如何获取WordPress站点全量端点URL含请求方法与参数?
Hey there, let's work through how to get all the endpoints you need for your WordPress site—both the auth-related ones like login/logout/password reset, and the full set of API details your Android dev team is requesting, since hitting /wp-json only gives you a partial list.
1. Core Authentication Endpoints (Login, Logout, Password Reset)
WordPress has some built-in auth paths, plus options to extend for REST-friendly access:
- Login: By default, WordPress REST API doesn't have a native login endpoint (it relies on cookies or external auth). For a REST-compatible login, install the JWT Authentication for WP REST API plugin—this adds the endpoint
wp-json/jwt-auth/v1/token(POST request, requires parametersusernameandpassword). If you're using the traditional login form, the submission endpoint iswp-login.php(POST request with form data likelog,pwd). - Logout: For JWT setups, you can invalidate tokens via
wp-json/jwt-auth/v1/token/validate(POST with valid token). The traditional logout path iswp-login.php?action=logout(GET/POST, requires valid user cookies). Some auth plugins also add dedicated REST logout endpoints likewp-json/auth/v1/logout(POST with auth token). - Password Reset: The official REST API endpoint for this is
wp-json/wp/v2/users/lostpassword(POST request, accepts eitherusernameoremailparameter). The traditional form submission path iswp-login.php?action=lostpassword(POST withuser_loginparameter).
2. Get the Full List of REST API Endpoints (Methods + Parameters)
If /wp-json only shows partial endpoints, it's likely because some require user permissions, or are registered by plugins/themes under restricted namespaces. Try these methods:
- Use a REST API Console Plugin: Install and activate the REST API Console plugin in your WordPress admin. It gives you a visual dashboard to browse every registered endpoint, including HTTP methods, required parameters, and permission requirements—perfect for your dev team to reference.
- Generate a Full Endpoint List via Code: Add this snippet to your theme's
functions.phpfile temporarily to output all registered endpoints:
Visitadd_action('rest_api_init', function() { $server = rest_get_server(); $all_endpoints = $server->get_routes(); echo '<pre>'; print_r($all_endpoints); echo '</pre>'; exit; });/wp-jsonafter adding this, and you'll see a complete breakdown of every endpoint, including parameters and supported methods. Don't forget to remove this code after use to avoid exposing sensitive data. - Check Plugin/Theme-Specific Endpoints: Plugins like WooCommerce, Members, or custom themes often register their own REST endpoints (e.g., WooCommerce uses the
wp-json/wc/v3/namespace). Make sure all relevant plugins are enabled, then use the above methods to capture these additional endpoints.
3. Tips for Your Android Developer
- Ensure your WordPress site has REST API enabled (default for WordPress 4.7+).
- For mobile-friendly authentication, stick with the JWT plugin approach—it avoids cookie-based restrictions that can cause issues on mobile.
- Test endpoints first with tools like Postman to validate request/response formats before integrating into the Android app.
- All parameter details (required fields, data types) will be visible in the full endpoint list generated via the methods above.
内容的提问来源于stack exchange,提问作者DJ Reddy
相关产品推荐
相关产品推荐

