Skip to content

Go live checklist ​

Before you consider your wall production-ready, run through this.

Configuration ​

  • [ ] Pinned root is the real Mother public root — not a test root. This is the one value that must be correct; a wrong root fails closed (rejects everything) or, worse, trusts the wrong authority.
  • [ ] siteId matches your verified domain exactly — the canonical hostname, no scheme, no path.
  • [ ] payTo is your address, on the network/asset you configured (default USDC Base Sepolia).

Traffic ​

  • [ ] Human browser → 200 (content serves)
  • [ ] Googlebot / link-preview bots → 200 (free pass)
  • [ ] curl / GPTBot → 402 (gated)
  • [ ] Valid scoped envelope → 200 (agents pass)
  • [ ] Cross-site envelope → 403 (rejected)
  • [ ] Malformed envelope → 400 (rejected)

Self-hosted extras ​

  • [ ] The wall runs as a service (systemd, PM2, container) with Restart=always — not a foreground process.
  • [ ] Static assets are excluded (never gated) — CSS/JS/images must load for humans.
  • [ ] Your origin is reachable from the wall (proxy target is correct).

Security ​

  • [ ] Your signing key never leaves your machine. MotherShy holds only your public key.
  • [ ] The site_secret (HMAC) is stored safely and shown only once.
  • [ ] Fail-closed behavior is acceptable: if the wall can't verify, it blocks agents — it never leaks content.

Staging first ​

You can exercise the entire loop on staging + testnet with zero real money: login, domain verification, wall mount, price, and settlement (Base Sepolia USDC). Production is only required for live Stripe/Auth0 and mainnet settlement.

Verified against real traffic

Every wall form factor has been proven against live origins — human 200, agent 402, Googlebot 200, plus the full signed-envelope matrix. The gating behavior is identical across all six.

Next ​

MotherShy — the economic operating layer for AI agents and publishers.