Skip to main content
Your /handshake response includes a capabilities array. It tells Castro which optional endpoints you implemented; Castro only ever calls what you declared, and hides UI actions your integration can’t perform.

Capability reference

A connection is rejected unless capabilities includes both posts.create and posts.update.

Changing capabilities later

Added an endpoint? Update your handshake response, then click Re-verify connection in Castro (Settings → Integration → Custom Website → Manage). Castro re-runs the handshake and refreshes the stored list: no key rotation needed.

What happens without a capability

  • Calls to undeclared operations are never sent; Castro returns a clear “not supported by this integration” message to the user instead.
  • UI actions that depend on a missing capability are hidden or disabled (e.g. no Delete button without posts.delete).