Cloudflare is blocking the connection
The request never reached the connector plugin. A security layer in front of the site answered instead, so Sentro received a challenge or block page rather than the JSON response it expects from /wp-json/crhub/v1/.
What to change, in order of preference
- Allow our outbound IP address 185.166.188.64 in the firewall or security plugin. Every Sentro request comes from this one fixed address, so this is normally the quickest fix.
- Or exclude the path /wp-json/crhub/v1/ from bot protection, firewall rules and rate limiting, so only the connector endpoints are affected.
- Our requests always identify themselves with the user agent RootsWP/2.4.1 (+https://rootswp.com); some products can allow that directly.
- As a test only, switch the protection off briefly, connect the site, and turn it back on. If the connection works then, you know where the block sits.
Where to look in Cloudflare
In the Cloudflare dashboard, open the domain and go to Security, then WAF, then Custom rules. Create a rule that matches requests whose URI path starts with /wp-json/crhub/v1/ and give it the Skip action, selecting the security products to skip (for example managed rules, bot protection and rate limiting).
Sentence you can send to support
Copy this to your host or firewall provider.
Our WordPress site is managed by Sentro. Requests to the REST path /wp-json/crhub/v1/ are being blocked by your security layer before they reach the site. All of these requests come from one fixed IP address, 185.166.188.64, and identify themselves with the user agent RootsWP/2.4.1 (+https://rootswp.com). Could you allow that IP address, or exclude the path /wp-json/crhub/v1/ from bot protection, firewall rules and rate limiting?
Our outbound IP address
Every request Sentro makes to your site leaves from one fixed IPv4 address: 185.166.188.64. Add that address to the allowlist of your firewall, security plugin or host and our calls to /wp-json/crhub/v1/ get through. You can send your host our IP page at https://rootswp.com/docs/ip.
The steps on this page were checked against the vendor documentation linked below.