Skip to content

Verify your domain ​

Before MotherShy issues your site's keys, it must prove you control the domain. This is a DNS TXT check — one record, standard, no origin changes.

Why it matters

The domain is the enforced audience in every capability. If MotherShy issued keys for a domain you don't control, an attacker could impersonate you and collect payments. Verification fails closed: no verified domain, no keys.

1. Register your site ​

In the dashboard → Register a site, enter your domain (e.g. example.com). MotherShy normalizes it to a canonical hostname:

text
https://Example.com/path → example.com
www.example.com          → www.example.com   (subdomains are distinct)

2. Add the TXT record ​

MotherShy returns a challenge token. Add this record at your DNS provider:

text
_mothershy.example.com   TXT   "mothershy-site-verification=<token>"

3. Verify ​

Click Verify. MotherShy queries DNS, confirms the record, and issues your site's keys and wall config.

Notes ​

  • TXT only — no HTTP fallback. The check proves routing control, which is what the aud binding protects. An HTTP /.well-known challenge proves only content-serving, not DNS control, and would admit a publisher with CMS access but no DNS rights.
  • Subdomains are distinct identities. www.example.com and example.com are verified separately. Linking them is a future "linked domains" feature.
  • A domain change creates a new site identity. Capabilities bound to the old hostname don't carry forward — this is correct fail-closed behavior.

Next ​

MotherShy — the economic operating layer for AI agents and publishers.