Skip to content

How MotherShy works ​

One page, the whole mechanic. There are three moving parts: the trust chain, the wall, and the payment rail.

The trust chain (identity → authorization) ​

An agent proves who it is and that it's allowed to pay for this site with a single signed object — an envelope sent in an HTTP header.

The chain has two links, both verifiable offline against a pinned public root:

  1. Root → agent — the Mother derives the agent's key and signs its birth certificate (cert). This is the agent's identity.
  2. Agent → request — the agent signs the canonical request (site, timestamp, amount). This is the agent authorizing this specific access.

On top of that sits the capability (cap) — a scoped spend key minted by the Mother. It says: "this agent may spend up to N micro-USD at site S, until time T." The certificate is identity; the capability is authorization. A wall requires both.

text
Root ──(signs birth cert)──▶ Agent ──(signs request)──▶ Wall
                                 └──(presents scoped capability)──▶ Wall

The wall ​

A wall is a small piece of code a publisher drops in front of their existing site. It reads the X-MotherShy header on every request and makes one decision:

  • Valid envelope, scoped to this site → pass through to the origin (the agent is authenticated and authorized to pay).
  • No header → classify by User-Agent: humans and search bots pass free; un-enrolled AI agents get a 402 pointing them at enrollment.
  • Malformed / tampered / wrong-site → rejected fail-closed (400 / 401 / 403).

The wall is keyless and offline: it pins only the Mother's public root. It never phones home, never holds a secret, and can gate traffic even if MotherShy itself is unreachable.

The payment rail ​

When a gated agent is asked to pay, the money doesn't flow through MotherShy. The wall issues an x402 PAYMENT-REQUIRED challenge; the agent's funder settles funder → publisher over an existing rail (x402, MPP, or Pay Per Crawl). MotherShy earns on the subscription — never a cut of your content revenue.

text
Agent ──402 challenge──▶ Funder ──settle (USDC, on-chain)──▶ Publisher
                                └──▶ facilitator records tx

The six wall form factors ​

The wall's trust core is byte-for-byte identical across every environment. Publishers pick whichever matches their stack:

Form factorRuntimeBest for
Cloudflare WorkerV8 isolateSites already behind Cloudflare
WordPress pluginPHPWordPress sites
Node.js middlewareNodeExpress / Node apps
Nginx / Go binaryGoSelf-hosted, any backend
Vercel edgeV8/edgeNext.js on Vercel
Netlify edgeDenoSites on Netlify

See Install the wall for all six.

Next ​

MotherShy — the economic operating layer for AI agents and publishers.