REST API Reference
All endpoints are under the roadmap/v1 namespace: https://yoursite.com/wp-json/roadmap/v1/.
Read endpoints (marked Public) require no authentication. Write endpoints check a WordPress capability or a specific permission callback (voting, commenting, and suggesting check the matching roadmap_vote / roadmap_comment / roadmap_suggest capability described in Architecture Overview); authenticate them the same way you’d authenticate any WordPress REST request (cookie + nonce for browser JS, or Application Passwords for external clients).
List items
Section titled “List items”GET /items| Param | Type | Notes |
|---|---|---|
product |
string | Required. Product slug to filter by. |
status |
string | Optional status slug filter. |
category |
string | Optional category slug filter. |
search |
string | Free-text search across title and content. |
sort |
string | One of votes, recent, comments, priority, title. |
page |
integer | Default 1. |
per_page |
integer | Default 100. Capped by the roadmap_max_per_page filter (default ceiling: 200) - this route is public, so page size can’t be raised without limit by the caller. |
Get a single item
Section titled “Get a single item”GET /items/{id}Create an item
Section titled “Create an item”POST /itemsRequires the capability to create roadmap items. Body includes title, content, status, categories, priority, progress, and the other item detail fields.
Update an item
Section titled “Update an item”PUT /items/{id}Permission is checked against that specific post (via Roadmap_Permissions::can_edit_item()), not a blanket edit_posts capability - this is what lets a member edit their own submitted item without being able to edit anyone else’s.
Delete an item
Section titled “Delete an item”DELETE /items/{id}Same per-post permission check, via Roadmap_Permissions::can_delete_item(). Deleting moves the item to the trash rather than deleting it permanently.
Voting
Section titled “Voting”POST /vote| Param | Type | Notes |
|---|---|---|
item_id |
integer | Required. |
vote_value |
integer | 1 to vote, -1 or 0 depending on context to remove/adjust. Default 1. |
Permission is checked by can_vote, which respects the Who Can Vote setting (including guest voting by IP).
Comments
Section titled “Comments”POST /comment| Param | Type | Notes |
|---|---|---|
item_id |
integer | Required. |
content |
string | Required. |
Get an item’s comments
Section titled “Get an item’s comments”GET /items/{id}/commentsSuggestions
Section titled “Suggestions”POST /suggest| Param | Type | Notes |
|---|---|---|
title |
string | Required. |
description |
string | Required. |
category |
string | Optional category slug. |
Permission is checked by can_suggest, which requires login on Free (guest suggestions are a Pro feature).
Settings
Section titled “Settings”GET /settingsPOST /settingsGET is public and returns the statuses, categories, and configuration the frontend needs to render. POST requires the roadmap_manage_settings capability.
GET /statsPublic. Returns aggregate counts (e.g. total items, total votes) used by the admin dashboard.
Changelog
Section titled “Changelog”GET /changelogGET /changelog/{id}GET /changelog-typesGET /changelog accepts product (Pro, for multi-product filtering) and standard pagination params, and is filterable via the roadmap_api_changelog_args hook.
Extending the API
Section titled “Extending the API”Register your own routes on the same nonce/capability model using the roadmap_register_api_routes action, which fires after Product Roadmap’s own routes are registered:
add_action( 'roadmap_register_api_routes', function ( $namespace ) { register_rest_route( $namespace, '/my-endpoint', array( 'methods' => 'GET', 'callback' => 'my_endpoint_callback', 'permission_callback' => '__return_true', ) );} );
