sandywp / plugins / disable-json-api

Disable REST API

4.8 out of 5 stars. 4.8 38 reviews

Disable the use of the REST API on your website to site users. Now with User Role support!

Launch a sandbox with this plugin → No signup.
Ready in seconds.

v1.8 80,000+ installs WP 4.9+ PHP 5.6+

your-sandbox.sandywp.com/wp-admin
Disable REST API running inside a SandyWP sandbox

What you get inside

3 screens
  • The JSON returned by a website with the API disabled via filters (WP versions 4.4, 4.5, 4.6)

  • The JSON returned by a website with the API disabled via authentication methods (WP versions 4.7+)

  • The Settings page lets you selectively whitelist endpoints registered with the REST API, on a per-user-role basis.

About this plugin

The most comprehensive plugin for controlling access to the WordPress REST API!

Works as a “set it and forget it” install. Just upload and activate, and the entire REST API will be inaccessible to your general site visitors.

But if you do need to grant access to some endpoints, you can do that too. Go to the Settings page and you can quickly whitelist individual endpoints (or entire branches of endpoints) in the REST API.

You can even do this on a per-user-role basis, so your unauthenticated users have one set of rules while WooCommerce customers have another while Subscribers and Editors and Admins all have their own. NOTE: Out of the box, all defined user roles will still be granted full access to the REST API until you choose to manage those settings.

For most versions of WordPress, this plugin will return an authentication error if a user is not allowed to access an endpoint. For legacy support, WordPress 4.4, 4.5, and 4.6 use the provided rest_enabled filter to disable the entire REST API.

Questions

How do I know if this plugin is working?

While logged into WordPress as any user, the REST API will function as intended. Because of this, you must use a new browser – or Chrome’s incognito mode – to test your website with a clean session. Go to yourdomain.com/wp-json/ (or yourdomain.com/?rest_route=/ if you have pretty permalinks disabled) while NOT LOGGED IN to test the results. You will see an authentication error returned if the plugin is active. “DRA: Only authenticated users can access the REST API.”

Does this plugin disable every REST API that is installed on my site?

This plugin is ONLY meant to disable endpoints accessible via the core REST API that is part of WordPress itself. If a plugin or theme has implemented their own REST API (not to be confused with implementing their own endpoints within the WordPress API) this plugin will have no effect.

4.8

38 reviews

  • 5 ★ 36
  • 4 ★ 0
  • 3 ★ 1
  • 2 ★ 0
  • 1 ★ 1

Ratings come from WordPress.org. SandyWP does not collect its own reviews.

sandywp / also on the shelf

Try another plugin

  • Loginizer

    4.8 · 1M+ installs

    Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

  • Redux Framework

    4.4 · 900K+ installs

    Redux is a simple, truly extensible, and fully responsive options framework for WordPress themes and plugins. It ships with an…

  • Admin Menu Editor

    4.6 · 300K+ installs

    Lets you edit the WordPress admin menu. You can re-order, hide or rename menus, add custom menus and more.

Spin up a real WordPress site in seconds.

Test plugins, build a demo, hand a client a link — then squash it and start again. No local setup, no Docker.