Local-first creator membership platform for gated digital products.
Signup → onboard → plan → checkout → subscribe → access gated content.
Features · Architecture · Tech Stack · Deployment · Quick Start · Testing · Contributing
A production-minded monorepo for creators who need a practical way to sell access, manage members, and deliver protected content — without fragile external dependencies. Built from the ground up with release governance, rollback validation, and local-first resilience as first-class concerns.
Membership Lifecycle
- User signup & authentication (JWT access + refresh tokens)
- Creator onboarding & profile management
- Plan / pricing tier configuration
- Checkout flow with IDPay payment gateway integration
- Subscription state management (active, expired, cancelled)
- Gated content delivery with access control enforcement
Platform & Operations
- Role-based access control (RBAC) with granular permission matrix
- Admin dashboard for member & subscription management
- Content protection layer (MinIO-backed storage, access-gated delivery)
- Structured audit logging for payment & access events
- Background job queue for async operations
- Rate limiting, CSRF protection, and security headers
Release Engineering
- Phased production deployment (Phases A–G) with go/no-go gates
- Rollback validation drill with evidence collection
- Health reporting & runtime observability
- Automated smoke test suite (auth, payments, RBAC, content download)
- Local-first development stack with proxy & database helpers
creatormembership/
├── apps/
│ ├── web/ # Next.js 16 (App Router) — public & admin UI
│ └── api/ # Fastify 5 — REST API, auth, payments, workers
├── tools/ # Quality gates, security scanning, phase runner
│ ├── quality-*.js # Lint, typecheck, unit, integration, e2e
│ ├── security/ # Local-first scan, dependency vulnerability
│ ├── docs-validator/ # Documentation integrity checks
│ └── phase-runner/ # Phased release orchestration
├── scripts/
│ ├── automation/ # Stack lifecycle, smoke tests, backup, autopilot
│ └── release/ # Rollback validation, RC gates, deploy prep
├── docs/ # Architecture decisions, runbooks, PRD, governance
└── ops/ # Operational configurations
Browser ──► Next.js (Web) ──► Fastify (API) ──► PostgreSQL
│
[IDPay Gateway]
│
[MinIO Storage]
│
[Background Worker]
The web app serves the customer-facing UI and admin panel. The API handles authentication, payment orchestration, content protection, and background jobs. All persistent state lives in PostgreSQL.
| Layer | Technology |
|---|---|
| Frontend | Next.js 16, React 19, TypeScript 5.9, Tailwind CSS 4 |
| Backend | Fastify 5, TypeScript 5.9, pg (node-postgres) |
| Database | PostgreSQL (via pg driver, raw SQL) |
| Auth | JWT (access + refresh token rotation), bcrypt |
| Payments | IDPay gateway integration (with mock mode for dev) |
| Storage | MinIO (S3-compatible object storage for gated content) |
| Jobs | In-process background worker with queue |
| Tooling | pnpm 9.12 workspaces, TypeScript strict, quality gates |
| CI/Release | Phased deployment scripts, smoke tests, rollback drills |
{
"apps/web": { "next": "^16.1.6", "react": "^19.2.4" },
"apps/api": { "fastify": "^5.7.4", "pg": "^8.19.0" }
}This project follows a structured 7-phase release model (A–G) with automated governance. Each phase has explicit go/no-go criteria, evidence collection, and rollback validation.
| Phase | Focus | Script |
|---|---|---|
| A | Database provisioning & schema deploy | production:phase-a |
| B | Auth endpoints & token issuance | production:phase-b |
| C | Creator onboarding & plan CRUD | production:phase-c |
| D | Payment gateway & checkout flow | production:phase-d |
| E | Subscription management & webhooks | production:phase-e |
| F | Gated content delivery & RBAC | production:phase-f |
| G | Admin dashboard, monitoring, go-live | production:phase-g |
Each phase includes:
- Smoke test suite execution
- Rollback drill validation (
release:rollback:validate) - Evidence recording (
evidence:record) - Go/no-go report generation (
release:go-no-go:evidence)
pnpm production:phase-a # Start with Phase A
pnpm release:rc:gates # Run release candidate gates (any phase)
pnpm release:rollback:validate # Validate rollback readiness- Node.js ≥ 20
- pnpm ≥ 9 (
npm i -g pnpm) - PostgreSQL ≥ 14
git clone https://github.com/alirezasafaei-dev/creatormembership.git
cd creatormembership
pnpm installCopy the environment templates and fill in your values:
cp .env.example .env
cp apps/api/.env.example apps/api/.envKey environment variables:
| Variable | Description |
|---|---|
DATABASE_URL |
PostgreSQL connection string |
PUBLIC_BASE_URL |
Public-facing API base URL |
JWT_ACCESS_SECRET |
Secret for access token signing |
JWT_REFRESH_SECRET |
Secret for refresh token signing |
SESSION_SECRET |
Session encryption key |
PAYMENT_GATEWAY |
mock or idpay |
PAYMENT_GATEWAY_WEBHOOK_SECRET |
Webhook signature secret |
CONTENT_STORAGE_ROOT |
Path for MinIO / local content |
# Start the local PostgreSQL + MinIO stack
pnpm local:stack:start
# Run the API (Fastify on :4000)
pnpm api:dev
# Run the web app (Next.js on :3000) in another terminal
pnpm dev
# Full local automation (stack + api + web + proxy)
pnpm run:local:fullLocal proxy helpers are also available:
pnpm local:proxy:start
pnpm local:proxy:status
pnpm local:proxy:stoppnpm seed:local-demopnpm lint # ESLint & code style
pnpm typecheck # TypeScript strict checking
pnpm test # Unit tests
pnpm build # Build both appspnpm test:integration # Integration tests
pnpm test:e2e # End-to-end tests
pnpm local-first:scan # Validate local-first constraints
pnpm docs:validate # Documentation integritypnpm smoke:all # Full smoke suite
pnpm smoke:auth-session # Auth & session flow
pnpm smoke:mock-payment # Payment simulation
pnpm smoke:idpay-callback # IDPay callback handling
pnpm smoke:rbac-admin # RBAC enforcement
pnpm smoke:content-download # Gated content accesspnpm runtime:health:report # Health check & report
pnpm status:local-report # Local environment status
pnpm evidence:record # Record release evidenceThe Fastify API exposes RESTful endpoints under these domains:
| Domain | Description |
|---|---|
POST /auth/* |
Signup, login, token refresh, logout |
GET /plans |
List available subscription plans |
POST /checkout |
Initiate payment checkout |
POST /webhook |
Payment gateway callback handling |
GET /content/* |
Gated content delivery (auth-required) |
GET /admin/* |
Admin dashboard & user management |
See docs/ARCHITECTURE/03_API_Standards.md for full endpoint documentation and error code reference.
- Core membership flow validated through smoke coverage
- Quality gates green across the documented pipeline
- Phased backlog maintained and automation-backed
- Release governance with evidence collection in place
Detailed status: docs/PROJECT_STATUS.md
Phased roadmap: docs/ROADMAP_PHASED.md
Architecture decisions: docs/ARCHITECTURE_DECISIONS/
Contributions are welcome. Please follow the engineering standards documented in the repo.
- Read the playbook —
docs/Engineering_Playbook.md - Review governance —
docs/GOVERNANCE.md - Open an issue for feature requests or bug reports
- Submit a PR with passing quality gates (
pnpm lint && pnpm typecheck && pnpm test)
All code must pass:
- TypeScript strict mode (no
any) - Quality gate scripts
- Security scan (
pnpm security:scan) - Local-first scan (
pnpm local-first:scan)
See docs/CONTRIBUTING.md for detailed guidelines.
MIT © 2026 Alireza Safaei