Skip to main content
PUT
Update a product

Authorizations

X-API-Key
string
header
required

The connection key the user generated in Jorge Castro (Settings → Integration → Custom Website). Reject any request whose key doesn't match yours.

X-Castro-Timestamp
string
header
required

Unix time in milliseconds when the request was signed — Castro uses Date.now(). Reject anything more than a few minutes old.

A seconds-based comparison makes every request look ~55,000 years in the future, and the freshness check then silently passes everything.

X-Castro-Signature
string
header
required

HMAC-SHA256("{timestamp}.{rawBody}", api_key), lowercase hex.

rawBody is the exact bytes of the request body — empty for GET and DELETE, which therefore sign over "{timestamp}.". Hash the raw bytes, never a re-serialized copy of the parsed JSON: whitespace and key order differences will break the comparison for some payloads and not others, which reads as an intermittent bug.

Compare in constant time (crypto.timingSafeEqual, hash_equals, hmac.compare_digest).

Path Parameters

id
string
required

The id your server returned when the entity was created. Castro stores it verbatim and never rewrites it.

Body

application/json

Copy-only product payload — no price, SKU or stock.

name
string
Example:

"Trail Runner X"

type
string
Example:

"simple"

description
string

Product body as HTML.

short_description
string
categories
string[]

Product category NAMES.

tags
string[]
images
object[]
status
enum<string>
Available options:
publish,
draft
source_id
string

Response

Product updated

id
string
required

Your id for the entity — any string; Castro stores it verbatim.

Maximum string length: 191
Example:

"8842"

url
string

Public URL of the entity (optional but recommended).

Example:

"https://your-site.com/blog/10-best-running-shoes"