=== Code and core Headless Fast API - Standalone, cacheable REST endpoints that skip the core load cycle ===
Contributors: codeandcore
Tags: headless, rest api, performance, acf, decoupled
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Fast, cacheable headless API endpoints answered before the theme, the REST API and WP_Query load.

== Description ==

**Your headless front end is only as fast as the API behind it.** Code and Core Headless Fast API gives your Next.js, Nuxt, Astro, Gatsby, SvelteKit, React Native or Flutter app a WordPress API built for speed. It does not run the whole of WordPress on every request.

Each request to the built-in WordPress REST API starts the full WordPress stack: every active plugin, the theme, `init`, the REST server, its controllers and `WP_Query`. On a typical site with 20 to 40 plugins, most of that work has nothing to do with the JSON you asked for. This plugin cuts that work out:

* It answers **before the theme, `init`, the REST API and `WP_Query` load**.
* In **Fast Mode**, it answers **before any regular plugin loads**.
* It builds each response with **a small number of batched, prepared SQL queries**.
* It can serve repeat requests **from one cached JSON file on disk**.

Your front end gets the familiar REST-style data, including ACF fields, Yoast SEO metadata and resolved relationships, with far less work on the server. The result is lower response times, less CPU and database load, and quicker static builds and server-side rendering.

The built-in REST API is not changed or disabled. This plugin adds its own read-only namespace, `/code-and-core-headless-fast-api/v1/`, next to it, so you can switch over one endpoint at a time.

= Why choose Headless Fast API? =

* **Built for headless.** Every design decision serves one job: getting content to a decoupled front end as quickly as possible.
* **Faster, especially on busy sites.** Response time no longer grows with each plugin you install (Fast Mode).
* **Lighter payloads.** Remove every field your front end does not use. Smaller JSON means faster transfers, faster parsing and faster pages.
* **Fewer round trips.** Resolve ACF relationships, images, terms and users inside one response, so you don't need ten follow-up requests.
* **Easy to adopt.** Items use the REST API's field names (`title.rendered`, `content.rendered`, `featured_media`, …), so existing front-end code needs only small changes.
* **No setup.** No server rules, no extra entry point, no Node.js service, no GraphQL schema to maintain. Activate, choose your content, copy the URLs.
* **Safe by design.** Read-only, `GET` only, prepared SQL, an allowlist of entities, and capability and nonce checks on every admin action.
* **Clean to remove.** Deactivating removes the Fast Mode file. Deleting removes every option and data file the plugin created.

= Built-in REST API compared with Headless Fast API =

* **Plugins loaded per request:** REST API: all of them. Headless Fast API: all of them, or none in Fast Mode.
* **Theme and `init`:** REST API: loaded. Headless Fast API: skipped.
* **Query engine:** REST API: `WP_Query` and REST controllers. Headless Fast API: direct, batched, prepared SQL.
* **Response cache:** REST API: none built in. Headless Fast API: optional disk cache, with a `HIT`/`MISS` header.
* **Removing fields:** REST API: `_fields` on each request. Headless Fast API: saved per endpoint in the admin, including nested ACF fields and flexible-content layouts.
* **ACF relationships:** REST API: IDs only, so you need extra requests. Headless Fast API: resolved into full objects in the same response.
* **Yoast SEO head:** REST API: provided by Yoast. Headless Fast API: built from Yoast's own indexable data, without loading Yoast.
* **List totals:** REST API: `X-WP-Total` headers. Headless Fast API: `total` and `total_pages` in the JSON body.
* **Server configuration:** neither needs any.

= Perfect for =

* Next.js, Nuxt, Remix and SvelteKit sites that use server-side rendering or incremental static regeneration.
* Static builds with Astro, Gatsby, Eleventy or Hugo, where builds that fetch thousands of pages finish sooner.
* React Native and Flutter apps that need small, predictable JSON.
* Agencies running content-heavy WordPress back ends with many plugins.
* Any site where the REST API has become the slowest part of the stack.

= Quick start in 60 seconds =

1. Install and activate the plugin.
2. In the popup, click **Enable Fast Mode** (recommended).
3. Under **Entities**, choose your post types and taxonomies, then click **Save & Sync Schemas**.
4. Open the **Dashboard**, copy an endpoint URL, and fetch it from your front end.

= Key features =

* **Early answer.** API requests are answered on `plugins_loaded`, before the theme, `init`, the REST API and `WP_Query` run.
* **Fast Mode (optional).** A small must-use loader answers API requests before any regular plugin loads, so response time does not grow with the number of plugins installed.
* **Direct SQL.** Posts, pages, media, custom post types, taxonomies, users and ACF options pages are read with prepared queries. Meta, terms, authors, featured media and images are loaded in batches, not one query per item.
* **REST-compatible items.** Each item follows the WordPress REST API format (`id`, `title.rendered`, `content.rendered`, `excerpt.rendered`, `featured_media`, `_links` and so on), so existing front-end code needs few changes.
* **Disk cache.** Finished JSON responses can be written to disk and served with a single file read.
* **Field exclusion.** Choose, per endpoint and per context (list or single), exactly which fields to remove from the response, down to individual ACF sub-fields and flexible-content layouts. Smaller payloads, faster pages.
* **Relationship resolving.** Turn ACF post, term, media and user IDs into full objects inside the same response, so the front end does not need to make extra requests.
* **Append rules.** Add extra data, such as the latest posts, to a field of a response.
* **Advanced Custom Fields.** ACF fields are included under `acf`, including repeaters, groups, flexible content and image fields. ACF options pages get their own endpoint.
* **Yoast SEO.** `yoast_head` and `yoast_head_json` are built from Yoast's own indexable data, ready for your front end's `<head>`.
* **Custom meta.** Expose any post meta key, typed as string, integer, boolean or JSON.
* **Live schema builder.** Send a request from the admin screen, see the live response as a tree, and switch fields on or off with a preview before saving.
* **API explorer.** The Dashboard lists every active endpoint with Copy and "Execute Request" buttons.
* **Import, export and reset.** Back up the whole configuration as JSON and restore it on another site.
* **No server configuration.** Works on Apache, Nginx, LiteSpeed and IIS through WordPress's normal `index.php`. No rewrite rules, no separate entry point.
* **Light and dark admin theme.** The admin screens are self-contained and load no third-party assets.

= How the speed is achieved =

1. **Short request path.** A request to `/code-and-core-headless-fast-api/v1/...` is recognised from the URL with a simple string check. All other requests continue as normal and pay almost nothing.
2. **No WP_Query and no REST server.** The router reads a static JSON schema file, builds SQL directly, shapes the result like the REST API, prints JSON and stops.
3. **Batched queries.** Meta, terms, authors, attachments and Yoast data for every item on a page are fetched together. Relationship fields are resolved in one query per object type.
4. **Fewer option reads.** The site options the API needs are fetched in one query per request.
5. **Disk cache.** With caching on, a repeat request is served from one JSON file.
6. **Fast Mode.** Skips loading all regular plugins and the theme on API requests.

= Fast Mode (optional) =

On sites with many plugins, most of a request's time is spent loading those plugins. Fast Mode answers API requests before any regular plugin loads.

Fast Mode is off until an administrator turns it on. After activation the plugin asks once, in a popup on its Dashboard screen, and nothing is installed unless the administrator clicks "Enable Fast Mode". It can be turned on or off at any time under **Advanced**.

Turning it on writes one small file, `wp-content/mu-plugins/0-cachfa-fast-path.php`, using the WordPress filesystem API. That file:

* acts only on requests to `/code-and-core-headless-fast-api/v1/...` and does nothing on any other request;
* does nothing if this plugin is deactivated or deleted;
* is removed when Fast Mode is turned off or this plugin is deactivated;
* is rewritten automatically after a plugin update;
* is never written over or deleted if a file of the same name was not created by this plugin.

Because other plugins do not run on API requests in Fast Mode, output they add through filters at runtime is not included in API responses. Data they save to the database is included.

= Endpoints =

All endpoints are `GET` only and start with:

`https://example.com/code-and-core-headless-fast-api/v1/`

* `home`: the static front page (Settings > Reading), or the latest posts if the front page shows posts.
* `posts`, `posts/{id_or_slug}`: posts.
* `pages`, `pages/{id_or_slug}`: pages.
* `media`, `media/{id_or_slug}`: attachments.
* `{post_type}s`, `{post_type}s/{id_or_slug}`: any public custom post type you enable (for example `products`, `products/blue-shirt`).
* `categories`, `categories/{id_or_slug}`: categories.
* `tags`, `tags/{id_or_slug}`: tags.
* `{taxonomy}s`, `{taxonomy}s/{id_or_slug}`: any public custom taxonomy you enable.
* `users`, `users/{id_or_slug}`: users (can be turned off under Entities).
* `options/{options_page_slug}`: fields from an ACF options page (needs ACF with options pages).

The Dashboard screen lists the exact URL of every active endpoint on your site.

Endpoints are available only for the post types and taxonomies you enable under **Entities**. Any other type returns a `404` with a JSON error.

= Query parameters =

**Posts, pages, media and custom post types**

* `page`: page number (default `1`).
* `per_page`: items per page, `1` to `100` (default `10`). Other values return `400 rest_invalid_param`, as in the REST API.
* `offset`: number of items to skip; overrides `page`.
* `search`: search title, content and excerpt.
* `slug`: one or more slugs, comma-separated.
* `include`, `exclude`: IDs, comma-separated.
* `author`, `author_exclude`: author IDs, comma-separated.
* `parent`, `parent_exclude`: parent IDs, comma-separated.
* `menu_order`: exact menu order.
* `after`, `before`: published after or before a date (any format `strtotime()` accepts, for example `2026-01-01T00:00:00`).
* `modified_after`, `modified_before`: modified after or before a date.
* `sticky`: `true` for only sticky posts, `false` to leave them out.
* `categories`, `categories_exclude`, `tags`, `tags_exclude`: term IDs, comma-separated.
* `{taxonomy}`, `{taxonomy}_exclude`: term IDs for any enabled custom taxonomy.
* `tax_relation`: `AND` (default) or `OR` between taxonomy filters.
* `media_type`: `image`, `video`, `audio`, `application`, … (media only).
* `mime_type`: exact MIME type, for example `image/png` (media only).
* `password`: password for a password-protected post. Without it, content and excerpt are empty.
* `orderby`: `date` (default), `title`, `id`, `modified`, `author`, `parent`, `slug`, `menu_order`, `include` (the order of `include`) or `include_slugs` (the order of `slug`).
* `order`: `DESC` (default) or `ASC`.

**Categories, tags and custom taxonomies**

* `page`, `per_page`, `search`, `slug`, `include`, `exclude`.
* `parent`: parent term ID (`0` for top-level terms).
* `hide_empty`: `1` to leave out terms with no posts.
* `post`: only terms assigned to this post ID.
* `orderby`: `name` (default), `id`, `count` or `slug`.
* `order`: `ASC` (default) or `DESC`.

**Users**

* `page`, `per_page` (`1` to `100`), `offset`, `search`, `slug`, `include`, `exclude`.
* `roles`, `capabilities`: comma-separated.
* `who=authors`: only users with published posts.
* `has_published_posts`: `1`, or a comma-separated list of post types.
* `orderby`: `name` (default), `id`, `registered_date`, `slug`, `url` or `include`.
* `order`: `ASC` (default) or `DESC`.

Array values such as `include[]=1&include[]=2` are accepted and treated as `include=1,2`.

= Response format =

A **single item** (`/posts/hello-world`) returns the item object, in the WordPress REST API format. Single posts also contain `pagination.previous_post` and `pagination.next_post` (`id`, `title`, `slug`) to make "previous / next" links easy.

A **list** (`/posts?per_page=5`) returns a wrapper object instead of a bare array, so you get the totals without reading headers:

`{ "type": "post", "count": 5, "total": 42, "total_pages": 9, "data": [ ... ] }`

Errors are JSON with the matching HTTP status, for example `{ "code": "rest_post_invalid_id", "message": "Invalid post ID.", "data": { "status": 404 } }`.

Every response includes:

* `Content-Type: application/json; charset=UTF-8`
* `Access-Control-Allow-Origin: *` and `Access-Control-Allow-Methods: GET, OPTIONS`, so the API can be called from a browser on any domain. `OPTIONS` preflight requests are answered straight away.
* `X-HeadlessFastAPI-Cache: HIT` or `MISS`, to show whether the disk cache was used.

= Example: fetching from a front end =

`const res  = await fetch('https://example.com/code-and-core-headless-fast-api/v1/posts?per_page=6&categories=3');`
`const json = await res.json();`
`json.data.forEach(post => console.log(post.title.rendered));`

`const page = await fetch('https://example.com/code-and-core-headless-fast-api/v1/pages/about').then(r => r.json());`

`// Next.js (App Router): revalidate every 60 seconds`
`const API = 'https://example.com/code-and-core-headless-fast-api/v1';`
`const posts = await fetch(API + '/posts?per_page=10', { next: { revalidate: 60 } }).then(r => r.json());`

= Performance tips =

* **Turn on Fast Mode.** It has the biggest effect on sites with many plugins.
* **Remove fields you don't use** on the Schema screen, for example `content` on list endpoints that only show cards.
* **Use resolve rules** instead of requesting related posts, images or terms one at a time.
* **Turn on disk caching** for content that doesn't change every minute.
* **Put a CDN in front of the API.** The responses are public, cookie-free `GET` requests, so they cache well at the edge.
* **Keep `per_page` small** and paginate with `page` and `total_pages`.
* **Check the `X-HeadlessFastAPI-Cache` header** in your browser's network tab to see whether the disk cache answered.

= Admin screens =

The plugin adds a **Code and Core Headless Fast API** menu with five screens:

* **Dashboard**: every active endpoint with its full URL, a Copy button and a built-in request tester with parameter fields and a live response viewer.
* **Entities**: switch post types, taxonomies and the Users endpoint on or off.
* **Schema**: the live response builder. Pick an endpoint, add query parameters, press Send, then switch individual fields off in the response tree. Settings are stored per endpoint and per context (list, single, or options page). You can also add custom meta fields, resolve rules and append rules here.
* **Integrations**: turn the Yoast SEO and ACF integrations on or off, enable "Strict REST API Parity" for ACF, and force a resync of the ACF field map.
* **Advanced**: disk cache, clear cache, Fast Mode, and import / export / factory reset of the configuration.

Press **Save & Sync Schemas** to save. Saving also scans for new post types, taxonomies and ACF fields again.

= Caching =

When **Enable Disk Caching** is on (Advanced screen), each response is stored as a JSON file. The key is the full request URL, so every combination of path and query string is cached separately.

* Cached responses are kept for **1 hour**, then built again on the next request.
* The cache is **not** cleared automatically when content changes. To show changes at once, turn on **Clear Cache on Save** and save the settings, or wait for the hour to pass.
* For busy sites, put a CDN or reverse proxy in front of the API as well. It is a public, read-only, cookie-free `GET` API, which makes it easy to cache at the edge.

= Advanced Custom Fields =

With the ACF integration on, each item has an `acf` object built from the stored field values and a field map generated from your field groups. The map is rebuilt when you save the settings, when you press **Force Sync**, and whenever an ACF field group is saved.

* Repeaters, groups and flexible content are returned as nested arrays and objects. Flexible-content rows include `acf_fc_layout`.
* Image fields set to return an array come back with `url`, `alt`, `width`, `height`, `mime_type` and every generated size.
* Options pages are available at `options/{menu_slug}`.
* **Resolve rules** (Schema screen) turn ID fields such as Post Object, Relationship, Taxonomy, Image/File and User into full objects in the same response, with an optional limit per field.
* Field exclusion paths can target a single flexible-content layout, for example `acf.sections.[hero_banner].subtitle`.

= Yoast SEO =

With Yoast SEO active and the integration on, post items include `yoast_head` (ready-made HTML for `<head>`) and `yoast_head_json` (title, description, robots, canonical, Open Graph, Twitter and schema.org graph). The data is read from Yoast's `yoast_indexable` table and settings. Make sure Yoast's SEO data optimisation (indexing) has run, so every post has an indexable.

= Files this plugin writes =

The plugin keeps its data in its own folder inside the uploads directory, resolved with `wp_upload_dir()`:

`wp-content/uploads/code-and-core-headless-fast-api/`

* `api-schema.json`: the saved configuration (entities, integrations, exclusions and rules).
* `api-schema-preview.json`: a temporary copy used by the Schema screen's live preview.
* `acf-map.json`, `acf-options.json`: the generated ACF field maps.
* `cache/`: cached responses, when caching is on.

If Fast Mode is on, it also writes the must-use plugin file described above.

Deactivating the plugin removes the Fast Mode file. Deleting the plugin also removes its options and its folder in the uploads directory.

= Security and privacy =

* The API is **read-only**. It only answers `GET` (and `OPTIONS`) requests and never writes content.
* Only the post types, taxonomies and entities you enable are served.
* Every request value is sanitized, and every value that reaches the database goes through `$wpdb->prepare()`, an allowlist or an integer cast.
* All admin actions check the `manage_options` capability and a nonce. Imported JSON is decoded and sanitized key by key.
* The API is public, like the core REST API. Use **field exclusion** to remove anything your front end does not need, and do not use the API to publish data that must stay private.
* User email addresses are not included in responses.

= External services =

This plugin does not load any scripts, stylesheets, fonts or images from a third-party server. All admin assets, including the Inter font, are bundled with the plugin.

API responses include each author's avatar URL as returned by WordPress core's `get_avatar_url()`, exactly as the core REST API does. The plugin does not request these URLs itself, and the site's avatar settings and filters apply.

== Installation ==

1. Upload the plugin files to `/wp-content/plugins/code-and-core-headless-fast-api`, or install the plugin from the **Plugins > Add New** screen.
2. Activate the plugin from the **Plugins** screen. You are taken to the plugin's Dashboard.
3. Choose whether to turn on Fast Mode in the popup (you can change this later under **Advanced**).
4. Under **Entities**, choose the post types, taxonomies and core entities to expose, then press **Save & Sync Schemas**.
5. Optional: under **Schema**, remove fields you do not need and add resolve rules for ACF relationships.
6. Optional: under **Advanced**, turn on disk caching.
7. Copy your endpoint URLs from the **Dashboard** into your front end.

Permalinks must be set to anything other than "Plain" (Settings > Permalinks), so that the `/code-and-core-headless-fast-api/v1/` URLs reach WordPress. No server configuration is needed on Apache, Nginx, LiteSpeed or IIS.

== Frequently Asked Questions ==

= Does this change or replace the built-in WordPress REST API? =

No. The built-in REST API is untouched and keeps working. This plugin adds its own endpoints under `/code-and-core-headless-fast-api/v1/`.

= Are the responses the same as the WordPress REST API? =

Individual items use the same field names and structure (`title.rendered`, `content.rendered`, `featured_media`, `_links`, …), plus `acf` and `yoast_head_json` when those integrations are on. Lists are wrapped in an object with `count`, `total`, `total_pages` and `data`, instead of a bare array with `X-WP-Total` headers.

Content is returned as stored, with paragraphs added. Shortcodes and blocks are not run through `the_content` filters, because the theme and most plugins have not loaded yet. Render dynamic blocks on your front end, or use the core REST API for the few requests that need them.

= Does it support ACF? =

Yes. Turn on the ACF integration under **Integrations**. Fields, repeaters, groups, flexible content, images and options pages are supported, and relationship fields can be expanded with resolve rules.

= Does it support Yoast SEO? =

Yes. With the Yoast integration on, items include `yoast_head` and `yoast_head_json`, built from Yoast's indexable data.

= Can I add my own post meta to the response? =

Yes. On the **Schema** screen, open the **Custom Fields** tab and add the meta key, its type (string, integer, boolean or JSON) and whether it holds a single value.

= Why don't my content changes show up? =

If disk caching is on, responses are kept for up to an hour. Save the settings with **Clear Cache on Save** turned on to clear the cache at once. Also check any CDN or proxy cache in front of the site.

= I get a 404 for a post type or taxonomy. =

Make sure it is public and turned on under **Entities**, then save. The endpoint name is the post type or taxonomy name with an `s` added (for example `product` becomes `products`). Categories, tags, pages and media use `categories`, `tags`, `pages` and `media`.

= The API returns my theme's HTML 404 page. =

Check that permalinks are not set to "Plain", and that the URL contains `/code-and-core-headless-fast-api/v1/`.

= Do I need to change my server configuration? =

No. Requests reach the API through WordPress's normal permalink handling on every server.

= What if the must-use plugins folder is not writable? =

Fast Mode cannot be turned on, and the plugin tells you so. The API keeps working and returns identical responses; it is answered on `plugins_loaded` instead, which is slower on sites with many plugins.

= Will other plugins' changes appear in Fast Mode? =

Data that plugins save to the database is included. Output that plugins add at runtime through filters is not, because those plugins do not load on API requests in Fast Mode. If you need that output, leave Fast Mode off.

= Can I move my configuration to another site? =

Yes. Use **Download Backup** under **Advanced** on the first site, then **Restore** on the second.

= Does it work on multisite? =

Each site has its own uploads folder, so each site keeps its own configuration and cache. Fast Mode checks both site-level and network-wide activation.

= Is the API public? Do I need authentication? =

The API is public and read-only, like the core REST API for published content. No API key or login is needed. Only the post types, taxonomies and entities you enable are served. Use field exclusion to remove anything your front end does not need.

= Can I write data (create, update or delete posts) through this API? =

No. The API is read-only and answers only `GET` requests. Use the built-in WordPress REST API for writes.

= Can I use both this API and the built-in REST API at the same time? =

Yes. They are completely separate. Many sites use this plugin for public, read-heavy pages and the core REST API for previews, forms and authenticated actions.

= Does it work with Gutenberg blocks? =

Block content is returned as saved in the database, with the block comment markup and HTML included. Static blocks display correctly. Dynamic blocks (latest posts, query loops, shortcodes) are not rendered on the server, because the theme and most plugins have not loaded yet. Render those on your front end.

= Does it work with page builders such as Elementor or Divi? =

Page builders usually render their output through filters at runtime, which do not run here. This plugin works best with content from the block editor, the classic editor and ACF fields. For pages made with a page builder, use the core REST API or build those sections from ACF fields.

= Does it support WooCommerce products? =

Products are a public post type, so `products` can be turned on under Entities, and the title, content, excerpt, images, terms and selected meta (for example `_price` or `_sku` through Custom Fields) are returned. Calculated WooCommerce data such as variations, tax-inclusive prices and stock status is not included. Use the WooCommerce Store API for cart and checkout.

= Does it support WPML or Polylang? =

There is no dedicated multilingual integration yet. Translated posts are returned like any other posts, but filtering by language is not available.

= Does it support custom post types and taxonomies made with CPT UI, ACF or code? =

Yes. Any public post type or taxonomy appears under Entities, however it was registered. Save once after adding a new one.

= Does it return drafts, scheduled or private posts? =

By default, only published posts (and attachments) are returned. Use WordPress's own preview tools or the authenticated core REST API for draft previews.

= How do I get the featured image URL? =

Each post includes `featured_media` (the attachment ID). To get the full image object in the same response, add a `media` resolve rule for `featured_media` on the Schema screen, or request `/media/{id}`.

= How do I get posts in a category by its slug? =

First get the term ID from `/categories/{slug}`, then request `/posts?categories={id}`. You can also cache the term ID on your front end.

= How do I paginate? =

Use `page` and `per_page`. Every list response includes `total` and `total_pages`, so you can build pagination without reading headers.

= How do I build a "previous / next post" link? =

Single post responses include `pagination.previous_post` and `pagination.next_post`, each with `id`, `title` and `slug`, or `null` at either end.

= How do I get the home page? =

Request `/home`. It returns the static front page set under Settings > Reading, or the latest posts if the front page shows posts.

= How do I remove fields from the response? =

Open the Schema screen, choose the endpoint, press Send, then switch off fields in the response tree and press **Save & Sync Schemas**. Exclusions are saved separately for list and single responses.

= What is the difference between "resolve rules" and "append rules"? =

A resolve rule replaces an ID (or a list of IDs) already in the response with the full object, such as a related post, image, term or user. An append rule adds new data that is not in the item, such as a list of the latest posts, under a field you choose.

= How long is the disk cache kept, and where? =

Up to one hour, as JSON files in `wp-content/uploads/code-and-core-headless-fast-api/cache/`. Each unique URL, including its query string, is cached separately.

= Can I use a CDN or Varnish in front of the API? =

Yes, and it is recommended. Responses are public, cookie-free `GET` requests with a JSON content type, which makes them easy to cache at the edge.

= How do I know whether a response came from the cache? =

Check the `X-HeadlessFastAPI-Cache` response header. It is `HIT` when the disk cache answered and `MISS` when the response was built.

= Can my front end on another domain call the API? =

Yes. Every response sends `Access-Control-Allow-Origin: *`, so browsers on any domain can call the API without a proxy.

= Will Fast Mode break my site? =

No. The Fast Mode file acts only on URLs that contain `/code-and-core-headless-fast-api/v1/`. Every other request, including the admin, the front end and the core REST API, loads exactly as before.

= Can I see the Fast Mode file in the Plugins screen? =

Yes. It is listed under **Plugins > Must-Use** as "Code and Core Headless Fast API - Fast Mode". Turn it off from the plugin's Advanced screen, not by editing the file.

= Does it work with security or caching plugins? =

Yes. Page-caching plugins may also cache the API URLs, which is fine for public content. If a security plugin blocks unfamiliar URLs, allow the `/code-and-core-headless-fast-api/v1/` path.

= Does it work with object caching (Redis or Memcached)? =

Yes. The plugin works with or without a persistent object cache. Its own response cache is separate and stored on disk.

= Will my settings be kept when I update the plugin? =

Yes. Settings are stored in the uploads folder and are not touched by updates. The Fast Mode file is rewritten for the new version automatically.

= What are the server requirements? =

WordPress 6.0 or later, PHP 7.4 or later, MySQL or MariaDB, and permalinks set to anything other than "Plain". Write access to the uploads folder is needed for settings and caching, and to `wp-content/mu-plugins` for Fast Mode.

= Where can I get support or report a bug? =

Use the plugin's support forum on WordPress.org, or contact Code and Core through https://codeandcore.com. Please include your WordPress, PHP and plugin versions and the endpoint URL you are calling.

= What happens when I deactivate or delete the plugin? =

Deactivating removes the Fast Mode file and stops the API. Deleting the plugin also removes its options and its `wp-content/uploads/code-and-core-headless-fast-api/` folder.

== Screenshots ==

1. **Dashboard: API endpoints reference.** Every active endpoint (home, posts, pages, media, custom post types, taxonomies, users and ACF options pages) with its full URL and a one-click Copy button.
2. **Dashboard: built-in request tester.** Open any endpoint, fill in path and query parameters (page, per_page, search, include, exclude, order, orderby), press "Execute Request" and see the status, request URL and live JSON response.
3. **Fast Mode popup.** Shown once after activation. Fast Mode is only turned on if you click "Enable Fast Mode", and it can be changed later under Advanced.
4. **Entities.** Switch each public post type, taxonomy and the Users endpoint on or off with one click.
5. **Schema: live response builder.** Pick an endpoint from the dropdown, add an ID or slug, and press Send to load a live sample of the real response.
6. **Schema: field exclusion tree.** Switch any field off, including nested ACF repeaters, groups and flexible-content layouts. Turning off a parent turns off all of its children.
7. **Schema: query parameters and custom fields.** Add, reorder and reset query parameters, and expose post meta keys as string, integer, boolean or JSON values.
8. **Integrations.** Status cards and switches for Yoast SEO and Advanced Custom Fields, with Strict REST API Parity and Force Sync for the ACF field map.
9. **Advanced: performance and Fast Mode.** Disk caching, Clear Cache on Save, and Fast Mode status with an enable or disable button.
10. **Advanced: import, export and reset.** Download a JSON backup of the whole configuration, restore it on any site, or reset to factory defaults.
11. **Dark and light theme.** Switch the admin screens between dark and light with the toggle on the Dashboard.
12. **JSON response.** A sample `/posts` response showing REST-style fields, the `acf` object, `yoast_head_json` and the `count`, `total` and `total_pages` totals.

== Credits ==

* Inter font family, Copyright 2020 The Inter Project Authors (https://github.com/rsms/inter), licensed under the SIL Open Font License 1.1. Bundled in `assets/fonts/inter/` with its license file.

== Changelog ==

= 1.0.0 =
* Initial release.
* Read-only JSON endpoints for posts, pages, media, custom post types, taxonomies, users and ACF options pages.
* Optional Fast Mode must-use loader.
* Disk response cache.
* Per-endpoint field exclusion, ACF resolve rules and append rules.
* ACF and Yoast SEO integrations.
* Import, export and factory reset of the configuration.

== Upgrade Notice ==

= 1.0.0 =
Initial release.
