The WordPress REST API in 2026.Every site is its own API.
To publish to a WordPress site from code, call the site's own REST API: POST /wp-json/wp/v2/posts with an application password, which a user creates in their profile or approves on wp-admin/authorize-application.php. It's built in since WordPress 5.6, free, and needs HTTPS. Free WordPress.com sites have no REST API at their own address and go through public-api.wordpress.com with OAuth2.
Northbeam Coffee
How we roast Morning Light
October 7, 2026
Eleven minutes from green bean to bag. We start low to dry the beans, push through first crack, then stop early to keep the honey and orange notes. That early stop is why it tastes lighter than our other coffees, and why it works as well in a latte as in a pour-over.
The WordPress API at a glanceWhat it takes before the first post.
- Price
- Free; WordPress is open source under the GPL
- Auth
- Application passwords since 5.6, sent as Basic auth over HTTPS. They act with the user's full role
- Getting one
- Users → Profile → Add Application Password, or the authorize-application.php flow for apps
- Posting
- POST /wp/v2/posts with title, content, status, date and featured_media; 201 with id and link
- Media
- POST /wp/v2/media: the raw file with Content-Disposition, or multipart; 7.1 adds a url to sideload
- Who can publish
- Authors, Editors and Administrators. Contributors write drafts and can't upload
- Rate limit
- None in WordPress itself; hosts, firewalls and security plugins set their own
- Scheduling
- status future, or a publish date at least 60 seconds ahead. WP-Cron runs it on a page load
Checked on October 7, 2026, from WordPress's developer documentation and terms.
To post to WordPress from your product, use Breakreach's API.We built it, so here's the case.
See the request- The blog post and its LinkedIn and X posts in one request, scheduled for the same morning
- Breakreach publishes at the time from its servers, so a quiet site's WP-Cron can't make it late
- Your users connect their own sites on a hosted page: type the address, approve in wp-admin
When to use WordPress's API directly. Breakreach publishes posts only, without categories, tags, excerpts or pages, and reads nothing back. For anything else on the site, call the REST API directly: it's free, documented and already on every WordPress 5.6+ site.
How to get access to the WordPress APIFrom a developer account to your first real post.
- 1Check it's availableGET /wp-json/ and look for authentication.application-passwords. It's missing when the site isn't on HTTPS, or when a plugin switches them off; Wordfence does by default.
- 2Send the person to approveOpen wp-admin/authorize-application.php with app_name, app_id (a UUID) and success_url, an https address or a custom scheme. WordPress asks the person to approve the connection.
- 3Read the credentials backOn approval, WordPress adds site_url, user_login and password to success_url. On refusal, the person lands on reject_url, or on success_url with success=false.
- 4Check the roleGET /wp/v2/users/me?context=edit with the new password: capabilities.publish_posts tells you whether this user can publish.
No app registration and no review: the site is the API. The person can revoke the password anytime in Users → Profile → Application Passwords.
How to post with the WordPress APIThe requests in the demo above, one by one.
- 1Upload the mediaPOST /wp/v2/media with the file as the raw body, plus Content-Type and Content-Disposition: attachment; filename=…, or as multipart with a field named file. It returns the attachment id and source_url.
- 2Create the postPOST /wp/v2/posts with title, content, status (publish, future, draft, pending or private), featured_media, categories and tags. It answers 201 with the post's id and link.
- 3Send blocks, not bare HTMLWrap content in block delimiters such as <!-- wp:paragraph -->. HTML without them opens in the editor as one Classic block.
Without pretty permalinks, /wp-json/ answers 404: use ?rest_route=/ instead. A post with status publish and a date at least 60 seconds ahead is saved as future, and WP-Cron publishes it on the next page load after that time.
Common WordPress API errorsWhat they mean and how to fix them.
| Error | What it means | Fix |
|---|---|---|
401 incorrect_password | The application password was revoked or mistyped. | Run the authorize flow again. |
401 rest_cannot_create | The request arrived without credentials: the host stripped the Authorization header. | Pass it through, with SetEnvIf on Apache or fastcgi_pass_header on Nginx. |
403 rest_cannot_publish | The user can't publish, a Contributor for example. | Use an Author or above, or send status draft. |
400 rest_cannot_create (media) | The user lacks upload_files. | Use an Author or above. |
400 rest_upload_image_type_not_supported | The server can't resize that image type, since 6.8. | Convert it to JPEG or PNG. |
501 on authorize-application.php | Application passwords are off: no HTTPS, a filter or a security plugin. | Turn on HTTPS, or allow them in the plugin. |
WordPress API limitsRate limits, text and media.
- UploadsThe server's upload_max_filesize and post_max_size. WebP needs 5.8 and AVIF 6.5, if the host supports them; since 6.8, images the server can't process are refused.
- RolesAuthors publish and upload their own posts. Contributors can't publish or upload. Creating categories takes an Editor; Authors can create tags.
- Rate limitsWordPress has none. Managed hosts, firewalls and security plugins may block bursts, so space bulk imports out.
- SchedulingScheduled posts go live through WP-Cron, which runs when someone loads a page. On a quiet site, a scheduled post can go out late.
Is the WordPress API free?
Yes. The REST API is part of WordPress, which is free software under the GPL, and WordPress.com's API is free too, within its responsible-use guidelines.
What it costs is the site's hosting and the care of a credential: an application password carries the user's whole role, with no narrower scope yet.
Through Breakreach, a WordPress site counts like any other connected account: $5 a month each up to 20, $3 up to 100, then $2.
Ways to post to WordPress from code
| What you set up | Price | Posts to WordPress | |
|---|---|---|---|
| Breakreach | An API key. Sites connect with an application password approved in wp-admin, or your users connect theirs on a hosted page | $5 a month per account, less from 21 | Yes, Sites with application passwords |
| WordPress's own API | An application password per site, or OAuth2 through WordPress.com | Free | Yes |
| Upload-Post | An API key | Free for 2 profiles and 10 uploads a month; Basic $24 a month for 5 profiles | Yes, On paid plans, self-hosted sites |
| Zernio | An API key | First 2 accounts free, then $6 per account up to 10, $3 up to 100, $1 after | Yes, Through a separate Blogs API |
| Ayrshare | An API key | From $149 a month for 1 profile, no free plan | No |
| Outstand | An API key | $19 a month for 3,000 posts, then per post | No |
What the WordPress API can't do
- Scope an application password: it acts with the user's whole role
- Reach a free WordPress.com site at its own address
- Report views: core has no stats; WordPress.com's stats API needs OAuth
- Publish exactly on time on a site nobody visits, with WP-Cron
- Let a Contributor publish or upload
Post to WordPress with Breakreach's APIOne request, scheduled, with retries.
What it posts on WordPress
- Blog postsThe first line is the title. Paragraphs, ## headings and - lists become editor blocks, with bold and links kept.
- Featured image and mediaThe first photo goes to the Media Library as the featured image; up to 9 more photos and one video follow the text.
- SchedulingscheduledAt in your workspace's timezone, the next free slot, or publishNow. Breakreach publishes at the time, so WP-Cron isn't involved.
- The same post elsewhereOne request can publish the article and share it on LinkedIn, X and the rest.
Not yet
- Categories, tags and excerpts
- Pages and custom post types
- Free WordPress.com sites
- Stats
The full reference, webhooks and the price per connected account are on the developers page, and the OpenAPI spec is at api.breakreach.com/v1/openapi.json.
Questions, answered.
Short answers about the WordPress API.
Yes. It's built into WordPress, which is free software. You call your own site's API at /wp-json/, so the only limits are your host's.
From outside the site, with an application password sent as Basic auth over HTTPS. The user creates one in Users → Profile, or approves your app on wp-admin/authorize-application.php. WordPress.com sites on the free plan use OAuth2 through public-api.wordpress.com.
POST /wp-json/wp/v2/posts with title, content and status publish, using an Author's or an Editor's application password. Set featured_media to the id of an image you uploaded to /wp/v2/media first.
Send status future with a date, or status publish with a date at least 60 seconds ahead, which WordPress turns into future. WP-Cron publishes it on the first page load after that time.
POST /wp/v2/media with the file as the body, a Content-Type and Content-Disposition: attachment; filename="photo.jpg", or as multipart with a file field. Since 7.1, a url parameter can sideload an external image instead.
If the user can publish, the Authorization header probably never reached WordPress, so the request counted as anonymous and got rest_cannot_create with a 401. Hosts running PHP as CGI often strip it; WordPress's REST FAQ gives the SetEnvIf line for Apache.
$5 a month per connected account up to 20, $3 up to 100, then $2. Each WordPress site is one account. You pay per connected account, never per post or per request.
Keep reading
Put your socials on autopilot.Live in two minutes.
Plans from $29 a month. Cancel anytime.