_user_cannot_view), /wp/v2/settings (rest_forbidden),
/wp/v2/themes (rest_cannot_view_themes), /wp/v2/plugins (rest_cannot_view_plugins),
/wp/v2/menus (rest_cannot_view), /wp/v2/block-types (rest_block_type_cannot_view) and
/wp/v2/posts/{id}/revisions (rest_cannot_read).
gated_surface:
description: >-
Routes present in the live route table but not anonymously readable. Recorded so the public
/private split of this surface is explicit rather than inferred.
routes:
- path: /wp/v2/users
status: 401
code: rest_user_cannot_view
- path: /wp/v2/settings
status: 401
code: rest_forbidden
- path: /wp/v2/themes
status: 401
code: rest_cannot_view_themes
- path: /wp/v2/plugins
status: 401
code: rest_cannot_view_plugins
- path: /wp/v2/menus
status: 401
code: rest_cannot_view
- path: /wp/v2/block-types
status: 401
code: rest_block_type_cannot_view
- path: /wp/v2/posts/{id}/revisions
status: 401
code: rest_cannot_read
docs: https://developer.wordpress.org/rest-api/using-the-rest-api/authentication/
x-evidence:
fetched: '2026-08-01'
host: https://www.gothamgreens.com
root_index: https://www.gothamgreens.com/wp-json/
namespaces: 17
routes_advertised: 406
authentication_field: []
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/gotham-greens-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.