/handbook/developing-for-block-editor-and-site-editor/rest-api-overview/

Good Work. Since 2009

Our Work

What We Do

Digital Platform MigrationsKey SolutionsManaged ServicesStaffing SolutionsIndustriesProducts



Drupal to WordPress



Kentico to WordPress



Sitecore to WordPress



AEM to WordPress



Umbraco to WordPress

Any CMS to WordPress

Arc XP to WordPress

Hubspot to WordPress

Contentful to WordPress

Optimizely to WordPress

Craft CMS to WordPress



Sanity to WordPress



Strapi to WordPress



OnePress

OnePress is a way to use WordPress for multi-brand organizations, intranet network sites or large publishers.



Corporate Website Development

Build a corporate website that speaks to all your stakeholders including investors, partners, corporate social responsibility, etc.



WordPress as a composable DXP

We make a case for WordPress as a composable DXP when the market has realized that monolithic systems are not going to cut it



Frappe/ERPNext

Build scalable ERP and custom web applications with ERPNext — from implementation and integrations to long-term support.



Discovery

Strategic consultancy & project roadmap



Growth Services

On demand development & consultation



Site Maintenance

Annual maintenance. Done for you



QE Services

Testing across SDLC for assured quality



Hosting Migration

Move to a performant hosting with zero downtime



WooCommerce

Enterprise commerce delivered without lock-in



AI

Unlock real use cases and integrations



All Services

A suite of services for any need



Staff Augmentation

Scale your team quickly with vetted WordPress engineers, ready to join in a week.
backed by flexible pricing, transparent practices, and full-time zone support.

Technology STACK

React

Node.js

Next.js

w3c accessibilities

PWA

Laravel

Nginx

GraphQL

Typescript



Digital publication & media

Deliver content-rich digital experiences with scalable WordPress and headless solutions.



Large product & SaaS

Accelerate your product or SaaS growth with tailored development and robust integrations.



Automotive

Build secure, high-performance WordPress solutions for the automotive industry’s unique needs.



Conglomerates

Handle complex, multi-business operations with unified digital strategy and infrastructure.



eCommerce

Scale your e-commerce with WooCommerce, integrations, and custom extensions for growth.



All Industries

Helping enterprises across industries with scalable WordPress solutions and tailored strategies.



GoDAM

Built-in transcoding, adaptive bitrate streaming, interactive video overlays, and asset management.



EasyEngine

Server management tool that makes using WordPress on Nginx easy.



Web Auditor

Performance Audit & Insights for your Website.

rtmedia

rtMedia

A complete media management plugin for WordPress.

Resources

Resources thumbnail

Resources

Extensive resources published from our enterprise web practice, covering migrations, multisite consolidations, DXP, and more.

Newsletters

Subscribe

client handbook thumbnail

Client Handbook

Blog thumbnail

Blogs

About Us



Good Work.
Good People.

About Us

The story behind becoming the go-to agency for global enterprises, & delivering scalable digital experiences with our 250+ professionals.

Partnerships

WordPress VIP Agency Partner

Pagely Partnerships

Frappe / ERP Partnership



Open Source Contributions



Careers

CLEAR

contact us

separator Resources separator Developing for Block Editor and Site Editor separator REST API & datastore separator REST API overview

Topics

On this page

Key Concepts

REST API Basics

Best Practices for Using the WordPress REST API

1. Use the Correct HTTP Method

2. Leverage Nonces for Security

3. Paginate Large Requests

4. Use Filtering and Query Parameters Efficiently

5. Validate and Sanitize Inputs

6. Cache Responses When Possible

7. Handle Error Responses Gracefully

8. Use Namespaces for Custom Endpoints

9. Authentication and Authorization

10. Rate-Limit API Requests

11. Version Your Endpoints

Example of Common REST API Requests

Retrieve All Posts

Create a New Post

Update Post Meta Data

Delete a Post

Last updated on May 26, 2026

REST API Overview

The WordPress REST API is a powerful tool that allows developers to interact with WordPress from external systems, apps, or frontend JavaScript without directly accessing the WordPress admin. It provides a flexible way to build custom features or integrate with third-party services.

Key Concepts

The REST API in WordPress allows for HTTP requests such as GET, POST, PUT, DELETE, etc., to retrieve, create, update, or delete data on the WordPress site. Each endpoint corresponds to a WordPress feature or data type, like posts, pages, users, or custom post types.

REST API Basics

Best Practices for Using the WordPress REST API

1. Use the Correct HTTP Method

Always use the proper HTTP method based on the action you intend to perform. For instance:

This ensures clarity in your code and leverages HTTP semantics properly.

2. Leverage Nonces for Security

When making requests that alter data (like POST, PUT, or DELETE), ensure you use nonces for security. Nonces help protect against CSRF (Cross-Site Request Forgery) attacks.


			wp_create_nonce('wp_rest');
		

Include the nonce in your request headers under the X-WP-Nonce field.

3. Paginate Large Requests

When querying large sets of data, such as posts or users, always use pagination to avoid performance bottlenecks. The REST API provides parameters like per_page and page for this purpose.

Example of paginated request:


			/wp-json/wp/v2/posts?per_page=10&page=2
		

This limits the response to 10 posts and fetches the second page of results.

4. Use Filtering and Query Parameters Efficiently

Rather than fetching all data and filtering it client-side, take advantage of built-in query parameters like filter, order, orderby, or custom ones like meta_query to narrow down results on the server.

For example, if you only want to retrieve published posts in ascending order of date:


			/wp-json/wp/v2/posts?status=publish&orderby=date&order=asc
		

This minimizes the amount of data transferred and processed by the client.

5. Validate and Sanitize Inputs

When building custom endpoints or handling sensitive data, always validate and sanitize the input data on the server side using functions like:


			sanitize_text_field();

sanitize_email();

esc_url_raw();
		

This ensures only safe, valid data gets processed by WordPress.

6. Cache Responses When Possible

To reduce server load and speed up your application, cache responses when possible. WordPress provides built-in support for caching with plugins like WP REST Cache. For client-side caching, use ETags and response headers like Last-Modified.


			Cache-Control: max-age=3600, must-revalidate
		

This instructs the browser to cache the response for 1 hour.

7. Handle Error Responses Gracefully

The REST API follows standard HTTP status codes. Always check for errors in your response and handle them gracefully.

Example of handling errors:


			fetch('/wp-json/wp/v2/posts')

  .then(response => {

    if (!response.ok) {

      throw new Error('Something went wrong');

    }

    return response.json();

  })

  .then(data => console.log(data))

  .catch(error => console.error('Error:', error));
		

8. Use Namespaces for Custom Endpoints

When adding custom endpoints, avoid conflicts by using unique namespaces. Custom namespaces help distinguish your routes from core WordPress routes.


			register_rest_route( 'myplugin/v1', '/custom-endpoint', array(

    'methods' => 'GET',

    'callback' => 'my_custom_function',

) );
		

This creates a new endpoint accessible via /wp-json/myplugin/v1/custom-endpoint.

9. Authentication and Authorization

For sensitive actions, implement strong authentication, such as OAuth or Application Passwords. Ensure that users have the correct capabilities by using permission callbacks in your custom routes:


			register_rest_route( 'myplugin/v1', '/data', array(

    'methods' => 'POST',

    'callback' => 'my_post_function',

    'permission_callback' => function() {

        return current_user_can( 'edit_posts' );

    }

) );
		

This checks if the user has permission to edit posts before allowing access.

10. Rate-Limit API Requests

To protect your API from abuse, consider implementing rate limiting or quotas for requests. This can be done with the help of a plugin or by custom coding a solution that limits the number of requests a user or IP can make within a certain timeframe.


			add_action( 'rest_api_init', function () {

    // Rate limit logic here

} );
		

11. Version Your Endpoints

Versioning your API ensures backward compatibility when you introduce changes. You can version your endpoints by adding version numbers in the namespace:


			register_rest_route( 'myplugin/v2', '/new-endpoint', array(

    'methods' => 'GET',

    'callback' => 'my_new_function',

) );
		

This allows existing users to continue using the v1 version without breaking functionality while new users can access the updated v2 endpoint.

Example of Common REST API Requests

Retrieve All Posts


			GET /wp-json/wp/v2/posts
		

This retrieves all posts in the WordPress database.

Create a New Post


			POST /wp-json/wp/v2/posts
		

			{

  "title": "New Post",

  "content": "This is the content of the post.",

  "status": "publish"

}
		

post request body.

Update Post Meta Data


			PUT /wp-json/wp/v2/posts/123
		

			{

  "meta": {

    "custom_meta_key": "New meta value"

  }

}
		

put request body.

Delete a Post


			DELETE /wp-json/wp/v2/posts/123
		

This removes the post with the ID 123 from the database.

State management

PREVIOUS

Security best practices

NEXT


Credits

Utsav

Utsav Patel

Author

Utsav Patel

Author

VIEW PROFILE

Good Work. Good People.

Industry partnerships

WordPress VIP Gold Agency Partner

WordPress VIP Partner Innovator

Compliance certifications

location-icon United States  location-icon India

© rtCamp Inc. since 2009. All rights reserved.

Terms of Service · Privacy Policy · Trust Center

Company

Solutions

Subscribe to our newsletter and get a few email updates every month.

subscribe to newsletter

location-icon United States  location-icon India

© rtCamp Inc. since 2009. All rights reserved.

Terms of Service · Privacy Policy · Trust Center

Cookie Consent

We value your privacy

We use cookies to give you the best possible experience. By clicking “Accept,” you consent to our use of cookies to improve site functionality, analyze usage, and personalize content and communications. Your privacy matters to us, and we are committed to handling your data responsibly and transparently. Please check our Privacy Policy for more details.

Manage PreferencesDon’t AllowAllow All

Why do we use cookies?

×

By clicking "Accept" or "Decline All" at the bottom, you consent to the use of cookies and other tools as described in our Cookie Policy in accordance with your settings and accept our Terms of Service.

Toggle EssentialEssential

Essential cookies enable basic functions and are necessary for the proper function of the website.

Name

Description

Duration

Geolocation Config

This cookie is used to store the consent settings based on the visitor's location.

30 days

Cookie Preferences

This cookie is used to store the user's cookie consent preferences.

30 days

Toggle CloudFlareCloudFlare

CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.

Service URL: developers.cloudflare.com (opens in a new window)

Name

Description

Duration

cf_clearance

Whether a CAPTCHA or Javascript challenge has been solved.

session

Toggle CommentsComments

These cookies are needed for adding comments on this website.

Name

Description

Duration

comment_author

Used to track the user across multiple sessions.

Session

comment_author_email

Used to track the user across multiple sessions.

Session

comment_author_url

Used to track the user across multiple sessions.

Session

Toggle GodamGodam

GoDAM" is primarily a specialized WordPress plugin and media management service designed to enhance video hosting, marketing, and asset management directly within the WordPress dashboard.

Service URL: godam.io (opens in a new window)

Name

Description

Duration

user_image

Temporarily stores the path to the user's avatar or profile picture for quick rendering in the website header.

session

user_id

Stores the numerical ID of the logged-in user to maintain session continuity and basic site operations.

session

full_name

Stores the logged-in user's display name to personalize the site interface without needing database queries.

session

system_user

First-party cookie used to store basic application state identifying the current system user role.

session

sid

A generic session ID cookie used to maintain user state and functionality as the visitor navigates through the site.

session

Toggle Google reCAPTCHAGoogle reCAPTCHA

Google reCAPTCHA helps protect websites from spam and abuse by verifying user interactions through challenges.

Name

Description

Duration

_GRECAPTCHA

Google reCAPTCHA sets a necessary cookie (_GRECAPTCHA) when executed for the purpose of providing its risk analysis.

179 days

Toggle Google Tag ManagerGoogle Tag Manager

Google Tag Manager simplifies the management of marketing tags on your website without code changes.

Name

Description

Duration

cookiePreferences

Registers cookie preferences of a user

2 years

td

Registers statistical data on users' behaviour on the website. Used for internal analytics by the website operator.

session

Toggle StatisticsStatistics

Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.

Toggle Factors AIFactors AI

Factors.ai is a B2B account intelligence and marketing analytics platform that helps Go-To-Market (GTM) teams identify anonymous website visitors, track buyer journeys, and measure the ROI of marketing campaigns.

Service URL: www.factors.ai (opens in a new window)

Name

Description

Duration

_fuid

It is sent to capture session details and track user behavior across your website to provide behavioral data and intent signals.

1 Year

Toggle Google AnalyticsGoogle Analytics

Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.

Service URL: policies.google.com (opens in a new window)

Name

Description

Duration

FPGSID

Stores a session or user identifier to track how visitors interact with a website. This helps Google Analytics measure website performance, user engagement, and usage patterns.

Session

FPLC

Used by Google Analytics to link visitor interactions and sessions across multiple related domains.

20 hours

FPID

A server-side Google Analytics cookie used as an alternative user identifier when third-party cookies are restricted.

2 years

_ga

ID used to identify users

2 years

_ga_

ID used to identify users

2 years

Toggle Jetpack StatsJetpack Stats

Jetpack's built-in visitor analytics. It records page views, referring sites, search terms, and outbound link clicks, and also carries the shared visitor-tracking library used by Jetpack Instant Search and WooCommerce Analytics.

Service URL: automattic.com (opens in a new window)

Name

Description

Duration

tk_aip

Stores a list of anonymous visitor IDs so they can be merged into one identity once a visitor is recognized.

Up to 5 years

tk_tc

Used once per page load to work out which cookie domain the Tracks library should use, then removed as soon as it's read back.

Session (deleted immediately after use)

tk_qs

Queues analytics events for Jetpack's Tracks library so none are lost if the page closes before they can be sent.

30 minutes

tk_ai

Stores a randomly-generated anonymous visitor ID so Jetpack's Tracks analytics library can link tracking events to the same visitor.

Session in wp-admin; up to 5 years on the frontend

Toggle Microsoft ClarityMicrosoft Clarity

Clarity is a web analytics service that tracks and reports website traffic.

Service URL: clarity.microsoft.com (opens in a new window)

Name

Description

Duration

CLID

Identifies the first-time Clarity saw this user on any site using Clarity.

12 months

ANONCHK

Indicates whether MUID is transferred to ANID, a cookie used for advertising. Clarity doesn't use ANID and so this is always set to 0.

Session

_clck

Persists the Clarity User ID and preferences, unique to that site is attributed to the same user ID.

12 months

_clsk

Connects multiple page views by a user into a single Clarity session recording.

12 months

Toggle Parse.lyParse.ly

Parse.ly is a content analytics platform that helps publishers optimize audience engagement and content performance.

Name

Description

Duration

cookies.js_dtest

This cookie determines whether the browser accepts cookies.

session

_parsely_session

JSON document storing information identifying a browsing session according to Parsely’s proprietary definition

30 minutes

_parsely_visitor

JSON document uniquely identifying a browser and counting its sessions

13 months

Toggle SalespanelSalespanel

Salespanel is a B2B marketing and sales software that identifies, tracks, and qualifies website visitors and leads in real-time using first-party data. It helps businesses monitor customer journeys, score leads based on behavior, and syncs this data with CRMs (like Pipedrive or HubSpot) to improve conversion rates.

Service URL: salespanel.io (opens in a new window)

Name

Description

Duration

track_uid

Identify and tracking a lead

12 moths

Toggle MarketingMarketing

Marketing cookies are used to follow visitors to websites. The intention is to show ads that are relevant and engaging to the individual user.

Toggle Bing / MicrosoftBing / Microsoft

Bing, powered by Microsoft, is a search engine providing web, image, video, and map search capabilities.

Name

Description

Duration

MR

Used to collect information for analytics purposes.

6 months

ANONCHK

Used to store session ID for a users session to ensure that clicks from adverts on the Bing search engine are verified for reporting purposes and for personalisation

10 minutes

SM

Used by Microsoft in synchronizing the MUID across multiple Microsoft domains to track users for advertising.

session

MUID

Identifies unique web browsers visiting Microsoft sites. These cookies are used for advertising, site analytics, and other operational purposes.

1 year

Toggle DoubleClick/Google MarketingDoubleClick/Google Marketing

A comprehensive digital advertising platform for managing campaigns, optimizing performance, and analyzing audience data.

Name

Description

Duration

IDE

This cookie is used for targeting, analyzing and optimisation of ad campaigns in DoubleClick/Google Marketing Suite

2 years

ar_debug

Store and track conversions

Persistent

Toggle LinkedInLinkedIn

LinkedIn is a professional networking platform for job seekers, employers, and industry connections.

Name

Description

Duration

bscookie

Used by LinkedIn to track the use of embedded services.

1 year

AnalyticsSyncHistory

Used to store information about the time a sync with the lms_analytics cookie took place for users in the Designated Countries

30 days

bcookie

Used by LinkedIn to track the use of embedded services.

1 year

li_sugr

Used to make a probabilistic match of a user's identity outside the Designated Countries

90 days

lidc

Used by the social networking service, LinkedIn, for tracking the use of embedded services.

1 day

UserMatchHistory

Used by LinkedIn Ads to synchronize and match user IDs across different ad networks and data providers.

30 days

Toggle LinkedIn InsightLinkedIn Insight

LinkedIn Insight is a web analytics service that tracks and reports website traffic.

Service URL: www.linkedin.com (opens in a new window)

Name

Description

Duration

li_sugr

Used to make a probabilistic match of a user's identity.

90 days

lidc

Used for routing and session management.

24 hours

Toggle LiveIntentLiveIntent

LiveIntent provides a platform for email advertising and identity-driven marketing solutions.

Name

Description

Duration

_lc2_fpi_js

Companion cookie to _lc2_fpi used by JavaScript to facilitate cross-domain ad tracking and user identification.

1 year

_lc2_fpi

First-party tracking cookie usually associated with LiveRamp to identify users across devices for targeted advertising.

1 Year

_li_ss

Sets a unique ID for the visitor, that allows third party advertisers to target the visitor with relevant advertisement. This pairing service is provided by third party advertisement hubs, which facilitates real-time bidding for advertisers.

1 month

lidid

Collects data on visitors' behaviour and interaction - This is used to make advertisement on the website more relevant. The cookie also allows the website to detect any referrals from other websites.

2 years

Toggle Cookie PolicyCookie Policy

You can find more information in our Privacy Policy.

Allow AllDecline All

Accept