"The Response Is Not a Valid JSON Response" in WordPress (2026 Fix)
Disclosure: some links on this page are affiliate links. We may earn a commission at no extra cost to you. How we test and rate hosts.
"Updating failed. The response is not a valid JSON response" means Gutenberg's save request hit the REST API and got back garbage - an HTML error page, a redirect, a firewall block - instead of JSON. The API is being intercepted somewhere. Six checks, ordered by how often each is the culprit.
1. Re-Save Permalinks (The #1 Fix)
The REST API lives at /wp-json/ - which depends on rewrite rules. Go to Settings > Permalinks and click Save Changes without modifying anything. This regenerates .htaccess and fixes the large majority of cases. If it recurs after migration or a permalink change, this is almost always it.
2. Test the API Directly
Open yoursite.com/wp-json/ in a browser while logged in. You should see a wall of JSON. What you see instead names the layer:
- -403 page = security plugin or mod_security blocking it (fix 3)
- -404 page = rewrite rules broken (back to fix 1, or .htaccess permissions)
- -Redirect to http or www variant = URL mismatch (fix 4)
Tools > Site Health also reports REST API status under "The REST API encountered an error" - check it.
3. Check Security Plugins and WAF
Security plugins that "harden" WordPress often restrict REST API access - look for REST API toggles in Wordfence, iThemes, or whatever firewall you run, and allow the API for logged-in users at minimum. Host-level mod_security can also block POST bodies that look "suspicious" - if the error only fires on posts containing certain words or code snippets, that's a WAF signature, and support can whitelist it.
4. Fix the http/https and www Mismatch
If you recently enabled SSL or changed the domain, check Settings > General: WordPress Address and Site Address must be identical, both https, same www preference. When the editor runs on https but the API URL is http, the request gets redirected - and a redirect response isn't JSON. If wp-admin is inaccessible or the fields are greyed out, set them in wp-config.php:
define('WP_HOME', 'https://yourdomain.com');
define('WP_SITEURL', 'https://yourdomain.com');
Related: if the site loads pages over https but still requests http assets, see our mixed content fix.
5. Deactivate Plugins, Switch Theme
Any plugin can pollute the API response - a PHP notice printed before JSON corrupts it. Enable WP_DEBUG_LOG, reproduce the error, check wp-content/debug.log for "headers already sent" or notices naming a file. Then deactivate plugins one by one, starting with anything that touches headers, caching, or the editor. Still broken? Switch to a default theme - a theme echoing whitespace in functions.php can break JSON too.
6. Classic Editor as a Bridge (Not a Fix)
Need to publish while you debug? Install Classic Editor - it saves via the old path, bypassing the REST API. Treat it as a bridge only: the API also powers contact forms, WooCommerce blocks, and the mobile app. A broken API has blast radius beyond the editor.
REST API That Isn't Firewalled by Accident
Some hosts' default mod_security rules block legitimate WordPress API calls. Bluehost's config plays nice with core endpoints - and 24/7 support can whitelist edge cases instead of telling you to disable security. From $3.99/mo.
Get Reliable HostingRelated: 403 forbidden error - redirect loop fix - 500 internal server error - Gutenberg editor guide.
What are you building?
Tell us about your project so we can match the perfect hosting plan.
Hosting Cost Calculator
See exactly how much you'll spend on hosting over time. Compare Bluehost vs popular alternatives and discover your potential savings.
Used to calculate transaction fees (Shopify charges 2% on sales)
Frequently Asked Questions
What causes 'the response is not a valid JSON response'?
Gutenberg saves posts through the WordPress REST API. When that API call returns something that isn't JSON - an HTML error page, a redirect, a firewall block page - the editor shows this error. Causes: broken permalinks, security plugin/WAF blocking the API, http/https Site URL mismatch, or mod_security.
What's the fastest fix for the JSON response error?
Go to Settings > Permalinks and click Save Changes without changing anything - this regenerates .htaccess rewrite rules, which is the #1 cause. If it persists, check Site Health for REST API errors and temporarily disable security plugins.
Why did it start after enabling SSL?
Mixed content: your Site URL still says http while the site loads over https, so the API request gets redirected and returns HTML instead of JSON. Fix: Settings > General > set both URLs to https, or define WP_HOME/WP_SITEURL in wp-config.php.
Can a security plugin cause this error?
Yes - Wordfence, iThemes, and similar plugins have options to block or restrict the REST API for non-logged-in users. Check the plugin's REST API settings and whitelist wp-json endpoints. Host-level mod_security rules can also block API calls.
How do I test if the REST API works?
Visit yoursite.com/wp-json/ in a browser - you should see JSON data, not an error page or redirect. If it 403s or 404s, the API is being blocked at the server, firewall, or .htaccess level.
Does switching to the Classic Editor fix it?
It's a workaround, not a fix - Classic Editor doesn't use the REST API for saving, so it bypasses the problem. Useful to keep publishing while you fix the actual API issue, which also affects contact forms, WooCommerce, and mobile apps.
Ready to launch?
Get Bluehost from $3.99/month with a free domain, free SSL, and 30-day money-back guarantee.
Related Articles
Bluehost vs Competitors: The Technical Deep Dive
We ran 47 benchmarks over 90 days. Here's the raw data on why Bluehost dominates.
Fix ERR_TOO_MANY_REDIRECTS in WordPress (2026): The 6 Real Causes
ERR_TOO_MANY_REDIRECTS means an infinite redirect loop. Match your Site URLs, fix Cloudflare SSL mode, reset .htaccess, kill plugin conflicts - step-by-step with code.
WordPress 403 Forbidden Error: 7 Fixes That Actually Work (2026)
403 means the server understood you but refuses to serve the page. Fix file permissions (755/644), regenerate .htaccess, kill security plugin blocks - in the right order.
Fix 502 Bad Gateway in WordPress (2026): Diagnose First, Then Fix
502 means the gateway got a bad response from your server - usually PHP timeouts, CDN issues, or overload. A 9-step diagnostic workflow from browser checks to server logs.
Fatal Error: Maximum Execution Time Exceeded - 6 Fixes (2026)
max_execution_time kills slow updates at 30-60s. Fix the culprit plugin/theme first, then raise the limit via wp-config, .htaccess or php.ini - with exact code.
HTTP Error Uploading Images in WordPress: 9 Fixes Ranked (2026)
The vague 'HTTP error' on image upload usually means memory limits or Imagick. Fix order: rename the file, bump memory, force GD library, check permissions - with code.