Improve your WordPress SEO: Write better content and have a fully optimized WordPress site using the Yoast SEO…
About Disable REST API
This plugin allows you to control access to the WordPress REST API. It can make the entire API inaccessible to general site visitors, but you can also whitelist specific endpoints or branches of endpoints and set different rules for different user roles.Screenshots



Frequently asked questions
What does this plugin do?
This plugin controls access to the WordPress REST API by making it inaccessible to general site visitors.
Can I grant access to specific endpoints?
Yes, you can whitelist individual endpoints or entire branches of endpoints in the REST API settings.
Can I set different access rules for different user roles?
Yes, you can set different access rules for unauthenticated users, WooCommerce customers, Subscribers, Editors, and Admins.
Do all user roles have full access to the REST API by default?
Yes, all defined user roles will have full access to the REST API until you choose to manage those settings.
What happens if a user is not allowed to access an endpoint?
For most versions of WordPress, this plugin will return an authentication error if a user is not allowed to access an endpoint.
Changelog
1.8
- Tested up to WP v6.3
- Added
dra_error_messagefilter so devs can customize the access error message - Fixed bug that caused fatal errors if activating plugin on installations running the LearnPress plugin
- Changed minimum requirements to PHP 5.6 (up from 5.3) and WordPress 4.9 (up from 4.4). Adding docblock comments to support minimums.
1.7
- Tested up to WP v5.8
- Replace use of filemtime() with plugin version number for static file enqueues. Props @tangrufus for bringing this up!
- Fixed logic bug for role-based default_allow rules. Props @msp1974 for the report!
- Few small code-style updates
1.6
- Tested up to WP v5.6
- Added support for managing endpoint access on a per-user-role basis
- Soooooooo many small changes behind the scenes to support the above
1.5.1
- Tested up to WP v5.5
1.5
- Tested up to WP v5.3
- Added enforcement for WordPress and PHP minimum version requirements
- Fixed minor bug to prevent unintended empty routes
- Minor text updates and adding textdomain to translation functions that didn’t have them
1.4.3
- Added
load_plugin_textdomain()for i18n
1.4.2
- Fixed issue causing unintentional unlocking of endpoints when another WP_Error existed before this plugin did its job
1.4.1
- Fixed echo of text URL to primary Plugins page in WP Dashboard
1.4
- Tested for WP v4.8
- Tested for PHP 5.3+
- Added settings screen
- Site Admins may now whitelist routes that they wish to allow unauthenticated access to
- Added
dra_allow_rest_apifilter to the is_logged_in() check, so developers can get more granular with permissions - Props to @tangrufus for all of the help that went into this release
1.3
- Tested for WP v4.7
- Adding new functionality to raise authentication errors in 4.7+ for non-logged-in users
1.2
- Tested for WP v4.5
- Removal of actions which publish REST info to the head and header
1.1
- Updated to support the new filters created in the 2.0 beta API
1.0
- Initial Release
