creator program · invite-only betaprogramma creator · beta su invito
Sell your Claude Code kits to people who never open GitHub.Vendi i tuoi kit per Claude Code a chi non apre mai GitHub.
Two audiences, one page: developers read the code, everyone else reads the plain version. Switch the view at the top.Due pubblici, una pagina: chi sviluppa legge il codice, tutti gli altri la versione semplice. La vista si cambia in alto.
Students, freelancers, professionals and small businesses across Italy and Europe buy a code, run one command and have a working tool in ten minutes. You sell through your own Stripe or Polar and the money lands in your account. IOD21 keeps 10%; founding creators 5%, for life.Studenti, freelance, professionisti e piccole imprese in Italia e in Europa comprano un codice, lanciano un comando e in dieci minuti hanno uno strumento che funziona. Vendi col tuo Stripe o Polar e i soldi arrivano sul tuo conto. IOD21 trattiene il 10%; i founding creator il 5%, a vita.
- 244/244 tests passing244/244 prove superate
- 52 red-team attacks, 0 bypasses52 attacchi di red team, 0 bypass
- EU · fra1UE · fra1
// in plain wordsin parole semplici
Your customer pastes a code. Ten minutes later everything is installed, and it works.Il tuo cliente incolla un codice e in dieci minuti ha tutto installato, funzionante.
No GitHub, no npm, no setup guide. The code works on up to two computers, and only for the person who paid.Niente GitHub, niente npm, niente guide d'installazione. Il codice vale su due computer al massimo, e solo per chi ha pagato.
translatestraduce node kit.mjs attiva --codice IOD-…
- kit.mjs
- one file, Node built-ins onlyun file, solo moduli di Node
- 2
- computers per codecomputer per codice
- 1-30
- modules per kitmoduli per kit
- 2 MB
- per kit, 200 files maxper kit, massimo 200 file
- 24-48 h
- human reviewrevisione umana
- fra1
- Frankfurt, data in the EUFrancoforte, dati in UE
the pathil percorso
Three steps: apply, publish, get paid.Tre passi: ti candidi, pubblichi, incassi.
- 01
ApplyCandidati
Two minutes: who you are and what you want to publish. A person replies, and if your kit fits the catalog you get an invite.Due minuti: chi sei e cosa vuoi pubblicare. Risponde una persona e, se il kit fa per il catalogo, ricevi l'invito.
Apply as a creatorCandidati come creator - 02
PublishPubblica
Upload your kit with its kit.json from your dashboard. The automatic check answers in seconds, the human review within 24 to 48 hours.Carichi il kit con il suo kit.json dal tuo pannello. Il controllo automatico risponde in pochi secondi, la revisione di una persona entro 24-48 ore.
How publishing worksCome si pubblica - 03
Get paidIncassa
Customers pay on your own Stripe or Polar and the money goes to you. We invoice our share once a month: 10%, founding creators 5%.I clienti pagano sul tuo Stripe o Polar e i soldi arrivano a te. La nostra quota la fatturiamo una volta al mese: 10%, founding creator 5%.
How you get paidCome incassi
01how it workscome funziona
From a folder on your laptop to a sale, in seven steps.Da una cartella sul tuo computer a una vendita, in sette passi.
The protocol as it actually runs, next to the same seven steps in plain words. The numbers match.Il protocollo come gira davvero, accanto agli stessi sette passi in parole semplici. I numeri corrispondono.
- 1POST /api/kits/upload → /api/creator/pubblicazip from your dashboard: kit.json + fileszip dal tuo pannello: kit.json + file
- 2controllo.js → review queueseconds, then 24-48 hsecondi, poi 24-48 h
- 3POST /api/admin/revisionapackage · sign Ed25519 · listimpacchetta · firma Ed25519 · pubblica
- 4GET /api/catalogo/:slug/startersigned free starterstarter gratuito firmato
- 5checkout · Stripe | Polaryour account, your priceil tuo conto, il tuo prezzo
- 6POST /api/webhook/creator/:slug → POST /api/attivacode with your prefix · max 2 computerscodice col tuo prefisso · massimo 2 computer
- 7charge.refunded · order.refundedlicence revoked · updates: changed modules onlylicenza revocata · aggiornamenti: solo i moduli cambiati
// the same, in plain wordslo stesso, in parole semplici
- You publish. Put your kit in a folder with a short description file and send it from your dashboard.
- A machine checks it, then a person reads it. The automatic check answers in seconds. A reviewer at IOD21 reads everything within 24 to 48 hours.
- Approved and signed. We package your kit, sign it and list it in the catalog.
- Free demo. Anyone can try the free part of your kit before buying.
- You sell, you get paid. Customers pay on your own Stripe or Polar page. The money goes straight to you.
- The code arrives. We email the customer an unlock code with your prefix. One command and the full kit is installed.
- Updates and refunds take care of themselves. New versions reach customers on their own. A full refund switches the licence off; a cancelled subscription only stops future updates.
- Pubblichi. Metti il kit in una cartella con un breve file di descrizione e lo carichi dal tuo pannello.
- Lo controlla una macchina, poi lo legge una persona. Il controllo automatico risponde in pochi secondi. Un revisore di IOD21 legge tutto entro 24-48 ore.
- Approvato e firmato. Impacchettiamo il kit, lo firmiamo e lo mettiamo nel catalogo.
- Demo gratuita. Chiunque può provare la parte gratuita del tuo kit prima di comprare.
- Vendi e incassi tu. I clienti pagano sulla tua pagina Stripe o Polar. I soldi arrivano direttamente a te.
- Arriva il codice. Mandiamo al cliente un codice di sblocco con il tuo prefisso. Un comando e il kit completo è installato.
- Aggiornamenti e rimborsi vanno da soli. Le versioni nuove arrivano ai clienti da sole. Un rimborso totale spegne la licenza; una disdetta ferma solo gli aggiornamenti futuri.
translatestraduce POST /api/kits/upload POST /api/attiva
02one manifestun manifesto
One manifest. We handle the rest.Un manifesto. Al resto pensiamo noi.
kit.json is the whole interface: what the kit is, what it costs, where every file lands. Upload a zip from your dashboard; the same check runs on our side.kit.json è tutta l'interfaccia: cos'è il kit, quanto costa, dove finisce ogni file. Carichi uno zip dal pannello; lo stesso controllo gira da noi.
{
"nome": "Kit Gelateria",
"slug": "kit-gelateria",
"versione": "1.0.0",
"prezzo_centesimi": 2900,
"valuta": "EUR",
"prefisso_codice": "GELA",
"descrizione": "Agents and commands to run a gelato shop.",
"link_acquisto": "https://buy.polar.sh/…",
"prodotto_fornitore": "<your Polar product id>",
"piano": "file",
"domini": [
"gelateria-esempio.it"
],
"hook": false,
"starter": [
"starter/CLAUDE.md",
"starter/STATO.md"
],
"moduli": [
{
"nome": "agenti",
"titolo": "Shop agents",
"file": [
".claude/agents/gelato-assistente.md",
".claude/commands/gelato-report.md"
]
},
{
"nome": "strumenti",
"titolo": "Tools",
"file": [
".claude/skills/gelato-skill/SKILL.md",
"moduli/gelato/README.md",
"moduli/gelato/conta.sh"
]
}
]
}- slug
- 3-40 chars, lowercase, digits, hyphens. Yours for good.3-40 caratteri, minuscole, cifre, trattini. Resta tuo per sempre.
- versione
- 1.0.0 form; every upload must be higher.forma 1.0.0; ogni invio deve essere più alto.
- prefisso_codice
- 2-8 letters A-Z, unique, permanent: IOD-GELA-XXXXX-…2-8 lettere A-Z, unico, permanente: IOD-GELA-XXXXX-…
- prezzo_centesimi
- catalog only. The real price is on your checkout.solo per il catalogo. Il prezzo vero è sul tuo checkout.
- domini
- every domain your files reference; anything else is rejected.ogni dominio citato nei tuoi file; il resto viene rifiutato.
- hook
- true only if modules ship Claude Code hooks; read line by line.true solo se i moduli hanno hook di Claude Code; letti riga per riga.
- starter
- the free version, under starter/. Required.la versione gratuita, in starter/. Obbligatoria.
- moduli
- 1-30. Files land only in .claude/agents, commands, skills, workflows and moduli/.da 1 a 30. I file finiscono solo in .claude/agents, commands, skills, workflows e moduli/.
// in plain wordsin parole semplici
Describe your kit in one file. We do the rest.Descrivi il tuo kit in un file, noi facciamo il resto.
- Name, price, and where each file goes on the customer's computer.
- A free version is required, so people can try before they pay.
- Your files stay yours. We only check, package and deliver them, and you can sell them elsewhere too.
- Nome, prezzo e dove va ogni file sul computer del cliente.
- Una versione gratuita è obbligatoria, così chi compra prova prima di pagare.
- I tuoi file restano tuoi. Noi li controlliamo, li impacchettiamo e li consegniamo, e puoi venderli anche altrove.
translatestraduce kit.json
- ×scarica-ed-eseguicurl | sh · wget | bash · bash <(curl …) · base64 -d | shcurl | sh · wget | bash · bash <(curl …) · base64 -d | sh
- ×sudosudo or doas, even inside a READMEsudo o doas, anche dentro un README
- ×claude-homeanything touching ~/.claudetutto ciò che tocca ~/.claude
- ×fuori-progettowrites outside the buyer's project folderscritture fuori dalla cartella del progetto del cliente
- ×persistenzalaunchctl · crontab · ~/.zshrc · ~/.sshlaunchctl · crontab · ~/.zshrc · ~/.ssh
- ×chiave-incorporata14 key and token formats: Anthropic, OpenAI, Stripe, GitHub, AWS, Telegram, private keys…14 formati di chiavi e token: Anthropic, OpenAI, Stripe, GitHub, AWS, Telegram, chiavi private…
- ×dominio-non-dichiaratoURLs to domains missing from "domini"indirizzi verso domini assenti da "domini"
- ×caratteri-di-controlloANSI escapes, bidi overrides (Trojan Source)sequenze ANSI, inversioni bidi (Trojan Source)
- ×settings-json · svg-attivono settings.json, no SVG with scripts, hooks only if declaredniente settings.json, niente SVG con script, hook solo se dichiarati
- !prompt-injection · caratteri-invisibiliflagged for the reviewer, not auto-rejectedsegnalati al revisore, non rifiutati in automatico
// in plain wordsin parole semplici
Anything dangerous is stopped before a person even looks at it.Tutto ciò che è pericoloso si ferma prima ancora che una persona lo guardi.
- Nothing that downloads programs from the internet and runs them.
- No requests for administrator rights, no passwords or keys hidden in the files.
- Nothing that touches the customer's computer outside the project folder.
- Then a person reads every instruction the way Claude Code would follow it.
- Niente che scarichi programmi da internet e li esegua.
- Nessuna richiesta di permessi da amministratore, nessuna password o chiave nascosta nei file.
- Niente che tocchi il computer del cliente fuori dalla cartella del progetto.
- Poi una persona legge ogni istruzione come la seguirebbe Claude Code.
translatestraduce POST /api/kits/upload controllo.js
03how it's builtcome è costruito
Built to be checked, not believed.Fatto per essere verificato, non creduto.
Every number below comes from the v1 test suite and the red-team report. Ask and we send you both.Ogni numero qui sotto viene dalla suite di prove e dal report di red team della v1. Chiedili e te li mandiamo.
// in plain wordsin parole semplici
We tried to break it before giving it to customers.Lo abbiamo provato a rompere prima di darlo ai clienti.
52 attacks, written by someone who had read all the code and bought a real unlock code. None got through. 244 automatic tests, all passing.52 attacchi, scritti da chi aveva letto tutto il codice e comprato un codice di sblocco vero. Nessuno è passato. 244 prove automatiche, tutte superate.
translatestraduce 244 passed · 52 attacks · 0 bypass
- region
- fra1 · Vercel functions, Frankfurtfunzioni Vercel, Francoforte
- database
- Postgres · Supabase, Frankfurt · data at rest in the EUFrancoforte · dati a riposo in UE
- rls
- ON · every table · policies bound to auth.uid() · anon: no access · column-level grantsogni tabella · policy legate ad auth.uid() · anon: nessun accesso · permessi colonna per colonna
- delivery
- AES-256-GCM · key per licence + computer, HKDF-SHA256chiave per licenza + computer, HKDF-SHA256
- manifest
- Ed25519 · verified before a single file is writtenverificata prima di scrivere un solo file
- watermark
- per licenceper licenza · <!-- kit-filigrana · licenza 3f2a91c0… -->
- codes
- 100-bit100 bit · Crockford base32 · stored as HMAC onlysalvati solo come HMAC
- tokens
- creator token encryptedtoken creator cifrato · AES-256-GCM · never sent to the browsermai mandato al browser
- client
- kit.mjs · one readable file · Node built-ins onlyun file leggibile · solo moduli di Node
// in plain wordsin parole semplici
Data stays in Europe, and every package is encrypted for one computer only.I dati stanno in Europa e ogni pacchetto è cifrato per un solo computer.
- Forwarded files don't open on someone else's computer.
- Every copy carries a hidden mark with its licence, so a leak points back to its source.
- Customers' emails and card details stay in your Stripe or Polar. You see sales, not people.
- I file inoltrati non si aprono sul computer di qualcun altro.
- Ogni copia porta un segno nascosto con la sua licenza: se esce, si sa da dove.
- Email e carte dei clienti restano nel tuo Stripe o Polar. Tu vedi le vendite, non le persone.
translatestraduce RLS ON · fra1 · AES-256-GCM
04moneysoldi
Your checkout, your money. We invoice our share once a month.Il tuo checkout, i tuoi soldi. La nostra quota la fatturiamo una volta al mese.
{
"fee": "10%",
"founding_fee": "5%",
"founding_for_life": true,
"fixed_costs": 0,
"invoicing": "monthly",
"paid_to": "your Stripe | Polar account",
"vat_on_sale": "your payment provider"
}// in plain wordsin parole semplici
The customer pays you. We generate the code.Il cliente paga a te, noi generiamo il codice.
of every sale stays with youdi ogni vendita resta a te
for founding creators, for lifeper i founding creator, a vita
subscription, setup or fixed costsdi abbonamento, attivazione o costi fissi
Founding creators: 5% for life, everyone else 10%. Nothing to pay before your first sale: once a month we invoice our share, calculated on the sales your checkout reports. VAT on the sale is handled by your payment provider.
Founding creator: 5% a vita, tutti gli altri 10%. Niente da pagare prima della prima vendita: una volta al mese fatturiamo la nostra quota, calcolata sulle vendite che il tuo checkout ci comunica. L'IVA sulla vendita la gestisce il tuo fornitore di pagamento.
translatestraduce POST /api/webhook/creator/:slug
05FAQ
Questions developers ask first.Le domande che chi sviluppa fa per prime.
Something missing? Write to Manca qualcosa? Scrivi a information@iod21.com; a person answers., risponde una persona.
Who owns the code in my kit?
You do. You grant IOD21 a non-exclusive licence, only while the kit is listed, to store, check, package, encrypt, sign and watermark it for delivery. Nothing else. You can sell the same kit elsewhere.
What does IOD21 see of my files?
Everything you send, because a person reviews it. We never change the content: we add packaging, the signature and the licence watermark. Paid modules leave our servers only encrypted, for one licence and one computer. The free starter travels signed and in clear.
Can I change the price?
Any time, on your checkout: that is the real price. The catalog price is in your dashboard and in kit.json.
What happens if a customer asks for a refund?
You refund on Stripe or Polar as usual. A full refund reaches us through your webhook and revokes the licence: no more activations or updates. Files already installed stay on the customer's disk.
Can I take my kit down?
Yes, whenever you want. It leaves the catalog and new sales stop; licences already sold keep working under the usual rules. Let your customers know with a last update or an email.
Who does the human review?
A person at IOD21, with a written checklist: the kit does what it promises; every agent, command and skill is read the way Claude Code would run it; hooks are read line by line; the main modules are tried in a clean project. Doubtful cases go to the platform lead.
Stripe or Polar?
Either, your choice. Stripe: a Payment Link, or your own Checkout sessions with a kit metadata field; we listen to checkout.session.completed, checkout.session.async_payment_succeeded, charge.refunded and customer.subscription.deleted. Polar: order.paid, order.refunded, subscription.revoked.
The webhook signing secret is entered once in your dashboard, stored encrypted and never shown again.
Who handles VAT?
VAT on the sale is handled by your payment provider, under its rules. IOD21 never touches the sale: it only invoices its own share to you, once a month.
Is the free demo mandatory?
Yes. kit.json needs at least one starter file: it lets a buyer see the kit work before paying. Keep it small and useful; it is signed like everything else.
How long does it all take?
Automatic check: seconds. Human review: 24 to 48 working hours, with a note and a new estimate if it runs longer. New versions follow the same path while the current one stays on sale.
Di chi è il codice del mio kit?
Tuo. Concedi a IOD21 una licenza non esclusiva, solo finché il kit è in catalogo, per conservarlo, controllarlo, impacchettarlo, cifrarlo, firmarlo e metterci la filigrana per la consegna. Nient'altro. Puoi vendere lo stesso kit anche altrove.
Cosa vede IOD21 dei miei file?
Tutto quello che invii, perché una persona lo rivede. Non cambiamo mai il contenuto: aggiungiamo confezione, firma e filigrana della licenza. I moduli a pagamento escono dai nostri server solo cifrati, per una licenza e un computer. Lo starter gratuito viaggia firmato e in chiaro.
Posso cambiare il prezzo?
Quando vuoi, sul tuo checkout: il prezzo vero è quello. Il prezzo del catalogo sta nel tuo pannello e in kit.json.
Cosa succede se un cliente chiede il rimborso?
Rimborsi su Stripe o Polar come sempre. Un rimborso totale ci arriva dal tuo webhook e revoca la licenza: niente più attivazioni né aggiornamenti. I file già installati restano sul disco del cliente.
Posso ritirare il kit?
Sì, quando vuoi. Esce dal catalogo e le vendite si fermano; le licenze già vendute continuano a funzionare con le regole di sempre. Avvisa i tuoi clienti con un ultimo aggiornamento o un'email.
Chi fa la revisione umana?
Una persona di IOD21, con una checklist scritta: il kit fa quello che promette; ogni agente, comando e skill viene letto come lo eseguirebbe Claude Code; gli hook riga per riga; i moduli principali provati in un progetto pulito. I casi dubbi passano al responsabile della piattaforma.
Stripe o Polar?
Tutti e due, scegli tu. Stripe: un Payment Link, oppure sessioni di Checkout tue con il metadata kit; ascoltiamo checkout.session.completed, checkout.session.async_payment_succeeded, charge.refunded e customer.subscription.deleted. Polar: order.paid, order.refunded, subscription.revoked.
Il segreto del webhook lo inserisci una volta nel pannello: viene cifrato e non si vede più.
Chi gestisce l'IVA?
L'IVA sulla vendita la gestisce il tuo fornitore di pagamento, secondo le sue regole. IOD21 non tocca la vendita: ti fattura solo la propria quota, una volta al mese.
La demo gratuita è obbligatoria?
Sì. kit.json richiede almeno un file starter: è quello che fa vedere il kit al lavoro prima di pagare. Tienila piccola e utile; è firmata come tutto il resto.
Quanto ci vuole?
Controllo automatico: pochi secondi. Revisione umana: 24-48 ore lavorative, con una nota e una nuova stima se serve di più. Le versioni nuove fanno lo stesso percorso mentre quella attuale resta in vendita.
06applycandidatura
Tell us about your kit.Raccontaci il tuo kit.
Invite-only while we are in beta. Founding creators keep 95% of every sale, for life.Su invito, finché siamo in beta. I founding creator tengono il 95% di ogni vendita, a vita.
// what happens nextcosa succede dopo
- A person replies. We read every application by hand, from information@iod21.com.
- You get an invite. Single use, valid 14 days. In your dashboard you connect Stripe or Polar with the webhook secret.
- You upload your kit. The automatic check answers in seconds; the review follows within 24 to 48 hours.
- Risponde una persona. Leggiamo ogni candidatura a mano, da information@iod21.com.
- Ricevi un invito. Monouso, vale 14 giorni. Dal pannello colleghi Stripe o Polar con il segreto del webhook.
- Carichi il kit. Il controllo automatico risponde in pochi secondi; la revisione segue entro 24-48 ore.
By publishing you accept the Pubblicando accetti i creator termstermini per i creator. Prefer email? Preferisci l'email? information@iod21.com
rpc piattaforma_candidatura
-- max 5 per hour per connection · bot trap
{
"p_nome": "",
"p_email": "",
"p_link": null,
"p_kit": "",
"p_lingua": "en"
}