Skip to content

REST API

The WordPress REST API lets programs read and change a site by exchanging JSON with addresses under /wp-json/. The block editor is built on it. When a firewall, a plugin or a missing rewrite rule blocks it, saving and publishing fail.

By
WP Ministry
Published

In short

  • The REST API lives at /wp-json/ on your site. Opening that address should show JSON, which is text that begins with a brace.
  • The block editor loads and saves posts through it. Block the API and saving fails with "Updating failed."
  • Do not switch it off. To keep strangers out, require a login for its requests, as WordPress's handbook describes.

The REST API is the part of WordPress that programs talk to. A program sends a request to an address on the site and gets its answer as JSON, a plain text format for data. WordPress's handbook calls it "the foundation of the WordPress Block Editor". Plugin screens, phone apps and outside services use it too.

Each kind of content has an address, called a route. /wp-json/wp/v2/posts returns a list of posts, and the same route accepts a request to create one. What the site shows the public, the API shows the public. Private content, and any change, needs a user who is allowed to see or make it. Inside the dashboard that is your own login, sent with a security token. An outside program uses an application password.

Where you meet it

  • The address /wp-json/. https://example.com/wp-json/ answers with the API's index, a list of every route the site offers. On a site with plain permalinks the same index is at https://example.com/?rest_route=/.
  • The block editor. It loads and saves posts through the API. When the save request fails, a bar across the editor says "Updating failed."
  • Tools, then Site Health. A working site lists "The REST API is available" among its passed tests. The text beneath says the block editor "relies on the REST API to display and save your posts and pages". A failing site shows "The REST API encountered an error" or "The REST API encountered an unexpected result", followed by two lines that begin "REST API Endpoint:" and "REST API Response:".

What goes wrong

  • /wp-json/ answers 404. The address exists only inside WordPress, so it needs the site's rewrite rules. How to fix "Updating failed" and "Publishing failed" starts with that case, and 404 errors on posts and pages that exist has the rules themselves.
  • Something refuses the request. A security plugin or the host's firewall can answer the editor's save with a 403. See how to fix the 403 Forbidden error, which separates a refusal on every page from one that only happens when you save.
  • Someone switched it off. A snippet or a plugin setting can refuse every REST request. On a site where each request is refused with a 403, the editor still opens. Saving fails with "Updating failed." and the reason, and Site Health reports "The REST API encountered an unexpected result" with "REST API Response: (403) Forbidden".
  • It was used against you. The API can create users, through the route wp/v2/users, for a caller who has authenticated and is allowed to. A POST to /wp-json/wp/v2/users in an access log, beside an administrator nobody recognizes, is one of the trails in unknown admin user in WordPress.

How to look at yours

From a terminal, with your own domain, ask for the status and the type of the answer:

bash
curl -s -o /dev/null -w "%{http_code} %{content_type}\n" https://example.com/wp-json/

A working site answers 200 application/json; charset=UTF-8. A 404 means the address was not found, and a 403 means the request was refused. A type of text/html means something other than the API answered.

Common questions

Can I disable the WordPress REST API?

You should not. The handbook says that doing so "will break WordPress Admin functionality that depends on the API being active". What it offers instead is a filter, rest_authentication_errors, that requires a login for every request. That shuts out anonymous callers and leaves the editor working.

Is the REST API a security risk?

It follows the same rules as the rest of the site. Content that is public on the site is public through the API. Private posts, and anything that changes the site, need a logged-in user with permission.

Why does /wp-json/ show a 404 on my site?

Either the site uses plain permalinks or its rewrite rules are missing. The handbook suggests enabling pretty permalinks, or using the rest_route form of the address: https://example.com/?rest_route=/.

Not sure what is wrong?

Tell us what you see. We reply with the cause and a fixed quote, and the diagnosis is free.