1 · Claim your API's entry
Find your API in the index (or submit it), hit Claim this API, and verify with an email on your domain (one click) or a DNS TXT record. The stamp flips to VERIFIED OWNER and the console unlocks.
2 · Start the storefront subscription
In the console (Owner? Manage it → White-label Storefront), start the $79/mo subscription. It includes Owner Pro for as long as the storefront is paid for. Promotion codes are entered on the Stripe checkout page. Activating a storefront means agreeing to the platform terms — in short: your buyers are your customers, we meter and issue keys.
3 · Create a Stripe restricted key
Your buyers pay you — checkout, subscriptions, and metering all run on your own Stripe account. In the Stripe dashboard: Developers → API keys → Create restricted key, and grant Write on exactly these:
| RESOURCE | ACCESS | WHY |
|---|---|---|
| Checkout Sessions | Write | buyer checkout |
| Products & Prices | Write | your metered price object |
| Billing Meters | Write | usage reporting |
| Subscriptions | Write | lapse detection |
| Customers | Write | buyer records |
| PaymentIntents | Write | top-up packs and auto top-up (one-off charges on a saved card) |
Everything else stays None. Paste the rk_live_… key into the storefront panel — it's encrypted at rest with a key the website itself can't read back out; only the billing task decrypts it. We never see your balance, payouts, or customers beyond what these scopes allow.
Tip for the less technical: the console has a built-in setup assistant (in the storefront panel) that walks you through every step and saves your settings as you chat — secrets go in its secure field, never the conversation. Or paste this page into Claude or ChatGPT, or ask Stripe's own AI assistant/MCP to "create a restricted key with write access to checkout sessions, products, prices, billing meters, subscriptions and customers."
4 · Configure and activate
Set your title, tagline, accent color, and your retail price per 1,000 requests. The origin your API actually lives at (with an upstream credential if your origin requires one — same encryption) is saved in the SELL HERE — THE GATEWAY panel; the storefront won't activate without it, because that is where buyers' calls go. Saving an origin does not list you for sale on the registry — that's the separate LIST FOR SALE HERE button, which is the marketplace channel with its 8% share. Hit Activate. Your storefront is live immediately at:
https://store.apidirectory.com/~your-slug/
4b · What each key gets, and where it stops
Three fields next to your price decide the shape of your plan:
| FIELD | MEANING |
|---|---|
| Included / mo | Requests each key gets before your per-1,000 price applies. Leave at 0 to bill every request. |
| Past that | Bill charges your rate for the overage. Stop returns HTTP 429 instead. Free tiers can only stop. |
| Hard cap / mo | An absolute ceiling per key — the gateway refuses past it even when you're billing overage. Blank means no ceiling. |
Combinations you'd actually use: free tier = included 10,000, stop. Pay as you go = included 0, bill, no cap — nothing ever stops a key. Plan with a safety net = included 100,000, bill, cap 500,000, so a customer's runaway script hits a wall instead of a five-figure invoice.
Periods run monthly from the day each key was issued, not from the calendar month. We email the buyer at 80% of their included volume and again when they hit the line; past a hard cap the gateway returns 429 quota_exceeded with the reset date. Every successful response carries X-Gw-Limit, X-Gw-Used, X-Gw-Remaining and X-Gw-Reset, so well-behaved clients — and AI agents — can throttle themselves before you have to refuse them.
4c · Brand, docs, try-it and usage
Everything below lives in the storefront's own configure area (sign in to your storefront with the owner email): one section per page — Brand, Domains, Billing, Gateway, Documentation, Plans, Usage, Assistant — with the status of each in the index on the left. Most of it is in the console panel too.
| THING | WHAT IT DOES |
|---|---|
| Logo | Upload a PNG, JPEG, WebP, GIF or SVG (or link an https URL). It replaces the colored square in the header, becomes the favicon, and heads every email your buyers get. Raster files are resized to fit 800×240; SVGs are accepted only when they carry no script or external references. Tick "my logo already includes the name" for a wordmark. |
| Generated reference | The default. From your OpenAPI/Swagger spec URL we build a full reference: every operation with parameters, request and response examples generated from your schemas, and curl / Python / JavaScript samples that already use your buyers' base URL and the X-API-Key header. Re-fetched daily; "re-fetch now" on save. |
| Your own docs | Set your docs URL and pick my own docs: the Docs link and the home page point at your site. Pick both to keep the generated reference with a link to your docs on it. |
| Try-it console | On the reference, every operation has a "Try it" form. A signed-in buyer's calls run through the real gateway to your origin on a sandbox key with a monthly cap you set (200 by default), so what they see is exactly what production returns. Switch it off per storefront if you'd rather not. |
| Usage | Configure → Usage: daily volume across every key, top buyers, plan mix, keys near their ceiling, an estimate of recurring plus overage revenue (Stripe stays the truth), and per-route calls, error share and latency as measured by the gateway. CSV export of the daily series. |
4d · MCP server for AI agents (add-on, $29/mo)
Switch it on in Configure → MCP server and your storefront answers the Model Context Protocol at …/mcp — on your own portal domain once that is live, or at the root of a dedicated MCP domain (mcp.yourdomain.com, see custom domains below). Every operation in your spec becomes a tool, named after its operationId, with parameters and body taken from its schemas, plus a generic request tool for anything not listed. You tick which operations to expose (up to 50) and can write notes every agent reads on connect. Buyers add the endpoint to Claude Code, Cursor or any MCP client with their key as a bearer token; each tool call runs through the gateway on that key, so it is metered, capped and billed exactly like a curl and shows on your usage page. A client with nowhere to put a header — a claude.ai connector takes a URL and nothing else — connects to …/mcp/k/<key>, the same endpoint with the key built into the URL. Agents that discover your API through the registry's own MCP server get the endpoint together with their key. The add-on is a line on your storefront subscription, prorated; switch it off any time.
5 · Custom domains (optional)
Three hostnames, all optional, all fully automatic:
| FIELD | EXAMPLE | WHAT IT SERVES |
|---|---|---|
| Portal domain | developers.yourdomain.com | your docs, checkout, and status pages |
| API domain | api.yourdomain.com | the metered endpoint your buyers call — replaces gw.apidirectory.com/your-slug/ in every code sample and key email |
| MCP domain | mcp.yourdomain.com | the MCP server add-on at its own address — the whole host answers the protocol, agents connect to its root; without one the portal serves it at /mcp |
Enter a hostname in the panel, then add a CNAME for it pointing to domains.apidirectory.com at your DNS provider. The TLS certificate issues automatically and the console flips the domain to LIVE within minutes of the record propagating — no ticket, no waiting on us. Keys work on both the branded host and the shared gateway host, so nothing breaks if you add the domain later.
Notes: a root domain (no subdomain) needs a DNS provider with CNAME flattening or ALIAS records. If your domain's DNS is hosted on Cloudflare, create the record as DNS only (grey cloud), not proxied.
How the money and the calls flow
Buyer pays on your Stripe → we mint them a key → they call gw.apidirectory.com/your-slug/… → the gateway checks the key, enforces limits, meters the request, and proxies to your origin → once a day we report usage to your Stripe meter, which bills them on your behalf. Your revenue never routes through us; your $79/mo is the only thing you pay us.
Setting your price to $0.00 makes the storefront a free tier: keys are issued instantly with no card and no Stripe key needed — the gateway still meters and rate-limits every call.
Fair-use note: ~5M gateway requests/month included; beyond that we'll talk about a few dollars per extra million — never a revenue share.
If your origin is behind Cloudflare
Bot protection can 403 gateway traffic. Add a WAF skip rule for requests carrying the header X-Forwarded-By: apidirectory-gateway.