/handshake response includes a capabilities array. It tells Castro
which optional endpoints you implemented; Castro only ever calls what you
declared, and hides UI actions your integration can’t perform.
Capability reference
A connection is rejected unless
capabilities includes both
posts.create and posts.update.Changing capabilities later
Added an endpoint? Update your handshake response, then click Re-verify connection in Castro (Settings → Integration → Custom Website → Manage). Castro re-runs the handshake and refreshes the stored list: no key rotation needed.What happens without a capability
- Calls to undeclared operations are never sent; Castro returns a clear “not supported by this integration” message to the user instead.
- UI actions that depend on a missing capability are hidden or disabled
(e.g. no Delete button without
posts.delete).

