What the invalid JSON response error means
The WordPress block editor communicates with the site through the WordPress REST API. A successful request to an API endpoint returns structured JSON data that the editor can read.
The error appears when that request fails or returns unexpected content. For example, the editor may receive an HTML error page, a login page, a firewall response, a PHP warning or a 404 instead of JSON.
This is why the same message can have several causes. It is better to find the HTTP status and response from the failing REST request than to assume that JSON itself is broken. WordPress Site Health can also flag REST API problems that affect editing or publishing.
Common causes of a WordPress invalid JSON response
Permalink and rewrite problems are common because REST API routes such as /wp-json/ must reach WordPress correctly. An incorrect WordPress Address or Site Address, especially after an HTTP-to-HTTPS or domain migration, can also send API requests to the wrong location.
Security plugins, web application firewalls and server security rules may return a 403 response for REST requests. Plugins or themes can also output PHP warnings or other text before the expected JSON response, making the result impossible for the editor to parse.
Less obvious cases include expired authentication, caching rules applied to REST endpoints, server errors and a proxy returning its own HTML error document. Looking at the browser Network panel normally distinguishes these situations quickly.
How to fix the invalid JSON response safely
Take a full backup of the website files and database before editing files, configuration or database values.
- Test the REST API. Open your site's /wp-json/ address. A normal WordPress REST index returns JSON. An HTML login page, 403, 404 or server error gives you a more useful direction for diagnosis.
- Check Site Health. In Tools, then Site Health, review critical issues and REST API warnings.
- Refresh permalinks. Go to Settings, then Permalinks and save the existing structure without changing it. This refreshes WordPress rewrite rules.
- Confirm the site URLs. Check that WordPress Address and Site Address use the intended hostname and HTTPS configuration.
- Inspect the failed request. In browser developer tools, open Network, reproduce the error and examine the request to /wp-json/. A 403 points towards access controls, a 404 towards routing, and a 500 towards server-side code or configuration.
- Test recent plugin or theme changes on staging where possible. Security, caching and optimisation plugins are particularly relevant if they alter API requests, authentication or output.
- Use logging for PHP failures. WordPress documents WP_DEBUG and WP_DEBUG_LOG for troubleshooting. Do not display debug output publicly on a production site, and remove or disable temporary logging after diagnosis.
For wider performance or configuration problems, see WordPress support.
When the REST API problem needs technical help
Stop if the failing response comes from a hosting firewall, reverse proxy or server configuration you cannot safely change. You should also avoid disabling security controls permanently simply to make the editor save.
A developer can trace the request status, response body, WordPress logs and server logs to identify whether the fault sits in rewriting, authentication, PHP code or infrastructure. That is more reliable than changing several unrelated settings at once.
Web Support Services offers an Emergency Fix for £249 per incident, with a response within 2 working hours. Care plans start from £59 a month for ongoing maintenance intended to reduce repeat faults.