

<strong>General Settings:</strong> The main configuration screen with the Master Switch and Redirect URL options.
Running a Headless WordPress site often involves exposing the REST API. Headless REST API Security provides tools for administrators to control which endpoints are accessible to the public or external applications.
This plugin restricts public access to REST API endpoints by default and offers a settings interface to allow-list only the specific routes required by a frontend application (such as Next.js, Gatsby, or mobile apps).
/wp/v2/posts) can be enabled while others remain restricted.X-API-KEY header for server-to-server or frontend requests.