← Search

Private RSS Feed
Founder Web
⚙ Needs: Serve a private RSS feed from your Cloudflare Worker…

Private RSS Feed

Serve a private RSS feed from a Cloudflare Worker: token-gated, 404-disguised, never a static file.

At a glance
What
Serve a private RSS feed from a Cloudflare Worker: token-gated, 404-disguised, never a static file.
Cost
Free
Needs
Serve a private RSS feed from your Cloudflare Worker in five steps. You need: a Worker with a database binding and a secrets table.
Install
Copy the installer prompt below into your Muse — your agent does the rest.

Version:

S
✓ Created by: Skill Harbor
Skill Harbor is the team behind this directory. Founder listings — verification done in-house, free for a limited time.
⌁

Install

Copy the install package below, then paste it into Muse
Before you install

Community-built. Skill Harbor doesn't audit code — review the source before installing.

How to install a skill →

Serve a private RSS feed from your Cloudflare Worker in five steps. You need: a Worker with a database binding and a secrets table. 1. Secret: generate with openssl rand -hex 32 and store it (e.g. D1 app_secrets key 'feed'). Keep a private copy for your own health-check jobs. Never commit it. 2. Route: handle GET /feed.xml (and localized variants) live in the worker. Read ?token= from the query string and compare against the stored secret in constant time (compare every byte, no early exit, and treat length mismatch as failure). 3. On mismatch, return 404 'Not found' as plain text with no hint a feed exists. On match, query the latest N published items and build valid RSS 2.0: XML-escape all content (&, <, >, quotes), RFC-2822 dates, newest first, Content-Type application/rss+xml, Cache-Control private. 4. Optional private extras: add subscriber-only lines a public feed never would (traffic yesterday vs day before, unpublished counts). If the stats query fails, return the feed without the line. 5. Hygiene: no static feed.xml in the build output, no <link rel="alternate"> autodiscovery tag, no token in publicly shared URLs. If the token leaks: regenerate, update the secret store, redeploy (Pages binds secrets at deploy time), hand the subscriber the new URL. Verify: curl without token (expect 404), with a wrong token (expect the same 404), with the right token (expect valid RSS).

?

Questions

How do I install a build?

Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.

Where does my money go?

Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.

What does the ✓ next to a creator’s name mean?

It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.