Skip to main content
PUT

Authorizations

X-API-Key
string
header
required

The connection key the user generated in Jorge Castro (Settings → Integration → Custom Website). Reject any request whose key doesn't match yours.

X-Castro-Timestamp
string
header
required

Unix time in milliseconds when the request was signed — Castro uses Date.now(). Reject anything more than a few minutes old.

A seconds-based comparison makes every request look ~55,000 years in the future, and the freshness check then silently passes everything.

X-Castro-Signature
string
header
required

HMAC-SHA256("{timestamp}.{rawBody}", api_key), lowercase hex.

rawBody is the exact bytes of the request body — empty for GET and DELETE, which therefore sign over "{timestamp}.". Hash the raw bytes, never a re-serialized copy of the parsed JSON: whitespace and key order differences will break the comparison for some payloads and not others, which reads as an intermittent bug.

Compare in constant time (crypto.timingSafeEqual, hash_equals, hmac.compare_digest).

Path Parameters

id
string
required

The id your server returned when the entity was created. Castro stores it verbatim and never rewrites it.

Body

application/json

The body of PUT /posts/{id} — a partial update. Any subset of the fields may arrive, and only those fields change. Everything you are not sent must keep its current value.

Three different Castro actions come through this one endpoint:

Treat the second as a full replace and you erase the user's title, categories, author and SEO. Nested objects follow the same rule — merge seo, don't replace it.

title
string
Example:

"10 Best Running Shoes in 2026"

content
string

Post body as HTML. The H1 is already stripped — render title as your page heading.

Example:

"<p>Choosing the right running shoe...</p>"

excerpt
string

Short summary / meta description text.

status
enum<string>
Available options:
publish,
draft
date
string

Publish datetime, YYYY-MM-DD HH:MM:SS.

Example:

"2026-07-03 14:22:01"

categories
string[]

Category NAMES. Create any that don't exist yet.

Example:
tags
string[]
Example:
author
string

Author display name.

Example:

"Jane Levy"

URL of the featured image, hosted by Castro.

reading_time
string
Example:

"5 minutes"

seo
object
source_id
string

Castro's internal content id — store it for idempotency.

Example:

"cnt_9f2ka83b"

Response

Post updated

id
string
required

Your id for the entity — any string; Castro stores it verbatim.

Maximum string length: 191
Example:

"8842"

url
string

Public URL of the entity (optional but recommended).

Example:

"https://your-site.com/blog/10-best-running-shoes"