Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

An introduction to the WordPress REST API

The REST API lets other apps read and change your WordPress content. This guide explains it simply and shows how to try it.

WordPress2 min read4 steps2 screenshots

What is an API?

An API is a set of rules that lets two programs talk to each other. Think of a waiter in a restaurant. You tell the waiter what you want. The waiter goes to the kitchen and brings it back. The API is the waiter between your app and your site.

What is REST?

REST is a popular style of API. It uses ordinary web addresses and the same methods your browser uses. The data comes back in JSON. JSON is a simple text format that programs read easily. It looks like a list of names and values.

With the WordPress REST API, an app can get your posts, add a page or update a user. A phone app or another website can use your content this way.

Screenshot: With the WordPress REST API, an app can get your posts, add a page or update a user. A pho

Common methods

  • GET reads data.
  • POST creates new data.
  • PUT or PATCH changes existing data.
  • DELETE removes data.
    Screenshot: DELETE removes data.

Try it yourself

You can read public posts without logging in.

  1. Open a new browser tab.
  2. Type your site address, followed by /wp-json/. You will see a long page of text. That is the list of what the API offers.
  3. Now type your address followed by /wp-json/wp/v2/posts.
  4. You will see your latest posts in JSON form.

If your site uses plain permalinks, use /?rest_route=/wp/v2/posts instead.

Useful addresses

Address endingWhat it returns
/wp-json/wp/v2/postsPosts
/wp-json/wp/v2/pagesPages
/wp-json/wp/v2/categoriesCategories
/wp-json/wp/v2/mediaMedia items

Using the command line

curl https://yourdomain.com/wp-json/wp/v2/posts?per_page=3

This asks for your three latest posts. Replace the domain with your own.

Logging in for private actions

Creating or changing content needs proof of who you are. WordPress offers "Application Passwords" for this. Go to Users, then Profile, and look for the Application Passwords section. Make one for each app. It is safer than using your normal password.

Warning: Never share an application password. Delete it if you stop using the app.
Tip: Some security plugins block the API. If it does not respond, check their settings or open a support ticket.

Quick recap

  • The REST API lets apps talk to your WordPress site.
  • Data comes back as JSON.
  • Try /wp-json/wp/v2/posts in your browser.
  • Use application passwords for private actions.