WebCalendar REST API Reference

WebCalendar REST API

Full CRUD access to events, categories, holidays, and more. Build custom integrations, sync with external services, or create headless calendar frontends.

Quick Start

Everything you need to start making API calls in under a minute.

Auth

Authentication

Cookie/nonce authentication for browser-based JavaScript. Application Passwords for external tools and server-to-server integrations. Feed tokens for public iCal subscription URLs.

URL

Base URL

All endpoints are namespaced under /wp-json/webcal/v1/. Append the resource path to your site URL: https://example.com/wp-json/webcal/v1/events

100/min

Rate Limiting

Default limit of 100 requests per 60 seconds per client. Stricter limits apply to public-facing endpoints like the iCal feed and frontend submissions.

Endpoint Overview

40 endpoints across 9 resource groups covering every aspect of calendar management.

Events — 8 endpoints

Full CRUD operations on events and recurring event instances. Includes iCal export (.ics), CSV export, and single-event ICS download.

Categories — 5 endpoints

Create, read, update, and delete event categories. Merge duplicate categories into one while preserving event assignments.

Holidays — 5 endpoints

CRUD for holiday entries with provider-based import from 100+ countries. Bulk import for quick setup of national and regional holidays.

Remote Calendars — 6 endpoints

Subscribe to external iCal feeds, manage sync intervals, and trigger manual refreshes. Requires Starter tier or above.

Shared Calendars — 4 endpoints

CRUD for team and resource calendars. Share calendars across users with configurable read/write permissions.

Layers — 4 endpoints

Subscribe to other users’ calendars as overlay layers. View multiple calendars side by side with color-coded differentiation.

Submissions — 4 endpoints

Frontend event submissions with admin approval queue. List pending submissions, approve, reject, or delete them. Requires Starter tier or above.

Users — 3 endpoints  |  Feed — 1 endpoint

User list and preference management. Public iCal subscription feed with optional token-based authentication for private events.

Common Operations

Copy-paste examples to get started quickly. Replace example.com with your WordPress site URL.

List Events

curl https://example.com/wp-json/webcal/v1/events?start_date=20260301&end_date=20260331

Returns public events without authentication. With a valid cookie or Application Password, returns all events visible to the authenticated user, including confidential and private entries.

Create an Event

curl -X POST https://example.com/wp-json/webcal/v1/events \
-H "Content-Type: application/json" \
-u "admin:APPLICATION_PASSWORD" \
-d '{"title":"Team Standup","start_date":20260315,"start_time":90000,"duration":1800,"location":"Room 4B","category_id":2}'

Requires authentication. Dates are integers in YYYYMMDD format. Times are integers in HHMMSS format. Duration is in seconds. Use -1 for start_time to create an all-day event.

Subscribe via iCal

curl https://example.com/wp-json/webcal/v1/feed?token=YOUR_FEED_TOKEN

Returns a standard RFC 5545 iCalendar feed. Use in Google Calendar, Apple Calendar, or Outlook as a subscription URL. Without a token, returns public events only. Generate a personal feed token from the admin settings.

Permissions & Security

Enterprise-grade access control built on WordPress capabilities and SQL-level filtering.

34

WordPress Capabilities

Granular role-based access control. Capabilities include webcal_can_view, webcal_can_edit, webcal_can_delete, webcal_can_approve, webcal_manage_categories, and 29 more. Assign per role or per user.

P / C / R

Access Levels

Every event has an access level: P (Public), C (Confidential), or R (Private). Filtering happens at the SQL query level, not post-query in PHP. Unauthorized users never see restricted event data in API responses.

Secure

Input Sanitization

All inputs sanitized via sanitize_text_field(), absint(), and wp_kses_post(). Nonce verification on all state-changing requests and exports. Psalm taint analysis in CI catches injection vectors before they ship.

Ready to Build?

Install the plugin to start making requests today. The complete per-endpoint reference, including request/response schemas, error codes, and tier-based feature gating, ships with the plugin as API_REFERENCE.md. See the WebCalendar overview or browse our FAQ.