How-to

Find your org slug and build public URLs

Private API paths never contain your org; public paths always do. You need the slug to go from one to the other.

Find your slug

bash
curl -s -H "Authorization: Bearer $WREN_API_KEY" https://wren.aemwip.com/api/v1/me
# → { "org": { "id": "…", "name": "…", "slug": "oak-spur-spur" }, "role": "owner", … }

wren me          # same, from the CLI

Slugs are generated words. The org owner can set a nicer one, as long as no other org has it:

http
PUT /api/v1/org/slug
{"slug": "tkd-tracker"}

Changing the slug changes every public URL. Links already shared, and custom domains proxying to the old slug, stop working.

Translate a private path into a public URL

Insert /orgs/{slug}, then drop the auth header. The URL only works if a principal: "*" read rule covers the tree or collection.

You have (private, with key)Public URL (no auth)
/api/v1/tree/mysite/index.html/orgs/{slug}/tree/mysite/index.html
/api/v1/events/api/v1/orgs/{slug}/events
/api/v1/events/{id}/api/v1/orgs/{slug}/events/{id}
/api/v1/images/{id}/raw/api/v1/orgs/{slug}/images/{id}/raw/photo.jpg (a trailing filename helps browsers)
POST /api/v1/events/_queryPOST /api/v1/orgs/{slug}/events/_query
/api/v1/events/_materialized/overview/api/v1/orgs/{slug}/events/_materialized/overview

To check what an org exposes, use GET /orgs/{slug}/llms.txt (collections, trees, samples and the URL map) or GET /api/v1/projects (every org with public content, including site entry URLs).

Which form to share

  • For people: https://<host>/orgs/{slug}/tree/{tree}/index.html, or your own domain (see Serve a site on your own domain).
  • For code: https://<host>/api/v1/orgs/{slug}/…. /orgs/{slug}/… is a GET-only alias, so POST _query needs the /api/v1 form. If your page works out its API base from its own URL, accept both prefixes.
  • Always use https://. Plain http:// redirects, and some clients don't follow redirects.

Troubleshooting

StatusUsually meansFix
404 on /api/me, /collections, /tree/…Missing /api/v1 prefixEvery authenticated route starts with /api/v1/
401 on /api/v1/…A private URL with no keySend Authorization: Bearer wren_…, or use the public /orgs/{slug} form
403 on /orgs/{slug}/…No * read rule for that tree or collectionPOST /api/v1/permissions {"principal":"*", "resource":"tree:mysite", "access":"read"}
404 on a public tree file that existsThe rule has labelFilter: "published" and the file isn't promoted yetwren promote mysite
405 on /orgs/{slug}/…A write sent to a public URLPublic URLs are read-only; write to /api/v1/{collection} with a key
403 with error code: 1010Cloudflare rejected the client's User-AgentSee Use WREN from Python