Technical

"The Response Is Not a Valid JSON Response" in WordPress (2026 Fix)

By Daniel Reyes•October 8, 2026•3 min read

Disclosure: some links on this page are affiliate links. We may earn a commission at no extra cost to you. How we test and rate hosts.

Our top pick for most WordPress sites
Bluehost: free domain, free SSL, 24/7 support, 30-day money-back guarantee.
Check Bluehost Deal →

"Updating failed. The response is not a valid JSON response" means Gutenberg's save request hit the REST API and got back garbage - an HTML error page, a redirect, a firewall block - instead of JSON. The API is being intercepted somewhere. Six checks, ordered by how often each is the culprit.

1. Re-Save Permalinks (The #1 Fix)

The REST API lives at /wp-json/ - which depends on rewrite rules. Go to Settings > Permalinks and click Save Changes without modifying anything. This regenerates .htaccess and fixes the large majority of cases. If it recurs after migration or a permalink change, this is almost always it.

2. Test the API Directly

Open yoursite.com/wp-json/ in a browser while logged in. You should see a wall of JSON. What you see instead names the layer:

  • -403 page = security plugin or mod_security blocking it (fix 3)
  • -404 page = rewrite rules broken (back to fix 1, or .htaccess permissions)
  • -Redirect to http or www variant = URL mismatch (fix 4)

Tools > Site Health also reports REST API status under "The REST API encountered an error" - check it.

3. Check Security Plugins and WAF

Security plugins that "harden" WordPress often restrict REST API access - look for REST API toggles in Wordfence, iThemes, or whatever firewall you run, and allow the API for logged-in users at minimum. Host-level mod_security can also block POST bodies that look "suspicious" - if the error only fires on posts containing certain words or code snippets, that's a WAF signature, and support can whitelist it.

4. Fix the http/https and www Mismatch

If you recently enabled SSL or changed the domain, check Settings > General: WordPress Address and Site Address must be identical, both https, same www preference. When the editor runs on https but the API URL is http, the request gets redirected - and a redirect response isn't JSON. If wp-admin is inaccessible or the fields are greyed out, set them in wp-config.php:

define('WP_HOME', 'https://yourdomain.com');
define('WP_SITEURL', 'https://yourdomain.com');

Related: if the site loads pages over https but still requests http assets, see our mixed content fix.

5. Deactivate Plugins, Switch Theme

Any plugin can pollute the API response - a PHP notice printed before JSON corrupts it. Enable WP_DEBUG_LOG, reproduce the error, check wp-content/debug.log for "headers already sent" or notices naming a file. Then deactivate plugins one by one, starting with anything that touches headers, caching, or the editor. Still broken? Switch to a default theme - a theme echoing whitespace in functions.php can break JSON too.

6. Classic Editor as a Bridge (Not a Fix)

Need to publish while you debug? Install Classic Editor - it saves via the old path, bypassing the REST API. Treat it as a bridge only: the API also powers contact forms, WooCommerce blocks, and the mobile app. A broken API has blast radius beyond the editor.

REST API That Isn't Firewalled by Accident

Some hosts' default mod_security rules block legitimate WordPress API calls. Bluehost's config plays nice with core endpoints - and 24/7 support can whitelist edge cases instead of telling you to disable security. From $3.99/mo.

Get Reliable Hosting

Related: 403 forbidden error - redirect loop fix - 500 internal server error - Gutenberg editor guide.

Find Your Perfect Hosting Plan

What are you building?

Tell us about your project so we can match the perfect hosting plan.

Question 1 of 425% complete
Interactive Tool

Hosting Cost Calculator

See exactly how much you'll spend on hosting over time. Compare Bluehost vs popular alternatives and discover your potential savings.

Used to calculate transaction fees (Shopify charges 2% on sales)

Shopify Basic (3yr)
$1,044
Bluehost (3yr)
$444
You Save
$600
58% less than Shopify Basic

Frequently Asked Questions

What causes 'the response is not a valid JSON response'?

Gutenberg saves posts through the WordPress REST API. When that API call returns something that isn't JSON - an HTML error page, a redirect, a firewall block page - the editor shows this error. Causes: broken permalinks, security plugin/WAF blocking the API, http/https Site URL mismatch, or mod_security.

What's the fastest fix for the JSON response error?

Go to Settings > Permalinks and click Save Changes without changing anything - this regenerates .htaccess rewrite rules, which is the #1 cause. If it persists, check Site Health for REST API errors and temporarily disable security plugins.

Why did it start after enabling SSL?

Mixed content: your Site URL still says http while the site loads over https, so the API request gets redirected and returns HTML instead of JSON. Fix: Settings > General > set both URLs to https, or define WP_HOME/WP_SITEURL in wp-config.php.

Can a security plugin cause this error?

Yes - Wordfence, iThemes, and similar plugins have options to block or restrict the REST API for non-logged-in users. Check the plugin's REST API settings and whitelist wp-json endpoints. Host-level mod_security rules can also block API calls.

How do I test if the REST API works?

Visit yoursite.com/wp-json/ in a browser - you should see JSON data, not an error page or redirect. If it 403s or 404s, the API is being blocked at the server, firewall, or .htaccess level.

Does switching to the Classic Editor fix it?

It's a workaround, not a fix - Classic Editor doesn't use the REST API for saving, so it bypasses the problem. Useful to keep publishing while you fix the actual API issue, which also affects contact forms, WooCommerce, and mobile apps.

Ready to launch?

Get Bluehost from $3.99/month with a free domain, free SSL, and 30-day money-back guarantee.

Start for $3.99 →

Related Articles