Install: Cloudflare Worker
The Cloudflare Worker wall runs at the edge, in front of any site on Cloudflare. It's the most common form factor — one-click mount via OAuth, or drop-in via wrangler.
When to use
Your site is already behind Cloudflare (nameservers or CNAME setup). This is the only form factor with a live online path — the ledger and revocation checks that the self-hosted walls skip.
1. Connect your zone
In the dashboard, choose Cloudflare from the install picker and start the OAuth consent flow. Grant MotherShy access to the zone you want to protect.
2. Mount the worker
MotherShy mounts the wall as a Worker route on your zone. You can also do it manually:
npm install -g wrangler
git clone https://github.com/Oppentec/MotherShy
cd MotherShy/workerSet the env vars:
# wrangler.toml
[vars]
MOTHERSHY_ROOT = "<base64 Mother public root>"
MOTHERSHY_ORIGIN = "https://origin.example.com" # pass-through targetnpx wrangler deploy3. Pin the root
The wall verifies every X-MotherShy header against the pinned Mother public root. This is the one value that must be correct — get it from your dashboard, never hardcode a test root in production.
4. Verify
# human (browser) → 200
curl -A "Mozilla/5.0 … Chrome/120.0" https://example.com/ -o /dev/null -w "%{http_code}\n"
# agent (curl) → 402
curl https://example.com/ -o /dev/null -w "%{http_code}\n"
# search bot → 200
curl -A "Googlebot/2.1" https://example.com/ -o /dev/null -w "%{http_code}\n"Behavior
| Request | Result |
|---|---|
| Valid envelope, scoped to this site | Pass through to origin |
| Human / search bot (no header) | Pass through |
| AI agent (no header) | 402 → enroll |
| Malformed / tampered / wrong-site | 400 / 401 / 403 |