Skip to content

Install: Cloudflare Worker ​

The Cloudflare Worker wall runs at the edge, in front of any site on Cloudflare. It's the most common form factor — one-click mount via OAuth, or drop-in via wrangler.

When to use

Your site is already behind Cloudflare (nameservers or CNAME setup). This is the only form factor with a live online path — the ledger and revocation checks that the self-hosted walls skip.

1. Connect your zone ​

In the dashboard, choose Cloudflare from the install picker and start the OAuth consent flow. Grant MotherShy access to the zone you want to protect.

2. Mount the worker ​

MotherShy mounts the wall as a Worker route on your zone. You can also do it manually:

bash
npm install -g wrangler
git clone https://github.com/Oppentec/MotherShy
cd MotherShy/worker

Set the env vars:

toml
# wrangler.toml
[vars]
MOTHERSHY_ROOT = "<base64 Mother public root>"
MOTHERSHY_ORIGIN = "https://origin.example.com"   # pass-through target
bash
npx wrangler deploy

3. Pin the root ​

The wall verifies every X-MotherShy header against the pinned Mother public root. This is the one value that must be correct — get it from your dashboard, never hardcode a test root in production.

4. Verify ​

bash
# human (browser) → 200
curl -A "Mozilla/5.0 … Chrome/120.0" https://example.com/ -o /dev/null -w "%{http_code}\n"

# agent (curl) → 402
curl https://example.com/ -o /dev/null -w "%{http_code}\n"

# search bot → 200
curl -A "Googlebot/2.1" https://example.com/ -o /dev/null -w "%{http_code}\n"

Behavior ​

RequestResult
Valid envelope, scoped to this sitePass through to origin
Human / search bot (no header)Pass through
AI agent (no header)402 → enroll
Malformed / tampered / wrong-site400 / 401 / 403

Next ​

MotherShy — the economic operating layer for AI agents and publishers.