WordPress REST API: Why Block Only Logged-Out Requests Instead of Disabling It

Affiliate disclosure v3.1
Affiliate disclosure v3.2 (mobile)

The WordPress REST API exposes your site's usernames through the wp-json address, even to visitors who are not logged in. Disabling it completely can make the block editor fail to save, so this guide shows how to block only logged-out requests and confirm it with a 401 response.

1️⃣ What Is the WordPress REST API: The wp-json Address and What It Does

The WordPress REST API is a built-in WordPress feature that exchanges site data such as posts, pages, and users in JSON format, and it responds under /wp-json/ after the site address.

Under /wp-json/, addresses are split by data type, such as [wp/v2/posts], [wp/v2/pages], and [wp/v2/users], and each of these addresses is called an endpoint. The block editor also sends requests to these addresses when it saves a post.

https://example.com/wp-json/
https://example.com/wp-json/wp/v2/posts
https://example.com/wp-json/wp/v2/pages
https://example.com/wp-json/wp/v2/users

2️⃣ Usernames Exposed Through wp-json

  • ↪️ Why block it: users 401 · also visible on author pages

The [wp/v2/users] endpoint returns a display name and a slug for each user who has published posts, and by default the slug contains the login username as is. On the test site, https://testpilotweb.com/, the administrator account's slug was also the same as its login username.

Once the login username is exposed, an attacker only needs to find the password to log in, and the test site's WordPress login page recorded 2,570 brute-force attempts on October 7, 2026 alone.

Even after this address is blocked, the same username remains in the author page address (/author/username/).

3️⃣ What Breaks When You Disable It Completely

  • ↪️ Block editor saving · MCP shows 0 tools

Disabling the WP REST API entirely first breaks saving in the block editor, which is why Perfmatters, one of the WordPress optimization plugins, splits the scope into two levels: [Disable for Non-Admins] and [Disable When Logged Out]. On sites with author or contributor accounts, [Disable for Non-Admins] also blocks those accounts from saving posts.

Even on a site that blocked only logged-out requests, connecting an MCP connector in claude.ai showed 0 tools after authentication finished. The server log recorded every MCP request as 401, and the cause was Perfmatters blocking the request before MCP checked the token.

[Disable REST API] valueusers address for logged-out visitorsSaving by non-admin accountsBest for
Default (Enabled)Usernames exposedSaves—
Disable for Non-Admins401Save failsSites without author or contributor accounts
Disable When Logged Out401SavesSites with author accounts; add exception paths for token connections such as MCP

4️⃣ Blocking Only Logged-Out Requests (Perfmatters)

  • ↪️ Where to set it · checking the 401 response

In the WordPress admin, go to [Settings] → [Perfmatters] → [General], change [Disable REST API] under [Core] to [Disable When Logged Out], and click [Save Changes].

WordPress Settings → Perfmatters → General(WordPress REST API)
Perfmatters Disable REST API: Disable When Logged Out

Perfmatters supported languages: English (default), Korean, German, French, Italian, Dutch, Portuguese (Brazil), Russian, Ukrainian, Turkish, Bulgarian, Hungarian, Indonesian, Persian, Chinese (Simplified)

Perfmatters settings simulator: General → Core
Perfmatters settings simulator · Perfmatters Review and Guide

When you open /wp-json/wp/v2/users in an incognito window without logging in, it returns a 401 response with the message [Sorry, you do not have permission to make REST API requests.], while the block editor keeps saving posts when you are logged in.

🔌 Same request, two responses GET /wp-json/wp/v2/users
Unblocked site
200
Visitors who are not logged in can see usernames.
[
  {
    "id": 1,
    "name": "User A",
    "slug": "user_a",
    "link": "https://example.com/author/user_a/"
  }
]
[Disable When Logged Out] site
401
Requests without login get a 401 response with a message.
{
  "code": "rest_authentication_error",
  "message": "Sorry, you do not have permission to make REST API requests.",
  "data": { "status": 401 }
}
slug By default, the slug contains the login username as is.
The left side shows only four fields from the response (id, name, slug, link), and the name is an example (user_a).


5️⃣ Adding Exceptions to Blocked Paths

  • ↪️ MCP path exception · difference from removing REST API links

When you need to open only a specific path while blocking, add that path to Perfmatters' [perfmatters_rest_api_exceptions] filter. The claude.ai MCP connector's 0-tools problem was solved by creating a PHP snippet in the Perfmatters [Code] menu and making only the MCP path an exception.

add_filter('perfmatters_rest_api_exceptions', function($exceptions) {
    $exceptions[] = '/mcp/mcp-oauth-server';
    return $exceptions;
});

Even after adding the exception, requests without a token are blocked by MCP itself with a 401 response and the message [MCP authentication required.], while /wp-json/wp/v2/users keeps returning Perfmatters' 401 response.

🚦 The order a request goes through
Before the exception · MCP request
A request sent by the claude.ai MCP connector after authentication, with [Disable When Logged Out] on.
Perfmatters
Blocked with 401
→↓
MCP token check
Never reached
→↓
Result
0 tools
After the exception · MCP request
/mcp/mcp-oauth-server : path added to the Perfmatters exceptions.
Perfmatters
Passes as an exception path
→↓
MCP token check
Checked by MCP itself
→↓
Result
401 if there is no token
[MCP authentication required.]
After the exception · /wp-json/wp/v2/users
Paths not added to the exceptions stay blocked.
Perfmatters
Blocked with 401
→↓
Result
Usernames stay hidden
⚠️ Perfmatters blocks the request before MCP checks the token.

[Remove REST API Links] in the same [Core] section only removes the api.w.org link from the page head and response headers; the WP REST API itself keeps responding.

🔢 FAQ & Recommended Content

xmlrpc.php is a different address from the REST API, so it keeps responding even when the REST API is blocked. The test site logged 734 POST requests to xmlrpc.php on October 8, 2026 alone, and Perfmatters can block it with [Disable XML-RPC] in the same [Core] section.

WP Rocket keeps /wp-json/ addresses on its cache exclusion list, so REST API responses change as soon as you save. Settings that change the page HTML, such as [Remove REST API Links], take effect after the cache is cleared.

No. The WordPress block editor sends requests to the REST API when it saves posts, and MCP connectors that link AI tools such as claude.ai also use paths under /wp-json/.

ℹ️ Affiliate Disclosure
This site's content contains affiliate links. When a visitor buys a product or service through one of them, the site receives a commission from the seller. The amount the buyer pays(it goes down during event discounts ↓)does not go up. Posted prices, discounts, and stock reflect the time of writing and may differ, so confirm with the seller before buying. Products are chosen and reviewed by our own standards, and commissions do not affect the order or content of reviews.

Leave a Reply

Your email address will not be published. Required fields are marked *

Prove your humanity: 2   +   4   =