Websites and Tech

REST API

Also called WordPress REST API, RESTful API

A way for other software to read and change a website's data using ordinary web addresses and requests, usually returning JSON.

Quick facts: REST API

Category
Websites and Tech
Also called
WordPress REST API, RESTful API
Level
Advanced
Affects
Integrations with other tools, the WordPress editor, headless set-ups, site security
Where to see it
Your browser (visit /wp-json/), Postman, WordPress Application Passwords, security plugins, server logs
In this article4
  1. How a REST API works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

A REST API is a way for other software to read and change a website’s data using ordinary web addresses and standard requests, rather than by loading pages. A tool sends a request to a set address, called an endpoint, and gets back structured data, usually as JSON, that it can use or display however it needs.

How a REST API works

REST is a set of conventions for designing an API. Each type of data has its own address, and the kind of request says what you want to do with it: GET to read, POST to create, PUT or PATCH to update and DELETE to remove. Responses come back with a status code, such as 200 for success or 401 for not authorised, alongside the data.

WordPress has had a built-in REST API since version 4.7. Its endpoints live under /wp-json/ on your domain. Visiting yourdomain.co.uk/wp-json/wp/v2/posts in a browser returns your published posts as JSON. Public content can be read by anyone; creating, editing or deleting anything requires authentication, typically through Application Passwords, which WordPress added in version 5.6, or a plugin that issues tokens.

Much of WordPress depends on it. The block editor saves your work through the REST API, many form, booking and SEO plugins use it, and a headless front end fetches all its content this way.

Why it matters

The REST API is how your website talks to other tools. A CRM that creates blog drafts, an automation service that adds each new enquiry to a spreadsheet, a stock system that updates WooCommerce product prices, or a mobile app that shows your latest articles all rely on it, directly or through connectors such as Zapier and Make. For a small UK business, that can replace a lot of copying and pasting.

It also affects security. By default, WordPress lists users who have published posts at /wp-json/wp/v2/users, with a slug that often matches the login name, which gives attackers half of what they need for password-guessing. Plugins sometimes add endpoints that expose more data than intended, such as order details or form entries, and those have been the source of real vulnerabilities.

For SEO, the /wp-json/ addresses are rarely a problem. Google can find them, but they return JSON rather than pages, so they are not normally indexed. What matters more is that blocking the API with an overzealous security plugin can break forms, the editor and parts of the front end that search engines need to render.

Common mistakes

  • Disabling the REST API entirely for security, which breaks the block editor, contact forms and some page features.
  • Connecting a third-party tool with a full administrator account rather than a limited user and an Application Password.
  • Leaving the user listing endpoint open with usernames that match login names.
  • Not revoking Application Passwords when a contractor or integration is no longer used.
  • Blocking /wp-json/ in robots.txt, which can stop Google rendering pages that load content through it.

How to act on it

Visit /wp-json/ on your own site to see what is public, and check /wp-json/wp/v2/users in particular. If it shows names you would rather keep private, restrict that endpoint with a security plugin or a small code change rather than switching the whole API off. Under Users, review which Application Passwords exist and revoke any you do not recognise.

When you add an integration, give it its own user with the lowest role that works, and note what it can change. Checking endpoints, integrations and what search engines can render on a WordPress site is part of my WordPress SEO service.

Do and do not

Do

  • Use Application Passwords or proper tokens for integrations
  • Give each integration the lowest user role that works
  • Review which endpoints your plugins add

Do not

  • Switch the REST API off completely without testing the editor and forms
  • Share an administrator login with a third-party tool
  • Assume public endpoints only expose what is on the website

Questions people ask about this

Should I disable the WordPress REST API?

Usually not completely, because the block editor and many plugins depend on it. A better approach is to restrict the parts that expose information you do not want public, such as the user list, and to require authentication for anything that changes data. Test the editor, forms and checkout after any change.

What is the difference between a REST API and a webhook?

With a REST API, one system asks another for data or asks it to make a change, whenever it chooses. A webhook works the other way round: the website sends a message to another system automatically when something happens, such as a new order. Many integrations use both.

Can Google index my /wp-json/ URLs?

Google can discover them, because WordPress links to the API in page headers, but it rarely indexes them since they return JSON rather than readable pages. If some do appear in Search Console, adding a noindex header to API responses is a cleaner fix than blocking the folder in robots.txt, which can stop pages rendering properly.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.