Documentation

WordPress

Protect WordPress REST APIs

Add x402 protection to exact WordPress REST API routes registered by WordPress, a plugin, or a theme.
Last reviewed August 9, 2026

What the adapter protects

The plugin protects an existing WordPress REST route. It does not create the business endpoint for you. Register the endpoint in WordPress, a theme, or another plugin before adding its Access402 rule.

Enter the route

Choose REST API route and enter the route beginning with /wp-json/, for example:

/wp-json/acme/v1/premium-insight

Set the price, access policy, description, and status. Test the exact endpoint in Sandbox before enabling Live.

Matching and normalization

Access402 normalizes repeated slashes and matches the canonical route. A request such as //wp-json/acme/v1/premium-insight cannot bypass a rule created for /wp-json/acme/v1/premium-insight.

Query strings do not create a new route identity unless the endpoint's own application behavior treats them as different input.

Discovery metadata

Eligible REST rules can include a method, description, request example, input schema, and output schema for CDP Bazaar discovery. Validate examples before publishing; discovery does not replace your public API documentation.