Skip to content

Install: Nginx / self-hosted (Go) ​

The self-hosted wall is a single Go binary you run in front of any backend — nginx, Apache, or anything else. It's the form factor for publishers who want full control and no platform dependency.

When to use

You self-host (VPS, bare metal, or your own container). Works as a reverse-proxy gate in front of any origin.

1. Build or download the binary ​

bash
git clone https://github.com/Oppentec/MotherShy
cd MotherShy
go build -o bin/wall ./cmd/wall

2. Run it in front of your origin ​

bash
./bin/wall \
  -root "<hex Mother public root>" \
  -site "example.com" \
  -origin "http://127.0.0.1:8080" \   # your app's origin
  -mode "agents-only" \               # or "all"
  -addr "127.0.0.1:8086"

The wall proxies humans and verified agents through to -origin, and returns 402 to un-enrolled agents.

3. Run it as a service ​

ini
# /etc/systemd/system/mothershy-wall.service
[Unit]
Description=MotherShy Wall (example.com)
After=network.target

[Service]
ExecStart=/usr/local/bin/wall -root <root-hex> -site example.com -origin http://127.0.0.1:8080 -addr 127.0.0.1:8086
Restart=always

[Install]
WantedBy=multi-user.target
bash
sudo systemctl enable --now mothershy-wall

4. Point nginx at it ​

nginx
location / {
    proxy_pass http://127.0.0.1:8086;
    proxy_set_header Host $host;
    proxy_set_header X-Forwarded-For $remote_addr;
}

5. Verify ​

bash
# human → 200, agent → 402, Googlebot → 200
curl -A "Mozilla/5.0 … Chrome/120.0" http://127.0.0.1:8086/ -o /dev/null -w "%{http_code}\n"
curl http://127.0.0.1:8086/ -o /dev/null -w "%{http_code}\n"
curl -A "Googlebot/2.1" http://127.0.0.1:8086/ -o /dev/null -w "%{http_code}\n"

Modes ​

ModeBehavior
agents-only (default)Humans + search bots pass free; only AI agents are gated
allEverything without a valid header is gated

Next ​

MotherShy — the economic operating layer for AI agents and publishers.