How-to
Find your org slug and build public URLs
Private API paths never contain your org; public paths always do. You need the slug to go from one to the other.
Find your slug
bash
curl -s -H "Authorization: Bearer $WREN_API_KEY" https://wren.aemwip.com/api/v1/me
# → { "org": { "id": "…", "name": "…", "slug": "oak-spur-spur" }, "role": "owner", … }
wren me # same, from the CLISlugs are generated words. The org owner can set a nicer one, as long as no other org has it:
http
PUT /api/v1/org/slug
{"slug": "tkd-tracker"}Changing the slug changes every public URL. Links already shared, and custom domains proxying to the old slug, stop working.
Translate a private path into a public URL
Insert /orgs/{slug}, then drop the auth header. The URL only works if a principal: "*" read rule covers the tree or collection.
| You have (private, with key) | Public URL (no auth) |
|---|---|
/api/v1/tree/mysite/index.html | /orgs/{slug}/tree/mysite/index.html |
/api/v1/events | /api/v1/orgs/{slug}/events |
/api/v1/events/{id} | /api/v1/orgs/{slug}/events/{id} |
/api/v1/images/{id}/raw | /api/v1/orgs/{slug}/images/{id}/raw/photo.jpg (a trailing filename helps browsers) |
POST /api/v1/events/_query | POST /api/v1/orgs/{slug}/events/_query |
/api/v1/events/_materialized/overview | /api/v1/orgs/{slug}/events/_materialized/overview |
To check what an org exposes, use GET /orgs/{slug}/llms.txt (collections, trees, samples and the URL map) or GET /api/v1/projects (every org with public content, including site entry URLs).
Which form to share
- For people:
https://<host>/orgs/{slug}/tree/{tree}/index.html, or your own domain (see Serve a site on your own domain). - For code:
https://<host>/api/v1/orgs/{slug}/…./orgs/{slug}/…is a GET-only alias, soPOST _queryneeds the/api/v1form. If your page works out its API base from its own URL, accept both prefixes. - Always use
https://. Plainhttp://redirects, and some clients don't follow redirects.
Troubleshooting
| Status | Usually means | Fix |
|---|---|---|
404 on /api/me, /collections, /tree/… | Missing /api/v1 prefix | Every authenticated route starts with /api/v1/ |
401 on /api/v1/… | A private URL with no key | Send Authorization: Bearer wren_…, or use the public /orgs/{slug} form |
403 on /orgs/{slug}/… | No * read rule for that tree or collection | POST /api/v1/permissions {"principal":"*", "resource":"tree:mysite", "access":"read"} |
| 404 on a public tree file that exists | The rule has labelFilter: "published" and the file isn't promoted yet | wren promote mysite |
405 on /orgs/{slug}/… | A write sent to a public URL | Public URLs are read-only; write to /api/v1/{collection} with a key |
403 with error code: 1010 | Cloudflare rejected the client's User-Agent | See Use WREN from Python |