WordPress 7.1 48 writes this block when you save permalinks. It needs mod_rewrite, AllowOverride FileInfo and Options FollowSymLinks:
# BEGIN WordPress
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>
# END WordPressWordPress regenerates the lines between the markers, so add yours outside. Apache 129 keeps Authorization out of HTTP_* variables; line 4 copies it in for API tokens. Line 6 ends the second pass (Stopping Rewrite Loops), and line 9's . leaves / to DirectoryIndex. A stub index.php answered:
/ index.php uri=/ auth= [200]
/2026/09/hello-world/?page=2 index.php uri=/2026/09/hello-world/?page=2 auth= [200]
/wp-content/themes/twentytwentyfive/style.css body{} [200]
/wp-json/wp/v2/posts index.php uri=/wp-json/wp/v2/posts auth=Bearer 7f3a9c [200]Without line 4, auth= read (none). A site in /blog/ puts /blog/ on lines 5 and 9.