Ffile2fix
Sign in Get started

Fix "The REST API encountered an unexpected result" in WordPress

The REST API encountered an unexpected result

The block editor, Site Health and many plugins talk to WordPress through the REST API at /wp-json/. This error means a request to it returned something other than the expected JSON, such as a 404, a 403 from a firewall, an HTML error page or JSON corrupted by PHP warnings. Opening /wp-json/ directly and reading the response usually reveals which one.

Also appears as: The REST API encountered an error · {"code":"rest_no_route","message":"No route was found matching the URL and request method.","data":{"status":404}} · {"code":"rest_cookie_invalid_nonce","message":"Cookie check failed","data":{"status":403}} · Updating failed. The response is not a valid JSON response.

Common causes

  • Permalink rewrite rules missing or broken, so /wp-json/ returns 404
  • A security plugin, WAF or ModSecurity rule blocking REST requests with 401 or 403
  • PHP notices or warnings printed before the JSON, making it invalid
  • The server cannot make loopback requests to itself (cURL error 28 timeout or DNS issue)
  • A plugin disabling the REST API or filtering rest_authentication_errors
  • Mixed HTTP/HTTPS site URLs or a CDN caching or blocking /wp-json/ requests

How to fix it

  1. Open the endpoint directly. Visit https://example.com/wp-json/ and https://example.com/?rest_route=/ in a browser, or run curl -i https://example.com/wp-json/. JSON means the API works; a 404, 403 or HTML page shows where the problem is.
  2. Refresh permalinks. If /?rest_route=/ works but /wp-json/ returns 404, go to Settings > Permalinks and click Save Changes. On Apache check that .htaccess contains the standard WordPress rewrite block; on Nginx make sure location / uses try_files $uri $uri/ /index.php?$args;.
  3. Check firewalls and security plugins. A 401 or 403 often comes from a security plugin, Cloudflare WAF rule or ModSecurity. Temporarily disable the plugin or check the firewall log for blocked /wp-json/ requests and allow them.
  4. Remove stray PHP output. If the response starts with a PHP warning or HTML before the JSON, set WP_DEBUG_DISPLAY to false and fix the warning shown in wp-content/debug.log. Invisible output such as a BOM in a theme file has the same effect.
  5. Fix loopback requests. Site Health tests call the site from the server itself. If they time out, check that the server can resolve and reach its own domain with curl -I https://example.com from the server, and that the firewall allows it.
  6. Find conflicting plugins. Use the Health Check & Troubleshooting plugin to disable plugins only for your session, or rename wp-content/plugins temporarily. Re-enable plugins one at a time until the error returns.

Nginx location for pretty permalinks and /wp-json/

location / {
    try_files $uri $uri/ /index.php?$args;
}

# Quick test from the server
# curl -i https://example.com/wp-json/
# curl -i 'https://example.com/?rest_route=/'

How to stop it happening again

  • Whitelist /wp-json/ paths your editor and plugins need in WAF and security plugin rules
  • Keep WP_DEBUG_DISPLAY off in production so notices never corrupt JSON
  • Re-save permalinks after migrations and server changes
  • Check Tools > Site Health after updates and configuration changes

Frequently asked questions

Can I just disable the REST API?

No. The block editor, Site Health and many plugins depend on it. You can restrict sensitive endpoints for logged-out users, but blocking it completely breaks the editor.

What does rest_cookie_invalid_nonce mean?

The logged-in request did not include a valid nonce, often because a cached page served an old nonce or cookies were stripped by a proxy. Exclude logged-in pages and wp-admin from page caching.

Why does 'Updating failed. The response is not a valid JSON response.' appear?

The editor saves through the REST API and got back an error page or invalid JSON. The causes are the same: broken permalinks, a firewall block, or PHP output mixed into the response.