Common causes
- Permalinks or rewrite rules broken, so /wp-json/ returns a 404 HTML page
- siteurl/home mismatch or HTTP-to-HTTPS redirect on REST requests
- PHP notices or warnings printed into the response (WP_DEBUG_DISPLAY on)
- A WAF, ModSecurity, Cloudflare rule or security plugin blocking /wp-json/ requests
- A plugin disabling the REST API for logged-in users
- A BOM or whitespace in a PHP file prepended to every response
How to fix it
- Open the REST API directly. Visit https://example.com/wp-json/ in your browser. You should see JSON; an HTML page, redirect or 404 points at the cause.
- Inspect the failing request. In browser DevTools > Network, click Publish, select the failed wp-json/wp/v2/posts request and read the Response tab. It shows the actual HTML or warning returned.
- Re-save permalinks. Settings > Permalinks > Save Changes. If /wp-json/ still 404s, check .htaccess or Nginx try_files rules.
- Fix the site URLs. Make sure WordPress Address and Site Address in Settings > General both use the correct https:// URL so REST calls are not redirected.
- Turn off on-screen errors. Set WP_DEBUG_DISPLAY to false (log to debug.log instead) so warnings are not mixed into JSON responses.
- Check firewalls and security plugins. If the response is a 403 block page, whitelist the REST route in your security plugin, ask your host about ModSecurity rule IDs, or review Cloudflare WAF events.
Quick REST API test (SSH)
curl -sI https://example.com/wp-json/
curl -s https://example.com/wp-json/ | head -c 300
wp rewrite flush --hard How to stop it happening again
- Keep WP_DEBUG_DISPLAY off on production
- Don't disable the REST API for logged-in users; the editor depends on it
- Recheck the REST API in Site Health after changing security or CDN settings