API Documentation
The NyasaBlog REST API provides programmatic access to your editorial content. All requests require Token-based authentication.
POST
Obtaining an Authentication Token
POST /api/account/login
Exchange your credentials for a session token. Use this token in the header of all protected requests.
Parameters
- username String (your email)
- password String
Response
{
"response": "Successfully authenticated.",
"pk": 1,
"email": "user@nyasablog.com",
"token": "27a46967801960de8734..."
}
POST
Creating a Blog Post
lock
Authentication Required
POST /api/blog/create
Body Parameters
- title String
- body Text/HTML
- image File
Response (201)
{
"title": "New Post Title",
"slug": "author-new-post-title",
"date_updated": "2026-04-02T15:19:33Z",
"username": "ephraim"
}
GET
Viewing a Specific Blog Post
lock
Authentication Required
GET /api/blog/<slug>/
Response (200)
{
"title": "Malawian Culture Today",
"body": "Exploring the rich traditions...",
"image": "/media/blog/1/image.jpg",
"date_updated": "2026-04-02T16:02:19Z",
"username": "ephraim",
"category": {"name": "Culture", "slug": "culture"},
"tags": [{"name": "Malawi"}],
"status": "published",
"view_count": 142,
"like_count": 24,
"comment_count": 8,
"reading_time": 5
}
PUT
Updating a Specific Blog Post
verified_user
Author Permission Only
PUT /api/blog/<slug>/update
Send title, body, and image fields. Only the post author can update.
Response
{
"response": "updated"
}
DELETE
Deleting a Specific Blog Post
verified_user
Author Permission Only
DELETE /api/blog/<slug>/delete
Warning: This action is irreversible. Ensure the client verifies intent before execution.
GET
List Blog Posts
lock
Authentication Required · Paginated
GET /api/blog/list/?search=<query>&ordering=-date_updated&page=1
Query Parameters
- search String
- category Slug (e.g. culture)
- status published / draft
- ordering title, date_updated, view_count
- page Int (10 per page)
Response
{
"count": 24,
"next": "/api/blog/list/?page=2",
"previous": null,
"results": [
{"title": "...", "slug": "...", ...}
]
}
GET
List Categories
Public — no authentication required.
GET /api/blog/categories/
POST
Likes & Bookmarks
lock
All require authentication
Toggle like:
POST /api/blog/<slug>/like/
{"liked": true, "count": 25}
Toggle bookmark:
POST /api/blog/<slug>/bookmark/
{"bookmarked": true}
List bookmarked posts:
GET /api/blog/bookmarks/
GET
PUT
User Profile
Get author profile (public):
GET /api/account/profile/<username>/
Update own profile (auth required):
PUT /api/account/profile/update/
bio — Text (max 500)
location — e.g. "Lilongwe, Malawi"
website — URL
twitter, facebook, instagram, linkedin — handles
Comments
List comments (public):
Create comment (auth required):
body — Comment text (required)
parent — Parent comment ID for replies (optional)
Delete own comment (auth required):