{"id":8843,"date":"2026-08-22T10:05:00","date_gmt":"2026-08-22T08:05:00","guid":{"rendered":"https:\/\/www.lukaswojcik.com\/blog\/?p=8843"},"modified":"2026-08-13T14:30:14","modified_gmt":"2026-08-13T12:30:14","slug":"secure-wordpress-rest-api-oauth-custom-endpoints","status":"publish","type":"post","link":"https:\/\/www.lukaswojcik.com\/blog\/en\/web-development\/secure-wordpress-rest-api-oauth-custom-endpoints\/","title":{"rendered":"Secure WordPress REST API: OAuth 2.0 and Custom Authorized Endpoints"},"content":{"rendered":"\r\n<h2 class=\"wp-block-heading\">Secure WordPress REST API: OAuth 2.0 and Custom Authorized Endpoints<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Integrating WordPress with external SaaS platforms, serverless data pipelines, or automated deployment agents requires exposing robust, high-performance API interfaces. Relying on default WordPress REST API endpoints or basic Application Passwords often grants excessive privileges across the entire Content Management System. Designing secure, enterprise-grade integration layers requires implementing OAuth 2.0 authorization flows alongside purpose-built custom REST endpoints with granular access restrictions.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\">1. Moving Beyond Application Passwords: The Power of OAuth 2.0<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Standard WordPress Application Passwords authenticate requests using Basic Authentication over HTTPS. While functional for simple scripts, this model inherits the full administrative capabilities of the associated user account. In complex architectures, OAuth 2.0 provides superior cryptographic separation and security governance:<\/p>\r\n\r\n\r\n\r\n<ul class=\"wp-block-list\">\r\n<li><strong>Strict Scope Limitation:<\/strong> OAuth 2.0 access tokens can be restricted to specific read or write scopes (e.g., granting permission solely to update specific custom database tables without providing access to user management or plugin configurations).<\/li>\r\n\r\n\r\n\r\n<li><strong>Short-Lived Tokens &amp; Revocation:<\/strong> Access tokens expire automatically after a predefined lifecycle, utilizing refresh token rotation to minimize exposure if an external SaaS integration is compromised.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<figure class=\"lw-diagram\">\n<img loading=\"lazy\" src=\"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/diagrams\/hand-restapi-en.png\" width=\"1120\" height=\"660\" decoding=\"async\"\n     alt=\"A request passing four gates \u2014 bearer header, token validity, payload schema and rate limit \u2014 before the WordPress REST handler is executed\">\n<figcaption>Every check happens before the handler, not inside it: the permission callback decides who gets in, the argument schema decides what may come in, and the rate limit decides how often.<\/figcaption>\n<\/figure>\n\n<h2 class=\"wp-block-heading\">2. Architecting Custom REST API Endpoints with Minimal Attack Surface<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">To prevent unauthorized data exfiltration or unintended database manipulation, custom endpoints must be registered using <code>register_rest_route()<\/code> with explicit input validation, sanitization routines, and strict permission callbacks.<\/p>\r\n\r\n\r\n\r\n<pre class=\"wp-block-code\"><code>\/\/ Example: Secure custom REST API endpoint with strict OAuth \/ token validation\r\nadd_action('rest_api_init', function () {\r\n    register_rest_route('lw-solutions\/v1', '\/ingest-telemetry', [\r\n        'methods'             =&gt; 'POST',\r\n        'callback'            =&gt; 'lw_handle_telemetry_ingestion',\r\n        'permission_callback' =&gt; function ($request) {\r\n            \/\/ Validate OAuth bearer token or custom JWT HMAC signature\r\n            $auth_header = $request-&gt;get_header('authorization');\r\n            if (!$auth_header || !str_starts_with($auth_header, 'Bearer ')) {\r\n                return new WP_Error('rest_forbidden', 'Missing authorization token', ['status' =&gt; 401]);\r\n            }\r\n            $token = substr($auth_header, 7);\r\n            return lw_verify_api_token($token); \/\/ Must return true or WP_Error\r\n        },\r\n        'args'                =&gt; [\r\n            'payload_hash' =&gt; [\r\n                'required'          =&gt; true,\r\n                'type'              =&gt; 'string',\r\n                'validate_callback' =&gt; function($param) {\r\n                    return (bool) preg_match('\/^[a-f0-9]{64}$\/i', $param);\r\n                }\r\n            ]\r\n        ]\r\n    ]);\r\n});<\/code><\/pre>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\">3. Hardening Best Practices for API Integrations<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Exposing REST endpoints to external automation scripts necessitates several defensive engineering practices:<\/p>\r\n\r\n\r\n\r\n<ul class=\"wp-block-list\">\r\n<li><strong>Rate Limiting &amp; Throttling:<\/strong> Implementing Redis-based or server-level request throttling prevents Denial-of-Service (DoS) vectors against resource-intensive endpoints.<\/li>\r\n\r\n\r\n\r\n<li><strong>Payload Schema Enforcement:<\/strong> Relying on strict JSON schema validation within the endpoint registration rules ensures that malformed payloads are rejected at the REST server level before executing any PHP backend logic.<\/li>\r\n\r\n\r\n\r\n<li><strong>Default Endpoint Disabling:<\/strong> Unused default routes (such as <code>\/wp\/v2\/users<\/code>) should be programmatically restricted or stripped from unauthenticated requests to prevent username enumeration.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\">Summary<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Secure REST API architecture in WordPress requires abandoning over-privileged basic authentication in favor of scoped OAuth 2.0 token workflows. Combining rigorous <code>permission_callback<\/code> validations, strict regex-based argument checks, and dedicated integration routes ensures seamless automation without expanding the CMS attack surface.<\/p>\r\n\n\n<div class=\"lw-quellen\">\n<h2>Sources<\/h2>\n<ul>\n<li><a href=\"https:\/\/developer.wordpress.org\/rest-api\/\" target=\"_blank\" rel=\"noopener noreferrer\">WordPress REST API handbook<\/a><\/li>\n<li><a href=\"https:\/\/owasp.org\/www-project-top-ten\/\" target=\"_blank\" rel=\"noopener noreferrer\">OWASP Top 10<\/a><\/li>\n<\/ul>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Technical guide on securing WordPress REST API integrations: implementing OAuth 2.0 scopes, registering custom authorized endpoints, and enforcing strict schema validation.<\/p>\n","protected":false},"author":1,"featured_media":11662,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[148],"tags":[91093,91392,91219,91115,91096],"class_list":["post-8843","post","type-post","status-publish","format-standard","hentry","category-web-development","tag-php","tag-rest-api","tag-tutorial","tag-web-security","tag-wordpress"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Secure WordPress REST API: OAuth 2.0 and Custom Authorized Endpoints - Lukas Wojcik - Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.lukaswojcik.com\/blog\/en\/web-development\/secure-wordpress-rest-api-oauth-custom-endpoints\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Secure WordPress REST API: OAuth 2.0 and Custom Authorized Endpoints - Lukas Wojcik - Blog\" \/>\n<meta property=\"og:description\" content=\"Technical guide on securing WordPress REST API integrations: implementing OAuth 2.0 scopes, registering custom authorized endpoints, and enforcing strict schema validation.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.lukaswojcik.com\/blog\/en\/web-development\/secure-wordpress-rest-api-oauth-custom-endpoints\/\" \/>\n<meta property=\"og:site_name\" content=\"Lukas Wojcik - Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-22T08:05:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/08\/hero-8843-secure-wordpress-rest-api-oauth-cust-c.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"luky\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"luky\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/web-development\\\/secure-wordpress-rest-api-oauth-custom-endpoints\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/web-development\\\/secure-wordpress-rest-api-oauth-custom-endpoints\\\/\"},\"author\":{\"name\":\"luky\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"headline\":\"Secure WordPress REST API: OAuth 2.0 and Custom Authorized Endpoints\",\"datePublished\":\"2026-08-22T08:05:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/web-development\\\/secure-wordpress-rest-api-oauth-custom-endpoints\\\/\"},\"wordCount\":383,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"image\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/web-development\\\/secure-wordpress-rest-api-oauth-custom-endpoints\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hero-8843-secure-wordpress-rest-api-oauth-cust-c.png\",\"keywords\":[\"PHP\",\"REST API\",\"Tutorial\",\"Web Security\",\"WordPress\"],\"articleSection\":[\"Web Development\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/web-development\\\/secure-wordpress-rest-api-oauth-custom-endpoints\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/web-development\\\/secure-wordpress-rest-api-oauth-custom-endpoints\\\/\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/web-development\\\/secure-wordpress-rest-api-oauth-custom-endpoints\\\/\",\"name\":\"Secure WordPress REST API: OAuth 2.0 and Custom Authorized Endpoints - Lukas Wojcik - Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/web-development\\\/secure-wordpress-rest-api-oauth-custom-endpoints\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/web-development\\\/secure-wordpress-rest-api-oauth-custom-endpoints\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hero-8843-secure-wordpress-rest-api-oauth-cust-c.png\",\"datePublished\":\"2026-08-22T08:05:00+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/web-development\\\/secure-wordpress-rest-api-oauth-custom-endpoints\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/web-development\\\/secure-wordpress-rest-api-oauth-custom-endpoints\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/web-development\\\/secure-wordpress-rest-api-oauth-custom-endpoints\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hero-8843-secure-wordpress-rest-api-oauth-cust-c.png\",\"contentUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hero-8843-secure-wordpress-rest-api-oauth-cust-c.png\",\"width\":1200,\"height\":630,\"caption\":\"Secure WordPress REST API: OAuth 2.0 and Custom Authorized Endpoints\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/web-development\\\/secure-wordpress-rest-api-oauth-custom-endpoints\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Secure WordPress REST API: OAuth 2.0 and Custom Authorized Endpoints\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/\",\"name\":\"Lukas Wojcik - Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\",\"name\":\"luky\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"contentUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"width\":424,\"height\":636,\"caption\":\"luky\"},\"logo\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\"},\"sameAs\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\"],\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/author\\\/luky\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Secure WordPress REST API: OAuth 2.0 and Custom Authorized Endpoints - Lukas Wojcik - Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.lukaswojcik.com\/blog\/en\/web-development\/secure-wordpress-rest-api-oauth-custom-endpoints\/","og_locale":"en_US","og_type":"article","og_title":"Secure WordPress REST API: OAuth 2.0 and Custom Authorized Endpoints - Lukas Wojcik - Blog","og_description":"Technical guide on securing WordPress REST API integrations: implementing OAuth 2.0 scopes, registering custom authorized endpoints, and enforcing strict schema validation.","og_url":"https:\/\/www.lukaswojcik.com\/blog\/en\/web-development\/secure-wordpress-rest-api-oauth-custom-endpoints\/","og_site_name":"Lukas Wojcik - Blog","article_published_time":"2026-08-22T08:05:00+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/08\/hero-8843-secure-wordpress-rest-api-oauth-cust-c.png","type":"image\/png"}],"author":"luky","twitter_card":"summary_large_image","twitter_misc":{"Written by":"luky","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/web-development\/secure-wordpress-rest-api-oauth-custom-endpoints\/#article","isPartOf":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/web-development\/secure-wordpress-rest-api-oauth-custom-endpoints\/"},"author":{"name":"luky","@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"headline":"Secure WordPress REST API: OAuth 2.0 and Custom Authorized Endpoints","datePublished":"2026-08-22T08:05:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/web-development\/secure-wordpress-rest-api-oauth-custom-endpoints\/"},"wordCount":383,"commentCount":0,"publisher":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"image":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/web-development\/secure-wordpress-rest-api-oauth-custom-endpoints\/#primaryimage"},"thumbnailUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/08\/hero-8843-secure-wordpress-rest-api-oauth-cust-c.png","keywords":["PHP","REST API","Tutorial","Web Security","WordPress"],"articleSection":["Web Development"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.lukaswojcik.com\/blog\/en\/web-development\/secure-wordpress-rest-api-oauth-custom-endpoints\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/web-development\/secure-wordpress-rest-api-oauth-custom-endpoints\/","url":"https:\/\/www.lukaswojcik.com\/blog\/en\/web-development\/secure-wordpress-rest-api-oauth-custom-endpoints\/","name":"Secure WordPress REST API: OAuth 2.0 and Custom Authorized Endpoints - Lukas Wojcik - Blog","isPartOf":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/web-development\/secure-wordpress-rest-api-oauth-custom-endpoints\/#primaryimage"},"image":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/web-development\/secure-wordpress-rest-api-oauth-custom-endpoints\/#primaryimage"},"thumbnailUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/08\/hero-8843-secure-wordpress-rest-api-oauth-cust-c.png","datePublished":"2026-08-22T08:05:00+00:00","breadcrumb":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/web-development\/secure-wordpress-rest-api-oauth-custom-endpoints\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.lukaswojcik.com\/blog\/en\/web-development\/secure-wordpress-rest-api-oauth-custom-endpoints\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/web-development\/secure-wordpress-rest-api-oauth-custom-endpoints\/#primaryimage","url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/08\/hero-8843-secure-wordpress-rest-api-oauth-cust-c.png","contentUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/08\/hero-8843-secure-wordpress-rest-api-oauth-cust-c.png","width":1200,"height":630,"caption":"Secure WordPress REST API: OAuth 2.0 and Custom Authorized Endpoints"},{"@type":"BreadcrumbList","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/web-development\/secure-wordpress-rest-api-oauth-custom-endpoints\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.lukaswojcik.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Secure WordPress REST API: OAuth 2.0 and Custom Authorized Endpoints"}]},{"@type":"WebSite","@id":"https:\/\/www.lukaswojcik.com\/blog\/#website","url":"https:\/\/www.lukaswojcik.com\/blog\/","name":"Lukas Wojcik - Blog","description":"","publisher":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.lukaswojcik.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9","name":"luky","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","contentUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","width":424,"height":636,"caption":"luky"},"logo":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg"},"sameAs":["https:\/\/www.lukaswojcik.com\/blog"],"url":"https:\/\/www.lukaswojcik.com\/blog\/author\/luky\/"}]}},"_links":{"self":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts\/8843","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/comments?post=8843"}],"version-history":[{"count":2,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts\/8843\/revisions"}],"predecessor-version":[{"id":10030,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts\/8843\/revisions\/10030"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/media\/11662"}],"wp:attachment":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/media?parent=8843"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/categories?post=8843"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/tags?post=8843"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}