Skip to main content
GET
List authors

Authorizations

X-API-Key
string
header
required

The connection key the user generated in Jorge Castro (Settings → Integration → Custom Website). Reject any request whose key doesn't match yours.

X-Castro-Timestamp
string
header
required

Unix time in milliseconds when the request was signed — Castro uses Date.now(). Reject anything more than a few minutes old.

A seconds-based comparison makes every request look ~55,000 years in the future, and the freshness check then silently passes everything.

X-Castro-Signature
string
header
required

HMAC-SHA256("{timestamp}.{rawBody}", api_key), lowercase hex.

rawBody is the exact bytes of the request body — empty for GET and DELETE, which therefore sign over "{timestamp}.". Hash the raw bytes, never a re-serialized copy of the parsed JSON: whitespace and key order differences will break the comparison for some payloads and not others, which reads as an intermittent bug.

Compare in constant time (crypto.timingSafeEqual, hash_equals, hmac.compare_digest).

Query Parameters

per_page
integer
default:100

Items per page. Castro asks for 100.

page
integer
default:1

1-based page number. Castro keeps paging until it receives a page shorter than per_page, so a full final page must be followed by an empty one — otherwise it will keep asking.

Response

Author list (bare JSON array)

id
string
required
username
string
email
string
display_name
string
first_name
string
last_name
string
description
string
url
string