Skip to content

REST API ​

The shaped-gallery/v1 routes, what they're for, and who may call them.

The plugin's entire server surface is REST — there are no admin-ajax handlers. Routes live under:

/wp-json/shaped-gallery/v1/

These routes serve the plugin's own screens

They're documented so you can understand what the admin and front end are doing, and so you can extend the plugin sensibly. They aren't a public, versioned API with a stability promise — treat them as internal.

Permissions ​

LevelWhoUsed by
Managemanage_optionsEverything on the Settings screen, the media browser, gallery management, the purge buttons.
Edit postsedit_postsThe Ready Patterns routes. They back a control inside the post editor, so the capability that matters is "may author content" — gating them on manage_options would hand an Editor a button that 403s.
PublicAnyonegallery-page only. It's the pagination window the front end requests.

Every write route has a real permission callback. Requests carry WordPress's standard REST nonce.

Galleries and media ​

RouteMethodPermissionWhat it does
/providersGETManageLists the registered media providers for the picker's source rail.
/mediaGETManageBrowses media from a provider — the picker's grid.
/galleriesGETManageLists saved galleries for the Saved Galleries table.
/galleries/{id}—ManageActs on one gallery.
/galleries/bulkPOSTManageBulk delete or duplicate.

Front end ​

RouteMethodPermissionWhat it does
/gallery-pageGETPublicReturns one window of a gallery — the route behind Ajax Pagination and server-side filtering.

gallery-page is public because the gallery it serves is public. It applies the same gates the renderer does — licence, visibility, password — so it can't be used to page through a gallery the front end is refusing to show.

Maintenance ​

RouteMethodPermissionWhat it does
/cache/purgePOSTManageClear Gallery Cache. Clears an allow-listed set of cache prefixes only, in batches.
/watermark/purgePOSTManagePurge Watermark Cache. Deletes generated derivatives.

The purge allow-list is a boundary, not tidiness

A broader "delete everything with our prefix" would also clear the password gate's failure counters — handing someone mid-lockout a fresh set of attempts from an unrelated button. Only two families of cache entry are ever flushable.

License ​

RouteMethodPermissionWhat it does
/licenseGETManageThe current license status. The key is masked — the raw value never leaves the server.
/license/activatePOSTManageActivates a key.
/license/deactivatePOSTManageDeactivates, freeing the seat.
/license/checkPOSTManageRe-checks with the store.

A refused key is a 200 with success: false — the request was well-formed and the store's reason is the body. Only an unreachable store is an error response.

Ready Patterns ​

RouteMethodPermissionWhat it does
/patternsGETEdit postsThe pattern catalogue, fetched server-side and cached.
/patterns/refreshPOSTEdit postsForces a re-fetch.
/patterns/importPOSTEdit postsFetches one pattern's block markup.
/patterns/favoritesGETEdit postsYour favourited patterns.

All four 403 when the Ready Patterns module is off. That's what actually stops the outbound third-party request — hiding the button in the editor alone wouldn't.

Calling them from JavaScript ​

Use @wordpress/api-fetch, which carries the nonce for you:

js
import apiFetch from '@wordpress/api-fetch';

apiFetch( { path: '/shaped-gallery/v1/galleries' } ).then( ( galleries ) => {
    console.log( galleries );
} );

Adding a route ​

Follow the plugin's own pattern: register in one place with an argument schema and a real permission_callback, sanitize at entry, validate ids against the post type, and return rest_ensure_response() or a prefixed WP_Error.

Things worth knowing ​

The namespace is fixed. shaped-gallery/v1 is shared by the free and Pro builds and won't change.

Settings aren't written through these routes. The Settings screen uses WordPress core's own settings endpoint, with each panel writing only its own keys. The license is the exception — it's a separate option, writable only through the license routes, so the settings endpoint has no path to it.

A route returning nothing isn't necessarily an error. The gates return empty output by design. If a gallery is blank, switch on Debug Performance — it names which gate fired.

Where to go next ​