Site Health: The REST API encountered an error / Your site could not complete a loopback request (cURL error 28)
WordPress couldn’t call itself over HTTP — needed for the block editor, cron, plugin/theme editors and Site Health.
Seen on:
WordPress
Meaning
Loopbacks go from the server to its own public URL. Firewalls, DNS that resolves to an unreachable IP inside the server, basic auth, Cloudflare challenges, or self-signed certificates break them (cURL error 28 timeout, cURL error 6/7/60).
Common causes
- Server can’t reach its own domain (firewall/NAT hairpin/DNS)
- Basic authentication on the site
- Security plugin/WAF blocking server-to-self requests
- Invalid/self-signed SSL certificate
- Slow plugin causing timeout
⚡ Quick fix
- From the server, curl -I https://yourdomain/wp-json/
- Add the domain to /etc/hosts pointing to 127.0.0.1 if NAT hairpin fails
- Allow the server IP in WAF/security plugins
Detailed fix by platform
Linux
- bash
curl -sI https://example.com/wp-json/ | head -3 echo "127.0.0.1 example.com www.example.com" | sudo tee -a /etc/hosts
How to diagnose
- Reach — curl from the server
- Error — cURL error number
- Auth — Basic auth enabled?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in WordPress
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026