Skip to main content
POST
Create a blog post (required)

Authorizations

X-API-Key
string
header
required

The connection key the user generated in Jorge Castro (Settings → Integration → Custom Website). Reject any request whose key doesn't match yours.

X-Castro-Timestamp
string
header
required

Unix time in milliseconds when the request was signed — Castro uses Date.now(). Reject anything more than a few minutes old.

A seconds-based comparison makes every request look ~55,000 years in the future, and the freshness check then silently passes everything.

X-Castro-Signature
string
header
required

HMAC-SHA256("{timestamp}.{rawBody}", api_key), lowercase hex.

rawBody is the exact bytes of the request body — empty for GET and DELETE, which therefore sign over "{timestamp}.". Hash the raw bytes, never a re-serialized copy of the parsed JSON: whitespace and key order differences will break the comparison for some payloads and not others, which reads as an intermittent bug.

Compare in constant time (crypto.timingSafeEqual, hash_equals, hmac.compare_digest).

Body

application/json

The body of POST /posts. title, content and status are always present; the rest depend on what the user filled in.

title
string
required
Example:

"10 Best Running Shoes in 2026"

content
string
required

Post body as HTML. The H1 is already stripped — render title as your page heading.

Example:

"<p>Choosing the right running shoe...</p>"

status
enum<string>
required
Available options:
publish,
draft
excerpt
string

Short summary / meta description text.

date
string

Publish datetime, YYYY-MM-DD HH:MM:SS.

Example:

"2026-07-03 14:22:01"

categories
string[]

Category NAMES. Create any that don't exist yet.

Example:
tags
string[]
Example:
author
string

Author display name.

Example:

"Jane Levy"

URL of the featured image, hosted by Castro.

reading_time
string
Example:

"5 minutes"

seo
object
source_id
string

Castro's internal content id — store it for idempotency.

Example:

"cnt_9f2ka83b"

Response

Post created

id
string
required

Your id for the entity — any string; Castro stores it verbatim.

Maximum string length: 191
Example:

"8842"

url
string

Public URL of the entity (optional but recommended).

Example:

"https://your-site.com/blog/10-best-running-shoes"