{"id":6825,"date":"2026-07-10T14:07:22","date_gmt":"2026-07-10T04:07:22","guid":{"rendered":"https:\/\/mediaplusdigital.co\/au\/?p=6825"},"modified":"2026-07-10T14:07:22","modified_gmt":"2026-07-10T04:07:22","slug":"wordpress-rest-api","status":"publish","type":"post","link":"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/","title":{"rendered":"WordPress REST API: What It Is, How It Works and What You Can Build"},"content":{"rendered":"<p class=\"p1\">The WordPress REST API is an interface that lets applications interact with a WordPress site by sending and receiving JSON data over HTTP. Instead of logging into wp-admin to read or change content, a program makes a web request to a URL and gets back structured data it can use anywhere.<\/p>\n<p class=\"p1\">That one capability changes what a WordPress site can be. It is no longer just a website you view in a browser. It becomes a content source that a mobile app, a React front end, a customer portal, another business system or an automation script can all talk to.<\/p>\n<p class=\"p1\">This guide covers both sides of that story. First, what the REST API is and why it matters if you run a business. Then the technical detail your developers will actually use: the routes, the common endpoints, example requests, authentication and a few practical cautions.<\/p>\n<p class=\"p1\">If you want the broader concept behind this first, our explainer on <a href=\"https:\/\/mediaplusdigital.co\/au\/what-is-api-integration\/\"><span class=\"s1\">what API integration is<\/span><\/a> sets the scene. The WordPress REST API is one concrete, widely used example of it.<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 counter-hierarchy ez-toc-counter ez-toc-light-blue ez-toc-container-direction\">\n<div class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/div>\n<label for=\"ez-toc-cssicon-toggle-item-6ac09ecdf0846\" class=\"ez-toc-cssicon-toggle-label\"><span class=\"ez-toc-cssicon\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/label><input type=\"checkbox\"  id=\"ez-toc-cssicon-toggle-item-6ac09ecdf0846\" checked aria-label=\"Toggle\" \/><nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#Why_the_REST_API_matters_in_plain_terms\" >Why the REST API matters in plain terms<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#How_the_WordPress_REST_API_works\" >How the WordPress REST API works<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#The_base_and_the_namespace\" >The base and the namespace<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#CRUD_through_HTTP_methods\" >CRUD through HTTP methods<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#A_first_request\" >A first request<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#Common_endpoints\" >Common endpoints<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#Authentication\" >Authentication<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#Cookie_authentication_with_nonces\" >Cookie authentication with nonces<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#Application_passwords\" >Application passwords<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#JWT_and_OAuth\" >JWT and OAuth<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#Custom_endpoints\" >Custom endpoints<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#Security_and_performance_to_plan_for\" >Security and performance to plan for<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#When_a_business_should_use_it\" >When a business should use it<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#Frequently_asked_questions\" >Frequently asked questions<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#Do_I_need_a_plugin_to_use_the_WordPress_REST_API\" >Do I need a plugin to use the WordPress REST API?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#How_do_I_check_if_the_REST_API_is_working_on_my_site\" >How do I check if the REST API is working on my site?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-17\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#Is_the_REST_API_a_security_risk\" >Is the REST API a security risk?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-18\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#What_is_the_difference_between_the_REST_API_and_headless_WordPress\" >What is the difference between the REST API and headless WordPress?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-19\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#Can_the_REST_API_create_and_edit_content_or_only_read_it\" >Can the REST API create and edit content, or only read it?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-20\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#Does_using_the_REST_API_slow_my_site_down\" >Does using the REST API slow my site down?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-21\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#Is_the_WooCommerce_API_the_same_as_the_WordPress_REST_API\" >Is the WooCommerce API the same as the WordPress REST API?<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-22\" href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-rest-api\/#Getting_it_built\" >Getting it built<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"p2\"><span class=\"ez-toc-section\" id=\"Why_the_REST_API_matters_in_plain_terms\"><\/span>Why the REST API matters in plain terms<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p class=\"p1\">Every WordPress install since version 4.4 (released December 2015) ships with the REST API built in. There is nothing to buy or bolt on. Your site is already able to serve its content as data.<\/p>\n<p class=\"p1\">For a business, that matters for a few reasons:<\/p>\n<ul class=\"ul1\">\n<li class=\"li3\"><b>You are not locked to one front end.<\/b> The same posts and products can power your website today and a mobile app next year without duplicating content.<\/li>\n<li class=\"li3\"><b>Systems can talk to each other.<\/b> A CRM, an email platform or an internal dashboard can pull WordPress content or push new content in, on a schedule, without anyone copying and pasting.<\/li>\n<li class=\"li1\"><b>You can modernise the look without a rebuild.<\/b> A fast JavaScript front end can sit in front of WordPress while your team keeps writing in the familiar editor.<\/li>\n<\/ul>\n<p class=\"p1\">The WordPress Block Editor itself runs on the REST API. Every time an author saves a draft or inserts an image, the browser is quietly making REST requests in the background. So this is not a fringe feature. It is core plumbing.<\/p>\n<h2 class=\"p2\"><span class=\"ez-toc-section\" id=\"How_the_WordPress_REST_API_works\"><\/span>How the WordPress REST API works<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p class=\"p1\">The API is a set of URLs, called routes, that represent your site&#8217;s data. A route plus the HTTP method you use against it forms an endpoint. Send a request to an endpoint, get back a JSON response.<\/p>\n<h3 class=\"p4\"><span class=\"ez-toc-section\" id=\"The_base_and_the_namespace\"><\/span>The base and the namespace<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p class=\"p1\">Everything lives under a single base path on your domain:<\/p>\n<p class=\"p5\">https:\/\/yoursite.com\/wp-json\/<\/p>\n<p class=\"p1\">Visit that URL in a browser on any standard WordPress site and you will see a large JSON document describing the API itself: which namespaces exist, which routes are available and what each accepts.<\/p>\n<p class=\"p1\">Routes are grouped into namespaces so that plugins can add their own without clashing. WordPress core content sits in the <span class=\"s2\">wp\/v2<\/span> namespace:<\/p>\n<p class=\"p5\">https:\/\/yoursite.com\/wp-json\/wp\/v2\/posts<\/p>\n<p class=\"p1\">WooCommerce, for example, exposes its data under <span class=\"s2\">wc\/v3<\/span>, and a plugin you build can register its own namespace. The version number (<span class=\"s2\">v2<\/span>) means the core team can introduce a <span class=\"s2\">v3<\/span> later without breaking existing integrations.<\/p>\n<h3 class=\"p4\"><span class=\"ez-toc-section\" id=\"CRUD_through_HTTP_methods\"><\/span>CRUD through HTTP methods<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p class=\"p1\">The REST API maps the four basic content operations to standard HTTP methods. This is the pattern to keep in mind:<\/p>\n<table class=\"t1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p3\">Action<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p3\">HTTP method<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p3\">Example<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">Read a collection<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">GET<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">GET \/wp-json\/wp\/v2\/posts<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">Read one item<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">GET<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">GET \/wp-json\/wp\/v2\/posts\/42<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">Create<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">POST<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">POST \/wp-json\/wp\/v2\/posts<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">Update<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">POST, PUT or PATCH<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">POST \/wp-json\/wp\/v2\/posts\/42<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">Delete<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">DELETE<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">DELETE \/wp-json\/wp\/v2\/posts\/42<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"p1\">Reading public content needs no login. Creating, updating or deleting almost always needs authentication, which we cover further down.<\/p>\n<h3 class=\"p4\"><span class=\"ez-toc-section\" id=\"A_first_request\"><\/span>A first request<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p class=\"p1\">Fetching the ten most recent published posts is a plain GET request. Here it is with <span class=\"s2\">curl<\/span>:<\/p>\n<p class=\"p5\">curl https:\/\/yoursite.com\/wp-json\/wp\/v2\/posts<\/p>\n<p class=\"p1\">You get back a JSON array. Each post object includes fields like <span class=\"s2\">id<\/span>, <span class=\"s2\">date<\/span>, <span class=\"s2\">slug<\/span>, <span class=\"s2\">status<\/span>, <span class=\"s2\">title<\/span>, <span class=\"s2\">content<\/span>, <span class=\"s2\">excerpt<\/span>, <span class=\"s2\">author<\/span> and <span class=\"s2\">featured_media<\/span>. The title and content come as objects with a <span class=\"s2\">rendered<\/span> property holding the HTML.<\/p>\n<p class=\"p1\">You can shape the response with query parameters instead of pulling everything and filtering later:<\/p>\n<p class=\"p5\">GET \/wp-json\/wp\/v2\/posts?per_page=5&amp;categories=12&amp;_fields=id,title,link<\/p>\n<p class=\"p1\">That asks for five posts in category 12 and returns only the id, title and link. Trimming fields with <span class=\"s2\">_fields<\/span> is one of the easiest ways to keep responses small and fast.<\/p>\n<h3 class=\"p2\"><span class=\"ez-toc-section\" id=\"Common_endpoints\"><\/span>Common endpoints<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p class=\"p1\">Under the <span class=\"s2\">wp\/v2<\/span> namespace you get endpoints for the main content types out of the box. A single item is addressed by appending its ID to the collection route.<\/p>\n<table class=\"t1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p3\">Resource<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p3\">Collection route<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p3\">Single item<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">Posts<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">\/wp-json\/wp\/v2\/posts<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">\/wp-json\/wp\/v2\/posts\/&lt;id&gt;<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">Pages<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">\/wp-json\/wp\/v2\/pages<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">\/wp-json\/wp\/v2\/pages\/&lt;id&gt;<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">Media<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">\/wp-json\/wp\/v2\/media<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">\/wp-json\/wp\/v2\/media\/&lt;id&gt;<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">Categories<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">\/wp-json\/wp\/v2\/categories<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">\/wp-json\/wp\/v2\/categories\/&lt;id&gt;<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">Tags<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">\/wp-json\/wp\/v2\/tags<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">\/wp-json\/wp\/v2\/tags\/&lt;id&gt;<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">Comments<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">\/wp-json\/wp\/v2\/comments<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">\/wp-json\/wp\/v2\/comments\/&lt;id&gt;<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">Users<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">\/wp-json\/wp\/v2\/users<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">\/wp-json\/wp\/v2\/users\/&lt;id&gt;<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">Taxonomies<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">\/wp-json\/wp\/v2\/taxonomies<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">\/wp-json\/wp\/v2\/taxonomies\/&lt;slug&gt;<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">Reusable blocks<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">\/wp-json\/wp\/v2\/blocks<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">\/wp-json\/wp\/v2\/blocks\/&lt;id&gt;<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">Site settings<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">\/wp-json\/wp\/v2\/settings<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">(single object)<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">Search<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p6\">\/wp-json\/wp\/v2\/search<\/p>\n<\/td>\n<td class=\"td2\" valign=\"top\">\n<p class=\"p3\">(query only)<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"p1\">Custom post types and custom fields can join this list too. When a developer registers a custom post type with <span class=\"s2\">show_in_rest<\/span> set to <span class=\"s2\">true<\/span>, it automatically gets its own endpoint, for example <span class=\"s2\">\/wp-json\/wp\/v2\/events<\/span>. That is how you expose bespoke content, such as properties, courses or job listings, to an app or another system.<\/p>\n<h3 class=\"p2\"><span class=\"ez-toc-section\" id=\"Authentication\"><\/span>Authentication<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p class=\"p1\">Public reads are open. The moment you want to create, edit or delete content, or read anything private, WordPress needs to know who is asking and whether they are allowed. There are four common approaches.<\/p>\n<table class=\"t1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p3\">Method<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p3\">Best for<\/p>\n<\/td>\n<td class=\"td1\" valign=\"top\">\n<p class=\"p3\">Notes<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td3\" valign=\"top\">\n<p class=\"p3\">Cookie plus nonce<\/p>\n<\/td>\n<td class=\"td3\" valign=\"top\">\n<p class=\"p3\">Code running inside WordPress (themes, plugins, the Block Editor)<\/p>\n<\/td>\n<td class=\"td3\" valign=\"top\">\n<p class=\"p3\">Uses the logged-in session; needs an <span class=\"s2\">X-WP-Nonce<\/span> token on each request<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td4\" valign=\"top\">\n<p class=\"p3\">Application passwords<\/p>\n<\/td>\n<td class=\"td4\" valign=\"top\">\n<p class=\"p3\">Remote apps and server-to-server integrations<\/p>\n<\/td>\n<td class=\"td4\" valign=\"top\">\n<p class=\"p3\">Built into core since 5.6; uses HTTP Basic Auth over HTTPS<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td4\" valign=\"top\">\n<p class=\"p3\">JWT (via plugin)<\/p>\n<\/td>\n<td class=\"td4\" valign=\"top\">\n<p class=\"p3\">Decoupled front ends and mobile apps<\/p>\n<\/td>\n<td class=\"td4\" valign=\"top\">\n<p class=\"p3\">Stateless tokens; needs a plugin and a signing secret<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"td4\" valign=\"top\">\n<p class=\"p3\">OAuth 1.0a (via plugin)<\/p>\n<\/td>\n<td class=\"td4\" valign=\"top\">\n<p class=\"p3\">Third parties acting on a user&#8217;s behalf<\/p>\n<\/td>\n<td class=\"td4\" valign=\"top\">\n<p class=\"p3\">More setup; suits multi-party delegated access<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3 class=\"p4\"><span class=\"ez-toc-section\" id=\"Cookie_authentication_with_nonces\"><\/span>Cookie authentication with nonces<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p class=\"p1\">When a user is logged into WordPress, the browser already holds a session cookie. Code that runs on the same site, such as the Block Editor or a plugin, can rely on that cookie. To stop other sites forging requests, WordPress also requires a nonce, a short-lived token passed as an <span class=\"s2\">X-WP-Nonce<\/span> header or a <span class=\"s2\">_wpnonce<\/span> parameter. This is the default for in-site JavaScript and needs no extra configuration.<\/p>\n<h3 class=\"p4\"><span class=\"ez-toc-section\" id=\"Application_passwords\"><\/span>Application passwords<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p class=\"p1\">This is the option most remote integrations should reach for. Since WordPress 5.6, each user can generate one or more application passwords from their profile page in wp-admin. These are separate from the account&#8217;s real password and can be revoked individually if a connected app is retired or compromised.<\/p>\n<p class=\"p1\">They work with standard HTTP Basic Authentication, so they must only ever travel over HTTPS:<\/p>\n<p class=\"p5\">curl -X POST https:\/\/yoursite.com\/wp-json\/wp\/v2\/posts \\<span class=\"s3\"><br \/>\n<\/span><span class=\"Apple-converted-space\">\u00a0 <\/span>&#8211;user &#8220;editor:abcd EFGH ijkl MNOP qrst UVWX&#8221; \\<span class=\"s3\"><br \/>\n<\/span><span class=\"Apple-converted-space\">\u00a0 <\/span>-H &#8220;Content-Type: application\/json&#8221; \\<span class=\"s3\"><br \/>\n<\/span><span class=\"Apple-converted-space\">\u00a0 <\/span>-d &#8216;{&#8220;title&#8221;:&#8221;Posted via the REST API&#8221;,&#8221;status&#8221;:&#8221;draft&#8221;}&#8217;<\/p>\n<p class=\"p1\">That creates a draft post as the <span class=\"s2\">editor<\/span> user. No plugin required.<\/p>\n<h3 class=\"p4\"><span class=\"ez-toc-section\" id=\"JWT_and_OAuth\"><\/span>JWT and OAuth<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p class=\"p1\">For a decoupled front end or a mobile app where users log in themselves, JSON Web Tokens are a common pattern. The client sends credentials once, gets back a signed token, then attaches that token to later requests. WordPress core does not include JWT, so this needs a plugin and careful handling of the signing secret. OAuth 1.0a, also via plugin, suits cases where a third-party service needs to act on behalf of your users without ever holding their password.<\/p>\n<p class=\"p1\">Whichever method you choose, permissions still apply. The REST API respects WordPress roles and capabilities, so an authenticated Subscriber cannot publish posts just because they hold a valid token.<\/p>\n<h3 class=\"p2\"><span class=\"ez-toc-section\" id=\"Custom_endpoints\"><\/span>Custom endpoints<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p class=\"p1\">The built-in endpoints cover core content, but real projects often need something specific: a combined payload for a dashboard, a purpose-built search, or an action that triggers business logic. You register your own route with <span class=\"s2\">register_rest_route<\/span>, usually hooked to <span class=\"s2\">rest_api_init<\/span>:<\/p>\n<p class=\"p5\">add_action( &#8216;rest_api_init&#8217;, function () {<span class=\"s3\"><br \/>\n<\/span><span class=\"Apple-converted-space\">\u00a0 <\/span>register_rest_route( &#8216;mpd\/v1&#8217;, &#8216;\/quote&#8217;, array(<span class=\"s3\"><br \/>\n<\/span><span class=\"Apple-converted-space\">\u00a0 \u00a0 <\/span>&#8216;methods&#8217; <span class=\"Apple-converted-space\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 <\/span>=&gt; &#8216;POST&#8217;,<span class=\"s3\"><br \/>\n<\/span><span class=\"Apple-converted-space\">\u00a0 \u00a0 <\/span>&#8216;callback&#8217;<span class=\"Apple-converted-space\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 <\/span>=&gt; &#8216;mpd_handle_quote&#8217;,<span class=\"s3\"><br \/>\n<\/span><span class=\"Apple-converted-space\">\u00a0 \u00a0 <\/span>&#8216;permission_callback&#8217; =&gt; function () {<span class=\"s3\"><br \/>\n<\/span><span class=\"Apple-converted-space\">\u00a0 \u00a0 \u00a0 <\/span>return current_user_can( &#8216;edit_posts&#8217; );<span class=\"s3\"><br \/>\n<\/span><span class=\"Apple-converted-space\">\u00a0 \u00a0 <\/span>},<span class=\"s3\"><br \/>\n<\/span><span class=\"Apple-converted-space\">\u00a0 <\/span>) );<span class=\"s3\"><br \/>\n<\/span>} );<\/p>\n<p class=\"p1\">This creates <span class=\"s2\">POST \/wp-json\/mpd\/v1\/quote<\/span>, routed to your <span class=\"s2\">mpd_handle_quote<\/span> function. Note the <span class=\"s2\">permission_callback<\/span>. Every custom route must define one. Leaving it open is a common and serious mistake, because it can expose an endpoint to anyone. If a route should be public, return <span class=\"s2\">true<\/span> deliberately rather than by omission.<\/p>\n<p class=\"p1\">Custom endpoints are where the REST API stops being a content feed and starts being an application interface tailored to your business.<\/p>\n<h2 class=\"p2\"><span class=\"ez-toc-section\" id=\"Security_and_performance_to_plan_for\"><\/span>Security and performance to plan for<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p class=\"p1\">The REST API is safe by design, but it still deserves attention on a live site.<\/p>\n<p class=\"p1\"><b>Security points worth checking:<\/b><b><\/b><\/p>\n<ul class=\"ul1\">\n<li class=\"li3\"><b>Always use HTTPS.<\/b> Application passwords and tokens are readable in transit without it.<\/li>\n<li class=\"li3\"><b>The users endpoint is public by default.<\/b> <span class=\"s2\">GET \/wp-json\/wp\/v2\/users<\/span> can list author accounts and usernames on many sites. Restrict or filter it if that concerns you.<\/li>\n<li class=\"li3\"><b>Set a permission callback on every custom route.<\/b> No exceptions.<\/li>\n<li class=\"li3\"><b>Validate and sanitise input.<\/b> Treat data arriving at your endpoints the same way you would treat any form submission.<\/li>\n<li class=\"li1\"><b>Rate limit and monitor.<\/b> Public endpoints can be hit hard. A caching layer or a firewall rule helps.<\/li>\n<\/ul>\n<p class=\"p1\"><b>Performance points worth checking:<\/b><b><\/b><\/p>\n<ul class=\"ul1\">\n<li class=\"li3\"><b>Ask for less.<\/b> Use <span class=\"s2\">_fields<\/span> to return only what you need and <span class=\"s2\">per_page<\/span> to control page size.<\/li>\n<li class=\"li3\"><b>Cache reads.<\/b> GET responses for public content can be cached at the CDN or object-cache level so WordPress is not rebuilding them on every hit.<\/li>\n<li class=\"li1\"><b>Reduce round trips.<\/b> Where a screen needs data from several sources, a single custom endpoint that assembles it is faster than many separate calls.<\/li>\n<\/ul>\n<p class=\"p1\">These are the same disciplines that govern any <a href=\"https:\/\/mediaplusdigital.co\/au\/what-is-web-development\/\"><span class=\"s1\">web development<\/span><\/a> work. The REST API does not remove the need for them.<\/p>\n<h2 class=\"p2\"><span class=\"ez-toc-section\" id=\"When_a_business_should_use_it\"><\/span>When a business should use it<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p class=\"p1\">The REST API is not the right answer to every project, so here is a straight read on when it earns its keep.<\/p>\n<p class=\"p1\"><b>Good reasons to use it:<\/b><b><\/b><\/p>\n<ul class=\"ul1\">\n<li class=\"li3\"><b>Headless or decoupled sites.<\/b> Keep WordPress as the editor your team knows, and serve the front end with a fast framework such as Next.js, Nuxt or a static build. Editors carry on as normal; visitors get a quicker, app-like experience.<\/li>\n<li class=\"li3\"><b>Mobile apps.<\/b> A native iOS or Android app can pull articles, listings or account data straight from WordPress rather than duplicating a content system. This pairs naturally with <a href=\"https:\/\/mediaplusdigital.co\/au\/mobile-app-development\/\"><span class=\"s1\">mobile app development<\/span><\/a>.<\/li>\n<li class=\"li3\"><b>Integrations.<\/b> Sync content or leads between WordPress and a CRM, ERP, email tool or internal system on a schedule.<\/li>\n<li class=\"li1\"><b>Custom dashboards and portals.<\/b> Build a members&#8217; area or a staff dashboard that reads and writes WordPress data through purpose-built endpoints.<\/li>\n<\/ul>\n<p class=\"p1\"><b>When to hold off:<\/b><b><\/b><\/p>\n<ul class=\"ul1\">\n<li class=\"li3\">A standard brochure or content site that is only ever viewed in a browser rarely needs a decoupled build. A well-made theme is simpler to run and cheaper to maintain.<\/li>\n<li class=\"li1\">Going headless adds a second codebase and a second thing to host, deploy and secure. That cost is worth paying when it buys performance or reach, and not much otherwise.<\/li>\n<\/ul>\n<p class=\"p1\">If you are still weighing up the platform itself, our pieces on <a href=\"https:\/\/mediaplusdigital.co\/au\/why-use-wordpress-for-your-website\/\"><span class=\"s1\">why WordPress works for many businesses<\/span><\/a> and the honest <a href=\"https:\/\/mediaplusdigital.co\/au\/pros-and-cons-of-wordpress\/\"><span class=\"s1\">pros and cons of WordPress<\/span><\/a> give a balanced view before you commit to an architecture.<\/p>\n<h2 class=\"p2\"><span class=\"ez-toc-section\" id=\"Frequently_asked_questions\"><\/span>Frequently asked questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3 class=\"p1\"><span class=\"ez-toc-section\" id=\"Do_I_need_a_plugin_to_use_the_WordPress_REST_API\"><\/span><b>Do I need a plugin to use the WordPress REST API?<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p class=\"p1\">No. It has been part of WordPress core since version 4.4 in December 2015. Any current WordPress site already exposes it at <span class=\"s2\">\/wp-json\/<\/span>. Plugins are only needed for extras such as JWT authentication or to add custom endpoints, which you can also do in your own code.<\/p>\n<h3 class=\"p1\"><span class=\"ez-toc-section\" id=\"How_do_I_check_if_the_REST_API_is_working_on_my_site\"><\/span><b>How do I check if the REST API is working on my site?<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p class=\"p1\">Open <span class=\"s2\">https:\/\/yoursite.com\/wp-json\/<\/span> in a browser. If you see a page of JSON describing the API, it is running. To test a real endpoint, try <span class=\"s2\">https:\/\/yoursite.com\/wp-json\/wp\/v2\/posts<\/span>, which should return your recent posts as JSON.<\/p>\n<h3 class=\"p1\"><span class=\"ez-toc-section\" id=\"Is_the_REST_API_a_security_risk\"><\/span><b>Is the REST API a security risk?<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p class=\"p1\">Used properly it is safe, and it respects the same user roles and permissions as the rest of WordPress. The usual cautions apply: serve everything over HTTPS, set a permission callback on every custom endpoint, validate incoming data, and restrict the public users endpoint if listing author names is a concern.<\/p>\n<h3 class=\"p1\"><span class=\"ez-toc-section\" id=\"What_is_the_difference_between_the_REST_API_and_headless_WordPress\"><\/span><b>What is the difference between the REST API and headless WordPress?<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p class=\"p1\">The REST API is the interface, the set of URLs that serve your content as data. Headless WordPress is one way to use it: you keep WordPress for editing but build a separate front end that reads content through the API instead of using WordPress themes to display it.<\/p>\n<h3 class=\"p1\"><span class=\"ez-toc-section\" id=\"Can_the_REST_API_create_and_edit_content_or_only_read_it\"><\/span><b>Can the REST API create and edit content, or only read it?<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p class=\"p1\">Both. Reading public content is open. Creating, updating and deleting content is done with POST, PUT, PATCH and DELETE requests and requires authentication, most commonly an application password for remote use.<\/p>\n<h3 class=\"p1\"><span class=\"ez-toc-section\" id=\"Does_using_the_REST_API_slow_my_site_down\"><\/span><b>Does using the REST API slow my site down?<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p class=\"p1\">Not inherently. Poorly built integrations that request too much data or make too many calls can add load. Trimming responses with <span class=\"s2\">_fields<\/span>, controlling page size, and caching public GET responses keep it fast.<\/p>\n<h3 class=\"p1\"><span class=\"ez-toc-section\" id=\"Is_the_WooCommerce_API_the_same_as_the_WordPress_REST_API\"><\/span><b>Is the WooCommerce API the same as the WordPress REST API?<\/b><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p class=\"p1\">It is built on the same foundation but uses its own namespace, <span class=\"s2\">wc\/v3<\/span>, and its own authentication keys. If you need product, order or customer data, you generally use the WooCommerce endpoints rather than the core <span class=\"s2\">wp\/v2<\/span> ones.<\/p>\n<h2 class=\"p2\"><span class=\"ez-toc-section\" id=\"Getting_it_built\"><\/span>Getting it built<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p class=\"p1\">The WordPress REST API turns a familiar content platform into something an app, a modern front end or another business system can build on. The concepts are approachable; getting authentication, permissions, caching and custom endpoints right on a production site is where experience pays off.<\/p>\n<p class=\"p1\">If you are considering a headless build, a mobile app backed by WordPress, or an integration between WordPress and your other systems, our team can help. See our <a href=\"https:\/\/mediaplusdigital.co\/au\/wordpress-website-development\/\"><span class=\"s1\">WordPress website development<\/span><\/a> and broader <a href=\"https:\/\/mediaplusdigital.co\/au\/web-design-development\/\"><span class=\"s1\">web design and development<\/span><\/a> services, or read <a href=\"https:\/\/mediaplusdigital.co\/au\/how-to-develop-a-wordpress-website\/\"><span class=\"s1\">how we approach building a WordPress website<\/span><\/a> from the ground up. Tell us what you want to connect, and we will map the shortest path to it.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The WordPress REST API is an interface that lets applications interact with a WordPress site by sending and receiving JSON data over HTTP. Instead of logging into wp-admin to read or change content, a program makes a web request to a URL and gets back structured data it can use anywhere. That one capability changes [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":6826,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[25],"tags":[],"class_list":["post-6825","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-website-design-and-development"],"_links":{"self":[{"href":"https:\/\/mediaplusdigital.co\/au\/wp-json\/wp\/v2\/posts\/6825","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mediaplusdigital.co\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mediaplusdigital.co\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mediaplusdigital.co\/au\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/mediaplusdigital.co\/au\/wp-json\/wp\/v2\/comments?post=6825"}],"version-history":[{"count":0,"href":"https:\/\/mediaplusdigital.co\/au\/wp-json\/wp\/v2\/posts\/6825\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mediaplusdigital.co\/au\/wp-json\/wp\/v2\/media\/6826"}],"wp:attachment":[{"href":"https:\/\/mediaplusdigital.co\/au\/wp-json\/wp\/v2\/media?parent=6825"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mediaplusdigital.co\/au\/wp-json\/wp\/v2\/categories?post=6825"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mediaplusdigital.co\/au\/wp-json\/wp\/v2\/tags?post=6825"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}