API Documentation

The NyasaBlog REST API provides programmatic access to your editorial content. All requests require Token-based authentication.

POST

Obtaining an Authentication Token

POST /api/account/login

Exchange your credentials for a session token. Use this token in the header of all protected requests.

Parameters

  • username String (your email)
  • password String

Response

{
  "response": "Successfully authenticated.",
  "pk": 1,
  "email": "user@nyasablog.com",
  "token": "27a46967801960de8734..."
}
POST

Creating a Blog Post

lock Authentication Required
POST /api/blog/create

Body Parameters

  • title String
  • body Text/HTML
  • image File

Response (201)

{
  "title": "New Post Title",
  "slug": "author-new-post-title",
  "date_updated": "2026-04-02T15:19:33Z",
  "username": "ephraim"
}
GET

Viewing a Specific Blog Post

lock Authentication Required
GET /api/blog/<slug>/

Response (200)

{
  "title": "Malawian Culture Today",
  "body": "Exploring the rich traditions...",
  "image": "/media/blog/1/image.jpg",
  "date_updated": "2026-04-02T16:02:19Z",
  "username": "ephraim",
  "category": {"name": "Culture", "slug": "culture"},
  "tags": [{"name": "Malawi"}],
  "status": "published",
  "view_count": 142,
  "like_count": 24,
  "comment_count": 8,
  "reading_time": 5
}
PUT

Updating a Specific Blog Post

verified_user Author Permission Only
PUT /api/blog/<slug>/update

Send title, body, and image fields. Only the post author can update.

Response

{
  "response": "updated"
}
DELETE

Deleting a Specific Blog Post

verified_user Author Permission Only
DELETE /api/blog/<slug>/delete
Warning: This action is irreversible. Ensure the client verifies intent before execution.
GET

List Blog Posts

lock Authentication Required · Paginated
GET /api/blog/list/?search=<query>&ordering=-date_updated&page=1

Query Parameters

  • search String
  • category Slug (e.g. culture)
  • status published / draft
  • ordering title, date_updated, view_count
  • page Int (10 per page)

Response

{
  "count": 24,
  "next": "/api/blog/list/?page=2",
  "previous": null,
  "results": [
    {"title": "...", "slug": "...", ...}
  ]
}
GET

List Categories

Public — no authentication required.

GET /api/blog/categories/
GET

List Tags

Public — no authentication required.

GET /api/blog/tags/
GET POST

Comments

List comments (public):

GET /api/blog/<slug>/comments/

Create comment (auth required):

POST /api/blog/<slug>/comments/create/

body — Comment text (required)

parent — Parent comment ID for replies (optional)

Delete own comment (auth required):

DELETE /api/blog/comments/<pk>/delete/
POST

Likes & Bookmarks

lock All require authentication

Toggle like:

POST /api/blog/<slug>/like/
{"liked": true, "count": 25}

Toggle bookmark:

POST /api/blog/<slug>/bookmark/
{"bookmarked": true}

List bookmarked posts:

GET /api/blog/bookmarks/
GET PUT

User Profile

Get author profile (public):

GET /api/account/profile/<username>/

Update own profile (auth required):

PUT /api/account/profile/update/

bio — Text (max 500)

location — e.g. "Lilongwe, Malawi"

website — URL

twitter, facebook, instagram, linkedin — handles