Skip to main content
POST
Verify the connection

Authorizations

X-API-Key
string
header
required

The connection key the user generated in Jorge Castro (Settings → Integration → Custom Website). Reject any request whose key doesn't match yours.

X-Castro-Timestamp
string
header
required

Unix time in milliseconds when the request was signed — Castro uses Date.now(). Reject anything more than a few minutes old.

A seconds-based comparison makes every request look ~55,000 years in the future, and the freshness check then silently passes everything.

X-Castro-Signature
string
header
required

HMAC-SHA256("{timestamp}.{rawBody}", api_key), lowercase hex.

rawBody is the exact bytes of the request body — empty for GET and DELETE, which therefore sign over "{timestamp}.". Hash the raw bytes, never a re-serialized copy of the parsed JSON: whitespace and key order differences will break the comparison for some payloads and not others, which reads as an intermittent bug.

Compare in constant time (crypto.timingSafeEqual, hash_equals, hmac.compare_digest).

Body

application/json
challenge
string
required

Random hex string to sign with your API key.

Example:

"3f9a1c62b6d94f0e8a17c54b9d2e6f38a1b0c9d8e7f6a5b4c3d2e1f009876543"

Response

Connection accepted

capabilities
enum<string>[]
required

Which endpoints you implemented. MUST include posts.create and posts.update.

Available options:
posts.create,
posts.update,
posts.delete,
blog_categories,
authors,
products,
product_categories,
seo,
pages.list
challenge_response
string
required

HMAC-SHA256 of the challenge, keyed with your API key, lowercase hex.

name
string

Your integration's display name.

Example:

"Acme Store Backend"

version
string
Example:

"1.0"