AI Engine talks to your WordPress site through its REST API (the /wp-json/ address of your site). Many hosts protect that API with a security layer: a firewall (WAF), a runtime shield (RASP) like Monarx or Imunify360, mod_security, or bot protection. Most of the time they don’t bother AI Engine. Sometimes they block one specific request, quietly, and a feature stops working without any error from AI Engine itself.
Here is how to recognize it, and exactly what to ask your host.
What it looks like
Uploads fail (images or files), but text works.
In the chatbot you see "Failed to upload image." or "Error uploading image. Please try again." In the Workspace app for Android, "Could not upload …" followed by your site’s message; on iOS, the file name turns red. Your host’s logs show a 403 on /wp-json/mwai-ui/v1/files/upload.
When WordPress or AI Engine refuses a request, the answer is a short JSON message (with a code like rest_forbidden). An HTML page such as "Access Denied", or a header like X-RASP-Block: 1, comes from something in front of WordPress: your host’s security layer.
If the message mentions a size limit ("This file is larger than your site accepts"), it’s not a firewall: raise upload_max_filesize and post_max_size in your PHP settings instead.
Claude or ChatGPT can’t connect to your site (MCP), or the connection drops.
You get a 401, a 403, "couldn’t connect to the server", or the OAuth sign-in page never loads. Common causes:
- the host removes the
Authorizationheader before it reaches WordPress (frequent with PHP-FPM / FastCGI setups), - the firewall blocks the servers of Claude or ChatGPT (they connect from the cloud, with user agents like
python-httpxorClaude-User), - the host restricts the REST API to certain countries or IP ranges (some Japanese hosts, like Shin Server, do this by default),
/.well-known/oauth-...addresses are answered by the server itself (404) instead of being passed to WordPress.
The chatbot reply appears all at once, very late, or freezes.
Replies are streamed. If a proxy or CDN buffers the response, you only see it when it’s complete. Long answers can also be cut if the server’s timeout is under 60 seconds.
The Workspace app can’t connect, while the site works in a browser.
The app uses an application password and the REST API. A REST restriction (by IP, by country, or "logged-in users only") will block it.
What to do
First, make sure AI Engine is up to date. For Claude or ChatGPT, run the check in AI Engine → Settings → MCP: the Connect an AI assistant card tests your host on its own and tells you what’s wrong, for example "Your host blocks Claude", "Your host blocks Claude’s requests", "AI assistants are blocked" (often Cloudflare’s AI bot blocking, under Security → Bots), "The sign-in discovery is blocked" or "A cache is serving an old error". When something is blocked, the card also gives you a ready message for your host. The detailed manual test is in the Connection Test section just below. If everything looks fine on the WordPress side, the fix is on your host’s side: they can allow AI Engine in a few minutes once they know what to allow.
You can copy and paste this message to your host’s support:
Hello,
I use the AI Engine plugin on my WordPress site. Some of its requests are blocked by your security layer (firewall / WAF / RASP). Could you please allow these REST API routes on my site, for authenticated requests?
/wp-json/mwai-ui/v1/*(chatbot, forms, file uploads includingPOST /wp-json/mwai-ui/v1/files/upload, multipart)/wp-json/mwai/v1/*(admin, mobile app, API)/wp-json/mcp/v1/*(MCP server used by Claude and ChatGPT: POST, GET and DELETE)/.well-known/oauth-protected-resourceand/.well-known/oauth-authorization-server(they must reach WordPress, not be served as static files)Could you also check that:
- the
Authorizationheader is passed to PHP (CGIPassAuth Onor equivalent),- responses with
text/event-streamare not buffered,- requests can run for at least 120 seconds,
- traffic from Claude and ChatGPT (user agents such as
python-httpxorClaude-User) is not blocked or challenged on/wp-json/mcp/v1/*.Thank you!
If your host needs more details, we have a one-page technical note written for their platform team: just ask us through the support form and we’ll send it.