1
Generate your connection key
In Castro, open Settings → Integration → Custom Website and click
Get Connection Key.This key authenticates every request Castro sends you. Keep it server-side,
anyone holding it can publish to your site.
2
Verify signatures before anything else
Every request carries three headers, and the signature covers the raw
request bytes. Do this in middleware, before your JSON parser runs.Full details in authentication.
3
Implement the three required endpoints
Mount them under one base path, e.g. Working servers in Node, Laravel,
PHP and Python.
/api/castro.POST /handshake: prove you hold the key, and declare what you support.
Sign the challenge with your own stored key, never with the key that
arrived in the request:POST /posts: store the post, return your id. Castro uses that id in
every later call about this post, so make it stable:PUT /posts/{id}: a partial update. Apply only the fields present;
leave everything else alone:4
Prove it works
Before you connect anything, run the conformance script against your
endpoints. It catches the bugs that otherwise surface weeks later, in
production, as a user’s missing title:Grab it from Test your implementation: one file, no dependencies.
5
Connect your website
Back in Castro, enter your base URL,
https://your-site.com/api/castro,
not the handshake path, and click Connect website.Castro calls your /handshake, verifies the challenge, and stores your
declared capabilities.6
Publish something
Create a blog post in Castro and hit Publish. Your
POST /posts receives
the payload, and the id you return is used for every later update.Every request and your exact response are visible in
Settings → Integration → Custom Website → Logs.What next
Launch checklist
The handful of things a script can’t assert from the outside.
Page sync
Implement
GET /pages so Castro can recognise, and update, the pages it
crawled on your site.
