rest_forbidden 📝 WordPress

WordPress REST API: {"code":"rest_forbidden","message":"Sorry, you are not allowed to do that."} (401/403)

The REST request isn’t authenticated or the user lacks the capability required by the route’s permission_callback.

Seen on: WordPress

Meaning

Cookie authentication needs the X-WP-Nonce header; external clients need Application Passwords (Basic auth) or OAuth/JWT. Some hosts strip the Authorization header, and security plugins can disable REST for anonymous users.

Common causes

  • Missing X-WP-Nonce for cookie-authenticated requests
  • External request without Application Password/JWT
  • Authorization header stripped by the server (CGI/FastCGI)
  • User lacks the capability
  • Security plugin restricting REST

⚡ Quick fix

  1. Send X-WP-Nonce (wp_create_nonce('wp_rest')) from the frontend
  2. Use an Application Password for external clients
  3. Pass Authorization through in .htaccess

Detailed fix by platform

Apache

  1. apache
    # .htaccess — keep the Authorization header for PHP
    RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]

Shell

  1. curl -u "user:abcd efgh ijkl mnop qrst uvwx" https://example.com/wp-json/wp/v2/posts?status=draft

How to diagnose

  1. Auth — Nonce or Application Password sent?
  2. Header — Reaches PHP?
  3. Capability — User role

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.