WordPress REST API: {"code":"rest_forbidden","message":"Sorry, you are not allowed to do that."} (401/403)
The REST request isn’t authenticated or the user lacks the capability required by the route’s permission_callback.
Seen on:
WordPress
Meaning
Cookie authentication needs the X-WP-Nonce header; external clients need Application Passwords (Basic auth) or OAuth/JWT. Some hosts strip the Authorization header, and security plugins can disable REST for anonymous users.
Common causes
- Missing X-WP-Nonce for cookie-authenticated requests
- External request without Application Password/JWT
- Authorization header stripped by the server (CGI/FastCGI)
- User lacks the capability
- Security plugin restricting REST
⚡ Quick fix
- Send X-WP-Nonce (wp_create_nonce('wp_rest')) from the frontend
- Use an Application Password for external clients
- Pass Authorization through in .htaccess
Detailed fix by platform
Apache
- apache
# .htaccess — keep the Authorization header for PHP RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
Shell
curl -u "user:abcd efgh ijkl mnop qrst uvwx" https://example.com/wp-json/wp/v2/posts?status=draft
How to diagnose
- Auth — Nonce or Application Password sent?
- Header — Reaches PHP?
- Capability — User role
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in WordPress
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026