WordPress REST API: {"code":"rest_cookie_invalid_nonce","message":"Cookie check failed"} (403)
A cookie-authenticated REST request carried a missing or stale X-WP-Nonce — common with cached pages or after re-login.
Seen on:
WordPress
Meaning
Front-end JavaScript must send a fresh wp_rest nonce. Cached HTML embeds old nonces; logging in/out changes the session; nonces expire after 12–24h.
Common causes
- Cached page serving an old nonce
- User logged in/out in another tab
- Nonce not localized to the script
- Long-open page
⚡ Quick fix
- Localize a fresh nonce with wp_localize_script/wp_add_inline_script
- Exclude pages using REST nonces from page cache, or fetch the nonce via AJAX
- Refresh on 403 and retry
Detailed fix by platform
WordPress
wp_add_inline_script('my-app', 'window.wpApi = ' . wp_json_encode(['nonce' => wp_create_nonce('wp_rest'), 'root' => esc_url_raw(rest_url())]), 'before');
How to diagnose
- Nonce — Sent and fresh?
- Cache — Page cached?
- Session — Changed?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- Are you sure you want to do this? WordPress: Are you sure you want to do this? Please try again. (nonce check failed)
- Not a valid JSON response WordPress: Updating failed. The response is not a valid JSON response.
- rest_forbidden WordPress REST API: {"code":"rest_forbidden","message":"Sorry, you are not allowed to do that."} (401/403)
Most viewed in WordPress
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026