Security
The connection key lives server-side only
Signatures are verified over the raw request bytes
Signature comparison is constant-time
crypto.timingSafeEqual in Node, hash_equals in PHP,
hmac.compare_digest in Python. A plain === leaks the signature one byte
at a time.Stale requests are rejected
X-Castro-Timestamp more than a few minutes old. Remember it’s
milliseconds.Your endpoints are HTTPS
http:// base URL, but the key travels in a header,
don’t send it in the clear.Correctness
PUT is partial, everywhere
seo object. Only the
fields present in the body change.source_id is stored and indexed
The id you return is stable
Categories, tags and authors are created if they don't exist
The title isn't rendered twice
content arrives with the H1 already stripped. Render title as the heading
yourself.A failure returns a non-2xx and a human-readable `error`
Capabilities
You declared exactly what you built
You re-verified the connection after adding an endpoint
Page sync
Only if you declaredpages.list:
GET /pages returns absolute, canonical URLs
Drafts are excluded
Pagination terminates
per_page, or Castro will keep asking.You publish a sitemap.xml
Operations
You tested against staging, not production
You know where the logs are
You have a key rotation plan

