Sucuri is blocking the connection
The request never reached the connector plugin. A security layer in front of the site answered instead, so Sentro received a challenge or block page rather than the JSON response it expects from /wp-json/crhub/v1/.
What to change, in order of preference
- Allow our outbound IP address 185.166.188.64 in the firewall or security plugin. Every Sentro request comes from this one fixed address, so this is normally the quickest fix.
- Or exclude the path /wp-json/crhub/v1/ from bot protection, firewall rules and rate limiting, so only the connector endpoints are affected.
- Our requests always identify themselves with the user agent RootsWP/2.4.1 (+https://rootswp.com); some products can allow that directly.
- As a test only, switch the protection off briefly, connect the site, and turn it back on. If the connection works then, you know where the block sits.
Where to look in Sucuri
For the Sucuri Firewall (the cloud WAF), sign in to the Sucuri dashboard for this site and open the firewall settings. Under the access control settings you can allow specific paths and URLs; add /wp-json/crhub/v1/ so requests to it are not challenged. If you only use the free Sucuri Security plugin inside WordPress, that plugin does not block traffic in front of the site — in that case the block comes from your host or another firewall, and the generic guide applies.
Sentence you can send to support
Copy this to your host or firewall provider.
Our WordPress site is managed by Sentro. Requests to the REST path /wp-json/crhub/v1/ are being blocked by your security layer before they reach the site. All of these requests come from one fixed IP address, 185.166.188.64, and identify themselves with the user agent RootsWP/2.4.1 (+https://rootswp.com). Could you allow that IP address, or exclude the path /wp-json/crhub/v1/ from bot protection, firewall rules and rate limiting?
Our outbound IP address
Every request Sentro makes to your site leaves from one fixed IPv4 address: 185.166.188.64. Add that address to the allowlist of your firewall, security plugin or host and our calls to /wp-json/crhub/v1/ get through. You can send your host our IP page at https://rootswp.com/docs/ip.
We have not verified the current interface of this product, so this page describes the setting in general terms rather than naming menus that may have changed.