Skip to main content
POST
Create a blog category

Authorizations

X-API-Key
string
header
required

The connection key the user generated in Jorge Castro (Settings → Integration → Custom Website). Reject any request whose key doesn't match yours.

X-Castro-Timestamp
string
header
required

Unix time in milliseconds when the request was signed — Castro uses Date.now(). Reject anything more than a few minutes old.

A seconds-based comparison makes every request look ~55,000 years in the future, and the freshness check then silently passes everything.

X-Castro-Signature
string
header
required

HMAC-SHA256("{timestamp}.{rawBody}", api_key), lowercase hex.

rawBody is the exact bytes of the request body — empty for GET and DELETE, which therefore sign over "{timestamp}.". Hash the raw bytes, never a re-serialized copy of the parsed JSON: whitespace and key order differences will break the comparison for some payloads and not others, which reads as an intermittent bug.

Compare in constant time (crypto.timingSafeEqual, hash_equals, hmac.compare_digest).

Body

application/json
name
string
description
string
slug
string
parent
string

Response

Created category

id
string
required
name
string
slug
string
description
string
parent
string