Skip to main content
POST
Create a product category

Authorizations

X-API-Key
string
header
required

The connection key the user generated in Jorge Castro (Settings → Integration → Custom Website). Reject any request whose key doesn't match yours.

X-Castro-Timestamp
string
header
required

Unix time in milliseconds when the request was signed — Castro uses Date.now(). Reject anything more than a few minutes old.

A seconds-based comparison makes every request look ~55,000 years in the future, and the freshness check then silently passes everything.

X-Castro-Signature
string
header
required

HMAC-SHA256("{timestamp}.{rawBody}", api_key), lowercase hex.

rawBody is the exact bytes of the request body — empty for GET and DELETE, which therefore sign over "{timestamp}.". Hash the raw bytes, never a re-serialized copy of the parsed JSON: whitespace and key order differences will break the comparison for some payloads and not others, which reads as an intermittent bug.

Compare in constant time (crypto.timingSafeEqual, hash_equals, hmac.compare_digest).

Body

application/json
name
string
description
string

Category body copy as HTML.

image
string

Image URL.

source_id
string

Response

Category created

id
string
required

Your id for the entity — any string; Castro stores it verbatim.

Maximum string length: 191
Example:

"8842"

url
string

Public URL of the entity (optional but recommended).

Example:

"https://your-site.com/blog/10-best-running-shoes"