Private RSS Feed
Serve a private RSS feed from a Cloudflare Worker: token-gated, 404-disguised, never a static file.
- What
- Serve a private RSS feed from a Cloudflare Worker: token-gated, 404-disguised, never a static file.
- Cost
- Free
- Needs
- Serve a private RSS feed from your Cloudflare Worker in five steps. You need: a Worker with a database binding and a secrets table.
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
The Private RSS Feed serves a feed that must stay private: internal changelogs, subscriber-only updates, personal briefings. It is served live from a Cloudflare Worker, gated by a per-feed secret token, never as a static file and never linked with an autodiscovery link tag. A wrong or missing token gets a quiet 404, indistinguishable from "no feed here". The handler reads ?token= from the query string, compares it against the secret stored in the worker's secrets table using a constant-time comparison, and returns 404 'Not found' as plain text on any mismatch. There is no "token exists but wrong" vs "no token" distinction: both are the same 404. A valid token builds the feed live from the database (latest N items, newest first, RFC-2822 dates, XML-escaped content) with a private Cache-Control header so shared caches never store a tokened feed. Because the feed is private, it can carry subscriber-only lines a public feed never would, like yesterday-vs-day-before traffic or unpublished counts. These stay clearly useful and never sensitive. If the stats query errors, the feed still returns valid without the private line: fail-open on extras, never fail-closed on the feed itself. Hygiene is the whole game: no static feed.xml in the build output (one deploy away from being public), no autodiscovery link tag, no token in URLs shared publicly. If the token leaks, you regenerate it with openssl rand -hex 32, update the secret store, redeploy (Pages binds secrets at deploy time), and hand the subscriber the new URL. Never reuse a leaked token.
Version:
Install
Copy the install package below, then paste it into MuseCommunity-built. Skill Harbor doesn't audit code — review the source before installing.
Serve a private RSS feed from your Cloudflare Worker in five steps. You need: a Worker with a database binding and a secrets table. 1. Secret: generate with openssl rand -hex 32 and store it (e.g. D1 app_secrets key 'feed'). Keep a private copy for your own health-check jobs. Never commit it. 2. Route: handle GET /feed.xml (and localized variants) live in the worker. Read ?token= from the query string and compare against the stored secret in constant time (compare every byte, no early exit, and treat length mismatch as failure). 3. On mismatch, return 404 'Not found' as plain text with no hint a feed exists. On match, query the latest N published items and build valid RSS 2.0: XML-escape all content (&, <, >, quotes), RFC-2822 dates, newest first, Content-Type application/rss+xml, Cache-Control private. 4. Optional private extras: add subscriber-only lines a public feed never would (traffic yesterday vs day before, unpublished counts). If the stats query fails, return the feed without the line. 5. Hygiene: no static feed.xml in the build output, no <link rel="alternate"> autodiscovery tag, no token in publicly shared URLs. If the token leaks: regenerate, update the secret store, redeploy (Pages binds secrets at deploy time), hand the subscriber the new URL. Verify: curl without token (expect 404), with a wrong token (expect the same 404), with the right token (expect valid RSS).
Saved to your recent installs. Find it anytime on /connect.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.