WooCommerce REST API基础认证(Basic Auth)无法正常使用求助
Hey there, let's break down why your Basic Auth isn't working with the WooCommerce REST API—this is a super common snag, but usually easy to fix once you check a few key details.
First, let's clarify a critical point: WooCommerce's REST API doesn't use regular WordPress user credentials for Basic Auth. Instead, you need to use the Consumer Key and Consumer Secret generated from each subdomain site's WooCommerce > Settings > Advanced > REST API section. If you've been using your WP username/password, that's almost certainly the root of the problem right there.
Assuming you have the correct keys, here are the most likely fixes to walk through:
1. Verify Your Basic Auth Header Format
When sending requests, the Basic Auth header needs to be a base64-encoded string of {consumer_key}:{consumer_secret}. It's easy to mess up this encoding or mix up the key/secret order in PHP. Here's a correct example of setting up a cURL request:
$consumer_key = 'your_subdomain_consumer_key'; $consumer_secret = 'your_subdomain_consumer_secret'; $api_endpoint = 'https://subdomain.example.com/wp-json/wc/v3/products'; $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $api_endpoint); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_HTTPHEADER, array( 'Authorization: Basic ' . base64_encode($consumer_key . ':' . $consumer_secret) )); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, true); // Keep this enabled for secure HTTPS requests $response = curl_exec($ch); curl_close($ch); // Debug the response to see what's happening var_dump($response);
Double-check that you're not swapping the key and secret, and that the base64 encoding is applied properly.
2. Check for Server/Security Plugin Blocks
Many hosting providers or security plugins (like Wordfence, iThemes Security) block Basic Auth requests by default to prevent brute-force attacks.
- Hosting Check: Reach out to your host or check their docs—some require you to enable Basic Auth via
.htaccessor a control panel setting. For Apache, you might need to add:
(Note: Don't add this without confirming with your host first—misconfiguring<IfModule mod_auth_basic.c> AuthType Basic AuthName "REST API Access" Require valid-user </IfModule>.htaccesscan break your site.) - Security Plugin Check: Temporarily disable any security plugins on the subdomain sites and test the API call again. If it works, you'll need to whitelist the REST API endpoints or your main site's IP address in the plugin settings.
3. Confirm REST API Endpoint and Permissions
- Make sure you're using the correct API endpoint: For WooCommerce 3.x+, the valid path is
/wp-json/wc/v3/products(not the outdated/wc-api/v3/path). - Double-check the API key's permissions: When you created the key, did you set it to Read? While "Read/Write" shouldn't break read access, it's worth verifying. Also, ensure the associated WordPress user has the
readcapability (which all default user roles like Subscriber or higher have).
4. Debug HTTPS/CURL Issues
Since all sites use HTTPS, confirm your PHP environment trusts the subdomain's SSL certificate. If you're getting SSL errors, you can temporarily set CURLOPT_SSL_VERIFYPEER to false for testing (but never leave this in production—it's insecure). If that fixes the issue, you'll need to update your server's CA certificates or specify a valid CA bundle path in your cURL settings.
5. Validate with Postman First
Even though your Postman details are incomplete, let's confirm that setup is correct:
- Set the request method to
GET - Enter the full endpoint URL (e.g.,
https://subdomain.example.com/wp-json/wc/v3/products) - Go to the Authorization tab, select Basic Auth, and input your Consumer Key as the username and Consumer Secret as the password.
- Send the request—if this fails, the issue is with the subdomain site's setup, not your PHP code. If it works, the problem lies in how you're implementing auth in your script.
Start with these checks—9 times out of 10, it's either using the wrong credentials, a security plugin blocking the request, or an incorrectly formatted auth header.
内容的提问来源于stack exchange,提问作者jsilva

