REST API reference

The performance-optimisation/v1 namespace, authentication, route groups, and response conventions.

2 min readPart of Performance Optimisation

The administrative API is registered under performance-optimisation/v1. It is an implementation surface for the dashboard, integrations, and trusted operators; it is not a replacement for WordPress capability checks.

Authentication

  • Administrative routes require manage_options and a valid X-WP-Nonce (or the standard WordPress REST nonce equivalent).
  • Requests are sent to /wp-json/performance-optimisation/v1/<route>.
  • rum_collect is intentionally public for anonymous field Web Vitals. It uses a daily per-path token, rate limits, bounded payloads, and local retention rather than an administrator nonce.

Never print or persist authorization headers, cookies, API keys, or raw settings payloads in a client log.

Route groups

GroupRepresentative routesPurpose
Cache and settingsclear_cache, update_settings, import_settings, settings_snapshot, restore_settingsClear or update bounded configuration and undo a prior save.
Imagesoptimise_image, delete_optimised_image, image_job_status, lcp_preload_candidateQueue conversion, inspect jobs, and read a safe LCP candidate.
Database and object cachedatabase_cleanup, database_cleanup_counts, object_cache, autoloaded_options, autoload_remediate, expired_transients_exportRun explicit cleanup, inspect Redis, and use bounded dry-run/remediation contracts.
CSS and derived cachesused_css_regenerate, used_css_status, regenerate_ccss, ccss_status, purge_used_css_cache, purge_derived_cachesRegenerate or promote CSS artifacts with existing health/rollback checks.
Monitoringperformance_scan, pagespeed_scan, pagespeed_results, web_vitals_trends, suggestions, rum_collect, rum_dataRead telemetry, queue explicit scans, and collect bounded field samples.
System and serversystem_info, server_rules, recent_activities, upgrade_purge_statusRead redacted diagnostics and generated server guidance.
Safety and preloadingsafe_mode_detect, safe_mode, preload_status, preload_resume, woo_cache_self_test, dismiss_welcomeRun read-only checks, resume bounded work, and manage onboarding state.
Sandbox and adaptive suggestionssandbox_preview, sandbox_save, sandbox_promote, sandbox_discard, ai_model, ai_learn, ai_suggestionsPreview/promote staged settings and read the opt-in adaptive surface.

Response conventions

Administrative handlers use the plugin response envelope with a success flag, message, and data payload where appropriate. Destructive operations require an explicit action/mode and preserve dry-run or health information. The exact route schema and callbacks are generated in the Rest source reference.

Safe client checklist

  1. Authenticate with the current WordPress REST nonce.
  2. Send only the route\’s documented parameters.
  3. Show the returned message and inspect the data before showing success.
  4. Abort stale requests when a component unmounts or a newer request supersedes them.
  5. Never surface a secret-shaped value in an error message or console log.