What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
For Contact Form 7 (CF7), choose authentication based on the system receiving the request—not on the form itself. Use a WordPress Application Password with HTTP Basic Authentication when a program or integration needs to access a WordPress site as a user; use a Bearer token when an API’s OAuth flow and documentation specify one; and use an API key exactly as its provider instructs. These credentials are not interchangeable, and CF7’s own Ajax submissions do not require you to add one of them to the public-facing form.
What is the difference between Bearer, API key, and Basic Auth?
Basic and Bearer are HTTP authentication schemes: they describe how a credential is presented in a request. An API key is a credential issued by a service, not a universal HTTP scheme. The service decides whether its key belongs in a custom header, an Authorization header, a query parameter, or another documented location.
| Option | Credential and request format | Use it when |
|---|---|---|
| Basic Auth | A user ID and password joined with a colon, then Base64-encoded and sent using Authorization: Basic …. |
The receiving service supports Basic Auth. For programmatic access to WordPress, use an Application Password rather than sharing the user’s main password. |
| Bearer | An access token sent using Authorization: Bearer <access-token>. |
The API’s documented authorization flow issues a token for use with the Bearer scheme. |
| API key | A provider-issued key presented in the exact location and format stated in that provider’s documentation. | The service’s integration instructions call for an API key, as with CF7’s documented Brevo integration. |
Base64 is encoding, not encryption. RFC 7617 warns that Basic Auth is not secure unless used with an external secure system such as TLS; send it only over HTTPS. Bearer tokens and API keys are also secrets and need secure transport and storage.
Which authentication should you use for your CF7 setup?
First identify which system is making the request and which system receives it. A visitor submitting a CF7 form, a WordPress integration accessing the site’s REST API, and CF7 sending information to an external service are different paths with different authentication requirements.
#1 Best Overall
| Situation | Documented starting point | Reason |
|---|---|---|
| A script or integration needs to access a self-hosted WordPress site as a user | That user’s WordPress Application Password sent with Basic Auth over HTTPS | WordPress documents Application Passwords as programmatic credentials that can be revoked individually. |
| An API’s authorization flow returns an OAuth access token and specifies Bearer | Authorization: Bearer <access-token> |
RFC 6750 defines the Bearer scheme for OAuth 2.0 access tokens. Follow the API’s instructions for obtaining, scoping, expiring, and refreshing its token. |
| CF7 connects submissions to Brevo | A Brevo v3 API key configured according to CF7’s integration guide | The integration is service-specific; a WordPress credential is not a substitute. See CF7’s Brevo integration guide. |
| A public WordPress endpoint supplies the data you need | No authentication, if the endpoint and site configuration allow anonymous access | WordPress REST API data that is public is generally accessible without credentials. |
| An API’s documentation says “API key” but does not explain where to send it | Check the provider’s current authentication documentation before sending a request | The words “API key” do not specify an HTTP scheme or a safe placement. |
Does Contact Form 7 need a Bearer token for Ajax submissions?
No—not simply because a CF7 form submits with Ajax. CF7’s official FAQ says version 4.8 and later uses the WordPress REST API for Ajax submissions. That describes how the plugin handles submissions on the WordPress site; it is not an instruction to put a Bearer token, API key, or Basic Auth credential in the form or browser code.
If the WordPress REST API is unavailable, CF7’s Ajax submission is unavailable, but non-Ajax submission remains possible. See the CF7 FAQ about a deactivated REST API.
Rank #2
How to choose and configure credentials safely
- Identify the receiving endpoint. Determine whether the request goes to WordPress or to an external service. Check that endpoint’s current documentation for supported authentication.
- Use the credential the receiver issues. For programmatic WordPress access, create an Application Password for the relevant user and send it with Basic Auth over HTTPS. For an OAuth API, use the access token and scheme its flow specifies. For a service integration, follow that service’s API-key setup.
- Limit access and keep secrets private. Use a dedicated, least-privilege credential where the service supports it. Keep secrets on a trusted server or in a secret manager; do not put them in public JavaScript, URLs, screenshots, logs, or public source repositories.
- Plan for revocation and rotation. Revoke credentials when an integration no longer needs them. WordPress Application Passwords can be revoked individually without changing the user’s main password.
- Check permissions separately from login. Authentication establishes which credential or identity was presented; authorization determines whether that identity may perform the requested operation. A valid credential does not override endpoint permissions.
What to check if WordPress rejects Basic Auth
Confirm that the request uses HTTPS, the correct WordPress username, and the Application Password created for that user. Then check whether a proxy or hosting layer is stripping the Authorization header before WordPress receives it. WordPress’s Application Password documentation flags this as a possible cause.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Also verify that the REST endpoint permits the requested operation for that user. WordPress’s REST API reference documents endpoint behavior; authentication alone does not grant permission.
Rank #3
Version note for CF7 integrations
Contact Form 7’s version 6.1 announcement, dated June 26, 2025, says Constant Contact integration was removed in that release and recommends Brevo as an alternative. An older Constant Contact setup page may remain in official documentation, so check that the instructions apply to your installed version rather than assuming the integration is still supported.
Use CF7’s documentation index and external API integration guidance for plugin setup. For a third-party service, its own current authentication instructions determine how to send its credentials.
Quick Recap
Best Value
Rank #4
- API Security in Action
- Manning Publications
- ABIS BOOK
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools

