{"id":1365,"date":"2026-07-13T15:58:09","date_gmt":"2026-07-13T15:58:09","guid":{"rendered":"https:\/\/www.jolt.co.uk\/help\/third-party-wordpress-api-integration-returns-403-on-a-custom-rest-endpoint\/"},"modified":"2026-07-13T15:58:09","modified_gmt":"2026-07-13T15:58:09","slug":"third-party-wordpress-api-integration-returns-403-on-a-custom-rest-endpoint","status":"publish","type":"post","link":"https:\/\/www.jolt.co.uk\/help\/third-party-wordpress-api-integration-returns-403-on-a-custom-rest-endpoint\/","title":{"rendered":"Third-party WordPress API integration returns 403 on a custom REST endpoint"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Description<\/h2>\n\n\n\n<p>A third-party integration may fail to connect to a WordPress REST API endpoint and return a 403 Forbidden response, even though the endpoint is available in a browser. This can happen when automated requests are blocked by server-side bot protection rather than by WordPress itself.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Symptoms<\/h2>\n\n\n\n<p>The affected service reports that it cannot access a WordPress REST API endpoint under a custom namespace, such as \/wp-json\/example-plugin\/v1.<\/p>\n\n\n\n<p>Typical behaviour includes:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The third-party platform reports a 403 Forbidden error when calling the API endpoint<\/li>\n\n\n\n<li>The endpoint responds normally when tested manually in a web browser<\/li>\n\n\n\n<li>The issue affects automated server-to-server requests rather than general site access<\/li>\n<\/ul>\n\n\n\n<p>[Screenshot: example 403 error shown by the third-party integration]<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Solution<\/h2>\n\n\n\n<p>The 403 response was caused by the platform&#8217;s bot protection blocking the third-party request user agent. In the confirmed case, the blocked requests used the Axios user agent.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Check the web server access logs for requests to the affected REST API endpoint.<\/li>\n\n\n\n<li>Identify requests returning 403 and confirm the associated user agent.<\/li>\n\n\n\n<li>If the requests are legitimate, add that user agent to the allowlist in the server&#8217;s bot protection or security layer.<\/li>\n\n\n\n<li>Test the integration again to confirm the endpoint now returns a valid response to the third-party service.<\/li>\n<\/ol>\n\n\n\n<p>For Example, allowing the Axios user agent through the bad bot blocker on Jolt Control Panel resolve issue with 403.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"778\" height=\"280\" src=\"https:\/\/kb.jolt.co.uk\/wp-content\/uploads\/sites\/5\/2026\/07\/image.png\" alt=\"\" class=\"wp-image-1366\" style=\"width:636px;height:auto\" srcset=\"https:\/\/kb.jolt.co.uk\/wp-content\/uploads\/sites\/5\/2026\/07\/image.png 778w, https:\/\/kb.jolt.co.uk\/wp-content\/uploads\/sites\/5\/2026\/07\/image-300x108.png 300w, https:\/\/kb.jolt.co.uk\/wp-content\/uploads\/sites\/5\/2026\/07\/image-768x276.png 768w, https:\/\/kb.jolt.co.uk\/wp-content\/uploads\/sites\/5\/2026\/07\/image-770x277.png 770w\" sizes=\"auto, (max-width: 778px) 100vw, 778px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Description A third-party integration may fail to connect to a WordPress REST API endpoint and return a 403 Forbidden response, even though the endpoint is available in a browser. This can happen when automated requests are blocked by server-side bot protection rather than by WordPress itself. Symptoms The affected service&hellip;<\/p>\n","protected":false},"author":8,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7,18],"tags":[],"class_list":["post-1365","post","type-post","status-publish","format-standard","hentry","category-our-control-panel","category-wordpress"],"_links":{"self":[{"href":"https:\/\/www.jolt.co.uk\/help\/wp-json\/wp\/v2\/posts\/1365","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.jolt.co.uk\/help\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.jolt.co.uk\/help\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.jolt.co.uk\/help\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.jolt.co.uk\/help\/wp-json\/wp\/v2\/comments?post=1365"}],"version-history":[{"count":1,"href":"https:\/\/www.jolt.co.uk\/help\/wp-json\/wp\/v2\/posts\/1365\/revisions"}],"predecessor-version":[{"id":1367,"href":"https:\/\/www.jolt.co.uk\/help\/wp-json\/wp\/v2\/posts\/1365\/revisions\/1367"}],"wp:attachment":[{"href":"https:\/\/www.jolt.co.uk\/help\/wp-json\/wp\/v2\/media?parent=1365"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.jolt.co.uk\/help\/wp-json\/wp\/v2\/categories?post=1365"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.jolt.co.uk\/help\/wp-json\/wp\/v2\/tags?post=1365"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}