rest_cookie_invalid_nonce 📝 WordPress

WordPress REST API: {"code":"rest_cookie_invalid_nonce","message":"Cookie check failed"} (403)

A cookie-authenticated REST request carried a missing or stale X-WP-Nonce — common with cached pages or after re-login.

Seen on: WordPress

Meaning

Front-end JavaScript must send a fresh wp_rest nonce. Cached HTML embeds old nonces; logging in/out changes the session; nonces expire after 12–24h.

Common causes

  • Cached page serving an old nonce
  • User logged in/out in another tab
  • Nonce not localized to the script
  • Long-open page

⚡ Quick fix

  1. Localize a fresh nonce with wp_localize_script/wp_add_inline_script
  2. Exclude pages using REST nonces from page cache, or fetch the nonce via AJAX
  3. Refresh on 403 and retry

Detailed fix by platform

WordPress

  1. wp_add_inline_script('my-app', 'window.wpApi = ' . wp_json_encode(['nonce' => wp_create_nonce('wp_rest'), 'root' => esc_url_raw(rest_url())]), 'before');

How to diagnose

  1. Nonce — Sent and fresh?
  2. Cache — Page cached?
  3. Session — Changed?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.