WordPress REST API Not Working: The Best Fix 2026
The REST API is one of those WordPress systems that stays invisible until something breaks it then suddenly the block editor stops loading, Elementor throws errors, or a mobile app connection fails. WordPress REST API not working issues almost always trace back to one of a handful of causes, and the specific error code you see is the fastest way to narrow down which one.
Step 1: Confirm Whether the API Is Actually Broken
Before troubleshooting, check the actual status by visiting: wordpress rest api not working
https://your-site.com/wp-json/
directly in your browser. What you see here tells you exactly what you’re dealing with:
- A 404 error routing/permalink issue
- A 403 error something is actively blocking access
- A 401 error authentication-related, usually affecting only specific authenticated requests, not the whole API
- A 500 error a PHP-level crash, usually from a plugin or theme conflict
- A blank white page a fatal PHP error not being displayed (enable
WP_DEBUGto see it)
Fix for 404 Errors: Permalink and Routing Issues
The REST API routes through the same URL rewriting system as your regular posts. If your permalinks are broken or set incorrectly, the API fails the same way a regular page would.
- Go to Settings > Permalinks
- Confirm the structure is not set to “Plain”; choose “Post name” instead
- Even if it already looks correct, click Save Changes anyway; this forces WordPress to regenerate its rewrite rules, which resolves a corrupted routing state even when the visible setting looks fine
If this doesn’t resolve it, confirm mod_rewrite is enabled at the server level (Apache), since the REST API depends on the same underlying rewrite system as pretty permalinks.
Fix for 403 Errors: Something Is Actively Blocking Access
A 403 means a request reached your server but was deliberately refused. This is almost always a security layer doing its job a little too aggressively.
Check security plugins first. Tools like Wordfence, All In One WP Security, and similar plugins often include a setting specifically restricting REST API access for unauthenticated visitors. Temporarily deactivate the plugin (or check its settings for a REST API-specific toggle) to confirm.
Check for a firewall or CDN block. If you’re using Cloudflare or another Web Application Firewall, check the security event log for blocked requests to /wp-json/ a firewall rule may be treating legitimate API requests as suspicious traffic.
Fix for 401 Errors: Authentication-Specific Issues
Unlike 404 and 403, a 401 error usually means the basic API is working, but a specific authenticated request is failing. This is common when:
- An API key or application password has expired or was entered incorrectly
- A plugin or external app is using an outdated authentication method
- WooCommerce’s Legacy REST API is required by an older integration but isn’t properly enabled
If you’re troubleshooting a specific plugin or app integration failing with a 401, check that integration’s authentication credentials first before assuming a broader site issue.
Fix for 500 Errors: A Plugin or Theme Is Crashing the API
A 500 error means something is causing a fatal PHP crash specifically when the REST API is accessed, even if the rest of your site loads fine.
- Deactivate all plugins temporarily
- Check
/wp-json/again if it now works, a plugin was the cause - Reactivate plugins one at a time, checking
/wp-json/after each, until you identify the culprit - If deactivating plugins doesn’t resolve it, switch to a default theme temporarily to rule out a theme-level conflict
Fix for a Blank Page: Hidden Fatal Errors
If visiting /wp-json/ shows a completely blank page rather than any error message, a fatal PHP error is happening but not being displayed.
Enable debug mode by adding this to wp-config.php:
define( 'WP_DEBUG', true );
define( 'WP_DEBUG_LOG', true );
define( 'WP_DEBUG_DISPLAY', false );
This logs the actual error to/wp-content/debug.log, turning an invisible crash into a specific, fixable error message.
Fix for Site URL Mismatches
If you recently installed SSL, migrated hosts, or changed domains, a mismatch between your configured URLs can silently break the API.
- Go to Settings > General
- Confirm WordPress Address (URL) and Site Address (URL) are absolutely identical in protocol (
https://) and format (with or withoutwww)
Diagnostic Quick Reference
| Error Seen | Likely Cause | Fix |
|---|---|---|
| 404 Not Found | Broken permalinks/routing | Resave permalinks |
| 403 Forbidden | Security plugin or firewall block | Check security plugin settings, firewall logs |
| 401 Unauthorized | Authentication/credential issue | Check API keys, app passwords, Legacy REST API |
| 500 Internal Error | Plugin or theme crash | Deactivate plugins/switch theme to isolate |
| Blank white page | Hidden fatal PHP error | Enable WP_DEBUG to reveal it |
Frequently Asked Questions of wordpress rest api not working
Why did my REST API suddenly stop working with no changes on my end? A recent plugin or WordPress core auto-update is the most common cause of a sudden, unexplained break check your site’s update history around the time the issue started.
Is it safe to disable my security plugin’s REST API restriction entirely? Not necessarily instead of fully disabling REST API protection, check whether the plugin offers a way to allow specific trusted requests (like your own site’s admin functions) while still blocking unauthenticated external access.
Does WooCommerce need special REST API handling? Older WooCommerce integrations sometimes rely on the Legacy REST API, which needs to be explicitly enabled separately from the standard WordPress REST API if an older plugin or app depends on it.
Can I test the REST API without technical tools? Simply visiting /wp-json/ directly in your browser (Step 1) gives you a fast, no-tools-needed status check and the specific error code you need to narrow down the cause.
Final Thoughts for wordpress rest api not working
WordPress REST API not working issues are much faster to fix once you know the specific error code you’re dealing with 404s point to permalinks, 403s point to security blocks, and 500s point to plugin/theme conflicts. If your site’s API is down and something critical (like the block editor or a plugin integration) depends on it, get in touch here and I’ll diagnose and fix it directly.
Recommended Tools & Plugins
Every tool below is something I actually use on client projects, not a random affiliate list.
- Hosting: Cloudways fast, managed WordPress hosting
- Theme: GeneratePress lightweight, built for speed
- Page Builder: Elementor Pro the builder behind most of my client sites
- Forms: WPForms reliable, beginner-friendly form builder
- Directory/Listing Sites: Directorist for business directory or listing projects
- Elementor Add-ons: Crocoblock (JetEngine) for dynamic, database-driven sites
- Keyword Research: Mangools is the SEO tool I use for keyword research
- Backups: UpdraftPlus never launch a site without a backup plan
- Course Platform: Tutor LMS is the LMS plugin
- Free Speed Test: Google PageSpeed Insights is the free tool I use to check real Core Web Vitals data