Skip to main content
GET
List published pages

Authorizations

X-API-Key
string
header
required

The connection key the user generated in Jorge Castro (Settings → Integration → Custom Website). Reject any request whose key doesn't match yours.

X-Castro-Timestamp
string
header
required

Unix time in milliseconds when the request was signed — Castro uses Date.now(). Reject anything more than a few minutes old.

A seconds-based comparison makes every request look ~55,000 years in the future, and the freshness check then silently passes everything.

X-Castro-Signature
string
header
required

HMAC-SHA256("{timestamp}.{rawBody}", api_key), lowercase hex.

rawBody is the exact bytes of the request body — empty for GET and DELETE, which therefore sign over "{timestamp}.". Hash the raw bytes, never a re-serialized copy of the parsed JSON: whitespace and key order differences will break the comparison for some payloads and not others, which reads as an intermittent bug.

Compare in constant time (crypto.timingSafeEqual, hash_equals, hmac.compare_digest).

Query Parameters

per_page
integer
default:100

Items per page. Castro asks for 100.

page
integer
default:1

1-based page number. Castro keeps paging until it receives a page shorter than per_page, so a full final page must be followed by an empty one — otherwise it will keep asking.

Response

Page list (bare JSON array)

id
string
required
slug
string
required
url
string
title
string
type
string

Your own type label (post, product, page, ...). Castro maps the well-known ones onto its page classification: product -> Ecommerce Product Page, product_cat -> Ecommerce Category Page, category -> Category Page, post -> Blog Page. Anything else leaves Castro's own classification intact.

categories
string[]

Optional. Category names this page belongs to.

tags
string[]

Optional. Tag names on this page.