Provider Onboarding
This guide walks you through registering as a ShadowFeed data provider. Estimated time: 5 minutes for sign-up, 30 minutes to wire up your HMAC verifier (Partner Bridge mode only).Prerequisites
- A Stacks wallet installed: Leather or Xverse
- For Partner Bridge mode: an HTTPS endpoint you control (e.g.
https://api.yourcompany.com) - For Hosted Mirror mode: a public JSON URL or willingness to push data via webhook
Step 1 — Sign in with your Stacks wallet
1
Visit shadowfeed.app
Open shadowfeed.app in a browser with Leather or Xverse extension installed.
2
Connect wallet
Click Connect Wallet → choose Leather or Xverse → approve in the popup.
3
Sign-In With Stacks
Click Providers in the nav → Become a Provider. Sign the SIWS challenge — this proves wallet ownership without exposing your private key.
Your wallet address becomes your provider account identity. You can link a different wallet for withdrawals later if revenue should go elsewhere (multisig, treasury, etc.).
Step 2 — Profile (wizard step 1)
Step 3 — Integration mode (wizard step 2)
- Partner Bridge
- Hosted Mirror
Pick this if you already have a production API — including one you already gate with x402 on Solana, Base, or another EVM chain. You point ShadowFeed at the same endpoint; it bypasses your existing paywall with an HMAC signature (see Coexisting with your existing x402 paywall).Required: partner endpoint URL — an origin only, e.g.
https://api.yourcompany.com. No path, no trailing slash. The per-feed source_path (next step) is appended to this. Registering a path here (e.g. …/v1) is the most common cause of dead-on-arrival integrations.The wizard will generate an HMAC secret in step 4. Save it immediately — it’s shown once.Step 4 — Add your first feed (wizard step 3)
After submit, your provider goes from
pending to active and the feed is live at /feeds/p/your-handle/feed-slug.
Step 5 — Save your HMAC secret
This step only applies to Partner Bridge mode. The wizard’s success screen shows the secret once. It looks like:Step 6 — Where to put the HMAC secret
This is the most common point of confusion: on which server does the secret live? Answer: on the same server that hosts yourpartner_endpoint. Whatever domain/runtime serves the URL ShadowFeed will call.
The secret never gets put on ShadowFeed’s side as a user-facing config. We already store it as a hash for verification at signup time. You only manage it on your side.
- TypeScript / Node
- Cloudflare Workers
- Python
- Go
Step 7 — Link a withdrawal wallet
Before you can withdraw STX, you must link a destination wallet. This can be the same wallet you signed in with, or a different one (multisig, treasury).1
Open the warning banner
In the dashboard, click link one under the ”⚠ No linked withdrawal wallet” message.
2
Sign the linking challenge
The destination wallet signs a SIWS message proving ownership.
3
Verify
The dashboard now shows “Linked withdrawal: SP…”
Step 8 — Verify end-to-end
First, run the free handshake test — before spending any STX. In the dashboard click Test connection (POST /providers/id/:id/hmac/test), or npx shadowfeed verify --endpoint https://api.you.com --secret "$SHADOWFEED_PARTNER_SECRET" if you use the SDK. It signs a request with your stored secret against your first feed’s source_path and probes your endpoint exactly like a real buyer would — catching secret and path mismatches in seconds. Don’t activate until this returns ok. Full breakdown: HMAC Integration → Verify your wiring.
Then confirm the unpaid path returns a 402 challenge:
1
STX settles on platform
Agent’s STX transaction lands on the ShadowFeed platform wallet.
2
ShadowFeed forwards HMAC-signed request
Calls
partner_endpoint + source_path with X-Sf-* headers.3
Your middleware verifies + serves
Middleware validates signature, your route returns data.
4
Revenue credited
97% of the price lands in your
pending_revenue counter.5
Dashboard updates
Query log entry appears with TX hash linkable to Hiro Explorer.
Step 9 — Publish your discovery manifest
Publish a.well-known/shadowfeed-feeds.json file on your own domain. This is how marketplaces, partners, and grant reviewers independently confirm — from infrastructure you control — that you opted into ShadowFeed. ShadowFeed’s public verification endpoint (/providers/your-handle/manifest) fetches this file live and reports it under independence_attestation.well_known_manifest_present.
Using
@shadowfeed/provider-sdk? This file is generated and served for you automatically from your registered feeds — skip straight to the verification commands below. The manual work here only applies to hand-rolled Partner Bridge integrations.feeds[].path must match the source_path you registered in Step 4. If you cross-list on other marketplaces (x402scan, payai, etc.), add one entry per marketplace under partnerships so every partner can verify you from this single file.
Verify it’s detected:
What’s next
HMAC Integration Guide
Verifier code in TypeScript, Python, and Go — copy-paste ready.
Withdrawals & Revenue
Sign a withdrawal, link a wallet, view settlement history.
Troubleshooting
Common errors and how to fix them.
Provider dashboard
Live portal for managing feeds and revenue.