Skip to Getting Started content
MenuFaro

Six clear starting points · one authoritative product

Start with your role.
Keep every handoff clear.

Choose the guide that matches what you need to do. This page is guidance, not completion tracking. Selecting a guide never grants access, writes data, connects a provider, or publishes a menu.

Role selector

Choose what you are here to do

Each option loads a server-rendered guide. All core instructions and links work without client-side JavaScript.

Skip role selector to Platform super admin guide
Guide 5 of 6Platform super admin
5 of 6Guide position only—not task completion or authorization.
Platform super admin

Operate the platform through explicit, audited authority.

The super-admin console can expose real platform state only to a pre-provisioned active platform identity. Local development uses clearly labeled deterministic data and does not create a production administrator.

Restricted console; production identity, MFA, D1, and provider configuration are prerequisites.
  1. 01
    Role or provider gate

    Enter through the protected console

    Use an active internal user whose hosting identity subject matches and whose platform role is PLATFORM_SUPER_ADMIN. Complete multi-factor authentication through the trusted identity provider.

    There is no first-visitor, client-header, or email-based bootstrap. A missing or mismatched record remains unauthorized.Open the protected super-admin console
  2. 02
    Available in this web slice

    Read freshness and degraded states first

    Review organizations, restaurants, users, plan state, publication counts, moderation, audit/outbox, database, storage, and provider health with their refresh context.

    A missing database, provider, or queue signal stays unavailable or degraded. The console does not invent real-time health.No action is required from this guide
  3. 03
    Role or provider gate

    Reauthenticate before a sensitive change

    Use a fresh MFA-backed assertion, preview the exact target and impact, enter a reason and ticket, confirm deliberately, and wait for database or provider readback.

    The assertion is server-signed, bound to the identity, and short-lived. A form preview is not a completed change.No action is required from this guide
  4. 04
    Role or provider gate

    Keep Stripe subscription billing separate from Connect

    MenuFaro Plus Checkout and billing webhooks manage the SaaS subscription. Stripe Connect onboarding and lifecycle webhooks manage a restaurant’s connected payment account only when that product path is configured.

    The two webhook endpoints use separate secrets and state. Stripe Connect does not activate Plus, and it does not turn MenuFaro into a guest-order checkout.Open Stripe Connect administration
  5. 05
    Human review required

    Treat provider and deployment setup as operations

    Configure secrets in the hosted secret store, register the exact webhook endpoints, verify live/test mode, and record provider confirmation. Never put credentials or MFA codes in source, logs, screenshots, or chat.

    A locally rendered provider panel is not evidence of a connected production account, accepted Stripe terms, successful webhooks, DNS, or TLS.No action is required from this guide

Shared release model

Draft to public menu without hidden steps

The website and installed web app use the same release contract. A visual preview is never the live menu.

  1. 01

    Edit a private draft

    Dish, price, media, theme, translation, availability, tax/service, and safety changes remain private.

  2. 02

    Run server preflight

    Resolve permission, plan, content, media, language, commercial-policy, allergen, and QR blockers.

  3. 03

    Confirm one immutable release

    Only an authorized owner or manager confirms the exact revision and fingerprint. Success waits for durable readback.

  4. 04

    Keep the permanent QR

    The stable token resolves the current immutable release. Republishing does not require reprinting the code.

State and recovery guide

Know what to do when the happy path stops

Loading or processing

Wait for the visible stage. Do not submit again while a consequential request is active.

Offline or reconnecting

Private work stays network-only. Reconnect, then reload the authoritative revision before editing or publishing.

Unauthorized or unavailable

Sign in with your own account, request the correct role, or ask an operator to restore the missing dependency.

Stale or conflicting

Compare the newer server version with your work. Never force a blind overwrite from another browser or phone.

Confirmed success

Trust a release, receipt, or provider state only after the page shows authoritative confirmation and identifiers.

Billing or Stripe problem

Keep Plus pending, failed, or past due until the billing provider and signed lifecycle event confirm the result.

Optional connected iPhone access

The website can live on your Home Screen

Installation changes how you launch MenuFaro, not where data lives. It is not a native iOS release.