Gotham Greens · Authentication Profile

Gotham Greens Authentication

Authentication

Gotham Greens secures its APIs with none and cookie across 2 declared security schemes, as derived from its OpenAPI definitions.

CompanyAgricultureControlled Environment AgricultureHydroponicsFoodConsumer Packaged GoodsFresh ProduceSustainabilityUrban FarmingContent
Methods: none, cookie Schemes: 2 OAuth flows: API key in:

Security Schemes

public-read none
wordpress-cookie-nonce cookie
· in: cookie ()

Source

Authentication Profile

Raw ↑
generated: '2026-08-01'
method: derived
source: live anonymous probes of https://www.gothamgreens.com/wp-json/ (2026-08-01)
summary:
  types:
  - none
  - cookie
  api_key_in: []
  oauth2_flows: []
  notes: >-
    Gotham Greens publishes no developer program and no product API. Its only machine-readable
    surface is the platform-provided WordPress REST API at /wp-json/, and the read half of that
    surface is fully public: every operation documented in this repo's openapi/ specs was
    verified to return HTTP 200 with JSON to an anonymous request carrying no credentials of any
    kind. There is no API key, no OAuth, no signup, and no rate-limit or quota signalling
    observed. The root index advertises an EMPTY `authentication` array — the site registers no
    additional REST authentication scheme beyond WordPress core. Write operations (POST/PUT/
    PATCH/DELETE) are registered on the same routes but reject anonymous callers with HTTP 401;
    they require a logged-in WordPress session cookie plus an X-WP-Nonce header, or an
    Application Password over HTTP Basic — both administrative credentials, not a public
    developer credential. Those write operations are deliberately NOT documented in the openapi/
    specs, which describe only the anonymously reachable read surface.
schemes:
- name: public-read
  type: none
  description: >-
    Anonymous public read access to the WordPress content API — posts, pages, media, categories,
    tags, search, oEmbed, the Yoast SEO head endpoint, and the type/taxonomy/status registries.
  evidence: >-
    GET /wp-json/wp/v2/posts?per_page=1 returned 200 with post JSON and X-WP-Total: 132; the same
    anonymous request pattern returned 200 on pages, media, categories, tags, comments, search,
    types, taxonomies, statuses, oembed/1.0/embed and yoast/v1/get_head.
- name: wordpress-cookie-nonce
  type: cookie
  description: >-
    WordPress core cookie authentication paired with an X-WP-Nonce request header, required for
    the write half of the same routes and for the administrative read routes. Not a public
    developer credential — it belongs to a logged-in site user.
  in: cookie
  evidence: >-
    Access-Control-Allow-Headers on /wp-json/wp/v2/posts advertises `Authorization, X-WP-Nonce,
    Content-Disposition, Content-MD5, Content-Type`. Anonymous GETs against the administrative
    routes returned 401: /wp/v2/users (rest_user_cannot_view), /wp/v2/settings (rest_forbidden),
    /wp/v2/themes (rest_cannot_view_themes), /wp/v2/plugins (rest_cannot_view_plugins),
    /wp/v2/menus (rest_cannot_view), /wp/v2/block-types (rest_block_type_cannot_view) and
    /wp/v2/posts/{id}/revisions (rest_cannot_read).
gated_surface:
  description: >-
    Routes present in the live route table but not anonymously readable. Recorded so the public
    /private split of this surface is explicit rather than inferred.
  routes:
  - path: /wp/v2/users
    status: 401
    code: rest_user_cannot_view
  - path: /wp/v2/settings
    status: 401
    code: rest_forbidden
  - path: /wp/v2/themes
    status: 401
    code: rest_cannot_view_themes
  - path: /wp/v2/plugins
    status: 401
    code: rest_cannot_view_plugins
  - path: /wp/v2/menus
    status: 401
    code: rest_cannot_view
  - path: /wp/v2/block-types
    status: 401
    code: rest_block_type_cannot_view
  - path: /wp/v2/posts/{id}/revisions
    status: 401
    code: rest_cannot_read
docs: https://developer.wordpress.org/rest-api/using-the-rest-api/authentication/
x-evidence:
  fetched: '2026-08-01'
  host: https://www.gothamgreens.com
  root_index: https://www.gothamgreens.com/wp-json/
  namespaces: 17
  routes_advertised: 406
  authentication_field: []

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/gotham-greens-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.