Cleantalk’s Security plugin (different from their Anti-Spam plugin) auto-blocks REST API requests by default. One toggle fixes it.
Allow authenticated REST API access
- Cleantalk → Security → Settings.
- Find REST API Authorization.
- Set it to Allow Authenticated.
Every call Claude makes carries the access your own site issued when you approved it, so it qualifies as “Authenticated” — Cleantalk will let it through. If it still blocks, allow Anthropic’s outbound range 160.79.104.0/21, which is where Claude’s requests come from.
The Anti-Spam plugin
Cleantalk’s Anti-Spam plugin is fine — it only operates on comment and form submissions, not REST API traffic. No action needed there.
