Common causes
- Permalink rewrite rules missing or broken, so /wp-json/ returns 404
- A security plugin, WAF or ModSecurity rule blocking REST requests with 401 or 403
- PHP notices or warnings printed before the JSON, making it invalid
- The server cannot make loopback requests to itself (cURL error 28 timeout or DNS issue)
- A plugin disabling the REST API or filtering rest_authentication_errors
- Mixed HTTP/HTTPS site URLs or a CDN caching or blocking /wp-json/ requests
How to fix it
- Open the endpoint directly. Visit https://example.com/wp-json/ and https://example.com/?rest_route=/ in a browser, or run curl -i https://example.com/wp-json/. JSON means the API works; a 404, 403 or HTML page shows where the problem is.
- Refresh permalinks. If /?rest_route=/ works but /wp-json/ returns 404, go to Settings > Permalinks and click Save Changes. On Apache check that .htaccess contains the standard WordPress rewrite block; on Nginx make sure location / uses try_files $uri $uri/ /index.php?$args;.
- Check firewalls and security plugins. A 401 or 403 often comes from a security plugin, Cloudflare WAF rule or ModSecurity. Temporarily disable the plugin or check the firewall log for blocked /wp-json/ requests and allow them.
- Remove stray PHP output. If the response starts with a PHP warning or HTML before the JSON, set WP_DEBUG_DISPLAY to false and fix the warning shown in wp-content/debug.log. Invisible output such as a BOM in a theme file has the same effect.
- Fix loopback requests. Site Health tests call the site from the server itself. If they time out, check that the server can resolve and reach its own domain with curl -I https://example.com from the server, and that the firewall allows it.
- Find conflicting plugins. Use the Health Check & Troubleshooting plugin to disable plugins only for your session, or rename wp-content/plugins temporarily. Re-enable plugins one at a time until the error returns.
Nginx location for pretty permalinks and /wp-json/
location / {
try_files $uri $uri/ /index.php?$args;
}
# Quick test from the server
# curl -i https://example.com/wp-json/
# curl -i 'https://example.com/?rest_route=/' How to stop it happening again
- Whitelist /wp-json/ paths your editor and plugins need in WAF and security plugin rules
- Keep WP_DEBUG_DISPLAY off in production so notices never corrupt JSON
- Re-save permalinks after migrations and server changes
- Check Tools > Site Health after updates and configuration changes