The administrative API is registered under performance-optimisation/v1. It is an implementation surface for the dashboard, integrations, and trusted operators; it is not a replacement for WordPress capability checks.
Authentication
- Administrative routes require
manage_optionsand a validX-WP-Nonce(or the standard WordPress REST nonce equivalent). - Requests are sent to
/wp-json/performance-optimisation/v1/<route>. rum_collectis intentionally public for anonymous field Web Vitals. It uses a daily per-path token, rate limits, bounded payloads, and local retention rather than an administrator nonce.
Never print or persist authorization headers, cookies, API keys, or raw settings payloads in a client log.
Route groups
| Group | Representative routes | Purpose |
|---|---|---|
| Cache and settings | clear_cache, update_settings, import_settings, settings_snapshot, restore_settings | Clear or update bounded configuration and undo a prior save. |
| Images | optimise_image, delete_optimised_image, image_job_status, lcp_preload_candidate | Queue conversion, inspect jobs, and read a safe LCP candidate. |
| Database and object cache | database_cleanup, database_cleanup_counts, object_cache, autoloaded_options, autoload_remediate, expired_transients_export | Run explicit cleanup, inspect Redis, and use bounded dry-run/remediation contracts. |
| CSS and derived caches | used_css_regenerate, used_css_status, regenerate_ccss, ccss_status, purge_used_css_cache, purge_derived_caches | Regenerate or promote CSS artifacts with existing health/rollback checks. |
| Monitoring | performance_scan, pagespeed_scan, pagespeed_results, web_vitals_trends, suggestions, rum_collect, rum_data | Read telemetry, queue explicit scans, and collect bounded field samples. |
| System and server | system_info, server_rules, recent_activities, upgrade_purge_status | Read redacted diagnostics and generated server guidance. |
| Safety and preloading | safe_mode_detect, safe_mode, preload_status, preload_resume, woo_cache_self_test, dismiss_welcome | Run read-only checks, resume bounded work, and manage onboarding state. |
| Sandbox and adaptive suggestions | sandbox_preview, sandbox_save, sandbox_promote, sandbox_discard, ai_model, ai_learn, ai_suggestions | Preview/promote staged settings and read the opt-in adaptive surface. |
Response conventions
Administrative handlers use the plugin response envelope with a success flag, message, and data payload where appropriate. Destructive operations require an explicit action/mode and preserve dry-run or health information. The exact route schema and callbacks are generated in the Rest source reference.
Safe client checklist
- Authenticate with the current WordPress REST nonce.
- Send only the route\’s documented parameters.
- Show the returned message and inspect the data before showing success.
- Abort stale requests when a component unmounts or a newer request supersedes them.
- Never surface a secret-shaped value in an error message or console log.