Integration guide
Connect your website and let Rankonpilot send a new article every day
This page shows the full process: how to add your site, wire a receiving endpoint, verify signatures, test the connection, and turn on automatic daily publishing.
Last updated
Key points
- Articles reach your site as JSON through a signed webhook: an HTTPS endpoint on your site that you or a developer add once. There's no WordPress, Webflow or Ghost plugin yet; those are planned.
- Each request is signed with HMAC-SHA256 in the X-RankOnPilot-Signature header. Check it against the raw body with your signing secret before saving anything.
- Approved keywords are scheduled one per day, at the UTC hour you choose for each website.
- With Auto-publish on, articles go to your site as soon as they're written. With it off, they wait in the dashboard for your review.
- Your endpoint must answer with a 2xx status within 30 seconds at the exact URL you entered, because redirects aren't followed.
- After a post goes live, Rankonpilot notifies search engines through IndexNow and resubmits your sitemap in Search Console, if you've connected it.
How an article reaches your site
Rankonpilot writes the article
At the daily hour you set for the website, it writes the article for the next approved keyword, with its images.
It signs the article and sends it
With Auto-publish on, the article goes to your endpoint as JSON as soon as it's written, signed with HMAC-SHA256. With it off, it goes when you publish it.
Your site saves the post
Your endpoint checks the signature, creates or updates the post, and answers with a 2xx status within 30 seconds.
Search engines hear about it
Rankonpilot notifies IndexNow and, if you've connected Search Console, resubmits your sitemap there.
Automatic daily flow
With Auto-publish on, each scheduled article is published as soon as it's written: your endpoint receives it with status "published". Rankonpilot then notifies search engines through IndexNow and resubmits your sitemap in Search Console, if you've connected it.
Review before publishing
Turn Auto-publish off to check articles first. Finished articles then wait in the dashboard. Open one in the editor, change what you need and publish it yourself.
One scheduled keyword per day
When you approve multiple keywords, Rankonpilot schedules them sequentially, one per day, starting from the website's configured UTC hour.
Full connection process
Follow these steps once per website. After the connection is tested, Rankonpilot can publish a new article every day without any manual upload work.
1. Add your website
Create a workspace, open New website, then enter your site URL, niche, target audience, tone, language, and optional sample article URLs.
2. Choose the daily schedule
Pick the hour for the daily posting slot, in UTC (Coordinated Universal Time, the same clock everywhere). Approved keywords are scheduled one per day at that hour.
3. Build a receiving endpoint
Create a webhook: an HTTPS URL on your site or CMS that Rankonpilot sends each article to as JSON. It should check the HMAC signature (a code computed from the request body with your signing secret, which proves the request came from Rankonpilot), then save the article, or update it when the same article id arrives again.
4. Add the integration in Rankonpilot
Go to Dashboard > Integrations, choose the website, paste the webhook URL and add the signing secret. If your endpoint requires it, also add a bearer token: a fixed password sent in the Authorization header.
5. Send a test payload
Use Send test to check your receiver before going live. Rankonpilot sends a sample article with the same headers and JSON shape used in production, marked with status "draft".
6. Turn on daily automation
Enable Auto-publish on the website. From then on, each scheduled article is published automatically when it's ready: it goes to your active integrations with status "published". Tick Auto-push drafts on an integration when you want only specific destinations to receive scheduled articles.
What your endpoint receives
Rankonpilot currently ships a generic webhook adapter. Your receiver should accept a POST request, check the signature against the raw JSON body, then create the post, or update it when the same article id arrives again. The status field is "published" for articles sent by Auto-publish or the Publish button, and "draft" for test payloads.
HTTP headers
| Header | Value |
|---|---|
| Content-Type | application/json |
| X-RankOnPilot-Signature | hex HMAC-SHA256 of the raw JSON body |
| X-RankOnPilot-Event | article.publish |
| X-RankOnPilot-Article-Id | The Rankonpilot article id |
| Authorization | Bearer <token> when you configured an optional bearer token |
Example payload
{
"event": "article.publish",
"status": "published",
"sentAt": "2026-05-16T21:00:00.000Z",
"website": {
"url": "https://example.com"
},
"article": {
"id": "cmp8k780l00019w490v1213q3",
"title": "How to Improve B2B SaaS Onboarding Conversion",
"slug": "how-to-improve-b2b-saas-onboarding-conversion",
"metaDescription": "A practical guide to improving onboarding conversion.",
"body": "<h2>...</h2><p>...</p>",
"faq": [],
"headings": [{ "level": 2, "text": "Why onboarding conversion matters" }],
"keywords": ["b2b saas onboarding conversion"],
"featuredImage": "https://res.cloudinary.com/...png",
"wordCount": 1287,
"readingTime": 6
}
}Example Next.js receiver
This example checks the HMAC signature with a timing-safe comparison and returns an external URL that Rankonpilot can store on the article record.
import crypto from "node:crypto";
import { NextRequest, NextResponse } from "next/server";
function signatureMatches(secret: string, rawBody: string, signature: string) {
const expected = crypto.createHmac("sha256", secret).update(rawBody).digest();
const received = Buffer.from(signature, "hex");
return received.length === expected.length && crypto.timingSafeEqual(received, expected);
}
export async function POST(req: NextRequest) {
const rawBody = await req.text();
const signature = req.headers.get("x-rankonpilot-signature") ?? "";
const secret = process.env.RANKONPILOT_SIGNING_SECRET ?? "";
if (!secret || !signatureMatches(secret, rawBody, signature)) {
return NextResponse.json({ error: "invalid signature" }, { status: 401 });
}
const payload = JSON.parse(rawBody);
// Create the post, or update it if this article id was sent before.
// payload.status is "published" (auto-publish or the Publish button)
// or "draft" (test payloads).
// Fields you usually store:
// payload.article.id
// payload.article.title
// payload.article.slug
// payload.article.metaDescription
// payload.article.body
// payload.article.featuredImage
return NextResponse.json({ ok: true, externalUrl: "https://example.com/blog/" + payload.article.slug });
}Questions about connecting your site
Does Rankonpilot work with WordPress?
Not through a plugin yet: WordPress, Webflow and Ghost integrations are planned. Today you connect WordPress the same way as any other site, with an endpoint that receives the signed webhook and creates the post, for example a small custom plugin or a REST API route.
Do I need a developer to connect my site?
Yes, once. Someone has to add an HTTPS endpoint that checks the signature and saves each article, and the example receiver on this page is a starting point. After that, articles arrive on their own every day.
Can I connect more than one website?
Yes. Every plan includes unlimited websites, and each website has its own webhook, daily publishing time and Auto-publish setting. Add each site from New website in the dashboard and connect its endpoint the same way.
What happens if I edit an article after it's published?
Edit it in the dashboard and publish it again. Rankonpilot sends the updated article to your endpoint with the same article id, so your receiver should update the existing post rather than create a new one.
Do articles include images?
Yes. Each article comes with 4 images: the featured image URL is its own field in the JSON, and the other images are already placed in the HTML body. All of them are hosted on Cloudinary, so your site only has to display them.
Ready to connect your site?
Start with one website, send a test payload, and turn on daily publishing once your receiver is saving articles correctly.
