Skip to content

Pro REST API reference

WP Career Board overviewFree + ProGet WP Career Board →

WP Career Board Pro adds routes to the wcb/v1 namespace, on top of the routes in the Free plugin (see the Free REST API reference). This page lists the Pro routes only. Base URL: https://your-site.com/wp-json/wcb/v1.

  • Logged-in browser calls send the X-WP-Nonce header (wp_create_nonce( 'wp_rest' )). External clients use Application Passwords over HTTPS.
  • Pro routes are not gated by the license. The license only controls automatic updates, so a route works on an unlicensed site.
  • Permission failures return 401 (not logged in) or 403 (logged in, not allowed) with a WP_Error body.
  • Abilities named below (for example wcb/manage-boards) are the Free plugin’s abilities. Administrators have all of them.
Route Method Who may call Params Notes
/jobs/{id}/kanban GET Needs wcb/view-applications, and be an admin, a moderator (wcb/moderate-jobs), or the job’s author stage_id (int, 0 = all columns), page (int, default 1) Returns one array item per stage with applications, total, has_more, page. With stage_id it returns that one column’s page. 25 cards per page by default (filter wcbp_kanban_stage_limit, capped at 100).
/applications/{id}/stage PUT, PATCH, POST Needs wcb/view-applications, and be a moderator or the author of the application’s job stage_id (int, required) 400 wcb_invalid_stage if the stage is not on the job’s board. 409 wcb_application_closed if the application is withdrawn, position closed or job removed. Fires wcbp_application_stage_changed.
Route Method Who may call Params Notes
/boards/{id} GET Anyone none Returns id, title, currency. 404 wcb_board_not_found.
/boards/{id} DELETE wcb/manage-boards none Deletes the board, its stages, and unlinks its jobs.
/boards/{id}/stages GET Logged in, and wcb/manage-boards or the board’s author none Ordered stage list.
/boards/{id}/stages POST wcb/manage-boards label, color (hex, default #6366f1), sort_order, is_terminal, terminal_outcome Creates a stage.
/boards/{id}/stages/{stage_id} PUT, PATCH, POST wcb/manage-boards label, color, sort_order Send only the fields to change.
/boards/{id}/stages/{stage_id} DELETE wcb/manage-boards none Its cards move to the board’s first remaining stage; the response reports moved_to_stage and applications_moved.

All Field Builder routes need wcb/manage-boards.

Route Method Params Notes
/fields/groups GET board_id, entity_type (default job) Lists groups.
/fields/groups POST board_id (required, 0 = global), label (required), entity_type (default job), sort_order, excluded_boards (int array) excluded_boards hides a job group on those boards.
/fields/groups/{id} PUT, PATCH, POST same as create, none required
/fields/groups/{id} DELETE none
/fields/groups/{group_id}/fields GET none Fields in a group.
/fields/groups/{group_id}/fields POST field_type (required), label (required), field_key, options (array), rules (object), visibility (public, employer_only, admin_only; default public), required (bool), sort_order Keys are stored with a wcbf_ prefix. 400 wcb_invalid_field_type, 404 wcb_group_not_found, 409 when the key already exists.
/fields/{id} PUT, PATCH, POST same as create, none required
/fields/{id} DELETE none
/fields/reorder POST items (array of objects, required) Saves drag-and-drop order.

The 17 accepted field_type values: text, textarea, number, url, email, date, date_range, select, multi_select, checkbox, radio, file, video_url, location, salary_range, repeater, conditional.

Route Method Who may call Params Notes
/resumes GET Anyone the candidate directory access level allows (setting resume_directory_access: public, members or approved; filter wcb_can_browse_candidates). Others get 401 (logged out) or 403 page, per_page (1-50, default 12), search, skill, open_to_work, experience, location, order (ASC, DESC), author Public candidate directory. Filtering runs on the server.
/resumes POST Logged in none Creates a resume for the current user.
/candidates/{id}/resumes GET The candidate, or a user with wcb/view-resumes none Blocked candidates return 404.
/candidates/{id}/resumes POST The candidate only title (required)
/resumes/{id} GET Owner, anyone who may read that resume, or wcb/manage-settings none
/resumes/{id} PUT, PATCH, POST Owner or wcb/manage-settings title, is_public, custom_fields, sections
/resumes/{id} DELETE Owner or wcb/manage-settings none
/resumes/photo-upload POST Needs wcb/manage-resume multipart file field photo
/resumes/{id}/pdf GET Same as GET /resumes/{id} none Streams the generated PDF as a download.
/resumes/{id}/pdf POST Owner or wcb/manage-settings multipart file field resume_file (PDF only) Replaces the attached CV. 400 wcb_invalid_file_type for non-PDF.
/resumes/{id}/bookmark POST Logged in none Toggles the bookmark for the current user.
Route Method Who may call Params Notes
/alerts GET Logged in none The current user’s alerts, up to 1000.
/alerts POST Logged in, or a guest with a valid email when guest alerts are on board_id (0 = all), search_query, filters (object: category, type), frequency (instant, daily, weekly; default daily), email (guests) Returns id and needsConfirm (true for guests, who must confirm by email). Guests: 5 requests per IP per hour (429 wcb_alert_rate_limited). Everyone: capped per person by the alerts limit (400 wcb_alert_limit).
/alerts/{id} PUT, PATCH, POST Alert owner or wcb/manage-settings frequency, search_query, filters, board_id Returns updated.
/alerts/{id} DELETE Alert owner or wcb/manage-settings none Returns deleted.
/alerts/{id}/unsubscribe/{token} GET, POST Anyone with the 32-character token none One-click unsubscribe used by the email header. 403 wcb_invalid_token if the token is wrong.

All routes need a logged-in user and only touch that user’s rows.

Route Method Params Notes
/notifications GET page (default 1), per_page (1-50, default 20) Returns notifications and unread_count.
/notifications DELETE none Clears all.
/notifications/{id} DELETE none
/notifications/{id}/read PUT, PATCH, POST none
/notifications/read-all POST none
Route Method Who may call Params Notes
/push/register-device POST Logged in expo_push_token (required), platform (ios, android), device_name 400 wcb_invalid_push_token unless the token looks like ExponentPushToken[...]. Returns 201.
/push/register-device DELETE Logged in expo_push_token (required)
Route Method Who may call Notes
/employers/{id}/credits GET That employer, or wcb/manage-credits Returns balance and the 50 newest ledger rows.
/jobs/{id}/feature POST The job’s author, or wcb/manage-credits Charges the Featured price and features the job. Only publish or pending jobs (409 wcb_not_featurable). Returns id, featured, balance.
/analytics/credits.csv GET wcb/view-analytics or wcb/manage-credits Streams the credit ledger as CSV, newest first.

The credit checkout, claim and webhook routes belong to the bundled Credits SDK and live under wbcom-credits/v1. See Credits SDK.

Each call counts against a limit of 30 AI requests per user per hour (429 wcb_rate_limit). See AI providers.

Route Method Who may call Params
/ai/match POST Logged in query (optional; empty uses the candidate’s resume)
/candidates/{id}/matches GET That candidate, or wcb/manage-ai none
/ai/ranked-applications/{job_id} GET wcb/view-applications, and an admin, moderator or the job’s author none
/jobs/ai-description POST wcb/post-jobs title, company_type, location
/jobs/{job_id}/ai-cover-letter POST wcb/apply-jobs none
Route Method Who may call Params Notes
/geocode GET Anyone address (required, 2-200 characters) Returns { lat, lng } from the active map driver. Results are cached (one day for a hit, one hour for a miss). 30 requests per IP per hour by default (filter wcbp_geocode_rate_limit, 429 wcb_rate_limited). 422 wcbp_geocode_failed when no place is found.

These three routes run the Pro steps of the setup wizard and need wcb/manage-settings.

Route Method Params
/wizard/activate-license POST license_key (required)
/wizard/setup-credits POST threshold (int, default 5)
/wizard/create-pro-pages POST none