Blog category

Architecture & Engineering

Engineering explainers and deep dives on building systems that hold up in production: API design, databases, authentication, multi-tenancy and performance.

48 articles

7 min read· October 2026

Technical SEO Checklist for 2026: The Foundation That Lets You Rank

A practical technical SEO checklist for 2026: the crawlability, indexing, speed, structured data and sitemap work that lets content rank at all, with exact Core Web Vitals thresholds and a JSON-LD example you can copy.

Read article
7 min read· October 2026

Local and Geo SEO for Service Businesses: Rank Where Your Customers Are

A practical guide to local and geo SEO for service businesses: how search decides who ranks for a place, the location pages and LocalBusiness markup that help, why consistent details matter, and how to scale across cities and countries organically.

Read article
14 min read· October 2026

SaaS Entitlements: Enforcing Plans, Limits and Add-ons in Code

SaaS entitlements are the rules that say what each customer may use: features, numeric limits and add-ons. Store them in your own database, write them from billing webhooks, check them in one server-side function, and count usage atomically. Here is the data model, the TypeScript check and the SQL.

Read article
12 min read· October 2026

Designing a Public API for Your SaaS: Keys, Versioning and Limits

A public SaaS API is a contract you cannot easily take back. Issue prefixed API keys and store only their hash, scope every key to one tenant, version so old clients never break, paginate with cursors, accept idempotency keys and publish rate limits. Here is the design, with TypeScript and SQL.

Read article
12 min read· October 2026

Sending Webhooks to Your SaaS Customers: Retries, Signing and Logs

Outgoing webhooks let your customers react to events in your SaaS without polling. Write each event to an outbox in the same transaction, deliver from a queue, sign with HMAC-SHA256 following the Standard Webhooks spec, retry with backoff for about a day, block internal addresses, and give customers delivery logs and replay.

Read article
12 min read· October 2026

Custom Domains for SaaS Customers: DNS, TLS and Routing

Custom domains let each SaaS customer serve your product at their own address. The customer adds a CNAME or A record, you verify ownership, a platform issues TLS automatically, and your app maps the Host header to a tenant. Here is how on Vercel, Cloudflare for SaaS or self-hosted Caddy, with code and the security traps.

Read article
11 min read· October 2026

Zero-Downtime Database Migrations for SaaS: A PostgreSQL Playbook

The rules for changing a live SaaS database without taking customers offline: why migrations cause downtime, the expand-migrate-contract release order, PostgreSQL-safe forms of risky statements, batched backfills, multi-tenant schema concerns and the CI checks that enforce it all. SQL examples throughout.

Read article
11 min read· October 2026

SaaS SLAs, Uptime and Status Pages: What to Promise Customers

How to choose an uptime commitment for a SaaS without over-promising: SLI, SLO and SLA in plain terms, how much downtime each percentage allows, why your SLA cannot beat your dependencies, what an SLA document should define, how to measure uptime with a health check, and how to run an honest status page.

Read article
12 min read· October 2026

SaaS Backup and Disaster Recovery: RPO, RTO and Restore Drills

A practical backup and disaster recovery plan for a SaaS: what RPO and RTO mean and how to choose them, what managed Postgres providers give you, why you still need an independent logical copy, how to restore a single tenant, and a restore-drill script that proves your backups work. Sources from PostgreSQL, AWS and Neon documentation.

Read article
11 min read· October 2026

Customer-Facing Analytics in SaaS: Build or Embed?

Build customer-facing analytics yourself when you need a few fixed charts that match your product. Embed a BI tool when customers want to explore, filter and build their own reports. Either way, lock every query to the tenant on the server and serve it from rollups, not your live tables. Costs, code and a decision table.

Read article
10 min read· October 2026

SaaS Technical Due Diligence: What Investors and Buyers Check

SaaS technical due diligence checks whether the product can scale, whether the code and IP are clean, and what fixing the gaps will cost. Reviewers look at architecture, code quality and tests, security, open-source licences, IP ownership, delivery metrics, infrastructure cost and key-person risk. What each area involves, the evidence to prepare, and how to fix gaps first.

Read article
13 min read· October 2026

PostgreSQL Row-Level Security for Multi-Tenant SaaS, with Tests

A working guide to PostgreSQL row-level security for multi-tenant apps: the roles, policies and FORCE setting, passing the tenant with set_config and SET LOCAL through a connection pool, the pitfalls that silently bypass RLS, and the CI tests that prove one tenant cannot reach another.

Read article
13 min read· October 2026

Lovable and Supabase Migrations: Stop Editing Production by Hand

Why hand edits to a production Supabase database break things, how Lovable records its own migrations, and a seven-step workflow to fix it: measure drift, pull a baseline, rebuild from files, write each change as a migration with its RLS policies, test it with pgTAP, deploy from CI, and decide where Lovable fits.

Read article
11 min read· October 2026

Rate Limiting Without Redis on Serverless: Postgres and Memory

The implementation behind the rate limits on this site, which run on serverless hosting with no Redis: the Postgres table and atomic upsert, which store each endpoint uses and why, cleanup without a cron job, failing open during a database outage, and why analytics beacons use a memory-only limiter so they do not wake the database on every page view.

Read article
13 min read· October 2026

Multi-Tenant vs Single-Tenant SaaS: A Decision Table

Multi-tenant is the default for SaaS; single-tenant is a paid exception for customers whose contracts demand it. A decision table, cost at 10, 100 and 1,000 tenants, noisy neighbours, per-tenant restores, compliance-driven isolation, and how to move a customer between the two models.

Read article
12 min read· October 2026

Database per Tenant vs Shared Schema: How Each Scales

A shared schema with row-level security scales to thousands of tenants on one set of migrations; a database per tenant scales isolation, not tenant count. Connection arithmetic, migration fan-out, per-tenant restore SQL, noisy-neighbour controls and how to move one tenant out of the pool.

Read article
10 min read· October 2026

Stripe Connect for Marketplaces: Express vs Custom, Fees and Payouts

How Stripe Connect works for a marketplace in 2026: Standard, Express and Custom accounts and the controller properties replacing them, direct, destination and separate charges, what Connect costs, how payouts and refunds move, and who verifies sellers, with TypeScript examples.

Read article
12 min read· October 2026

Turning a Single-Tenant App Into Multi-Tenant SaaS Without a Rewrite

You can make a single-tenant app multi-tenant without rewriting it: add a tenants table and a tenant_id column, backfill it in batches, enforce it with constraints added NOT VALID, scope every query, switch on PostgreSQL row-level security, then move customers over one at a time. The phases, the SQL, the risks and how long each step usually takes.

Read article
10 min read· October 2026

Better Auth vs NextAuth vs Clerk for a B2B SaaS: An Honest Comparison

For a new B2B SaaS in 2026, Better Auth is the self-hosted default, Clerk is the fastest hosted option if its per-user pricing fits, and NextAuth (Auth.js) is right for existing apps that already run on it. What each one gives you for organizations, roles and enterprise SSO, what it costs, and why this site still runs NextAuth.

Read article
10 min read· October 2026

Marketplace Split Payments, Escrow and Seller Payouts Explained

How a marketplace splits one payment between itself and its sellers: the three money-flow models, why holding seller funds is not escrow, the ledger that makes commission, refunds and payouts correct, SQL for releasing and paying out balances, and how TheSkinProof records commission per order line.

Read article
11 min read· October 2026

Integrating bKash, Nagad and SSLCommerz in One Checkout

How to run bKash, Nagad, SSLCommerz and cash on delivery behind one checkout: a shared payment interface, bKash token reuse and create/execute calls, SSLCommerz sessions, IPN and the validation API, marking orders paid safely, and what TheSkinProof runs in production.

Read article
11 min read· October 2026

Stop Overselling: Stock Reservation Inside the Order Transaction

Why two customers can buy the last unit, and how to stop it in PostgreSQL: the conditional UPDATE, SELECT ... FOR UPDATE, a CHECK constraint as a floor, locking lines in a fixed order to avoid deadlocks, when to reserve stock during payment, and a concurrency test that proves the fix.

Read article
15 min read· October 2026

One GCC Checkout for Tabby, Tamara and Checkout.com: Webhooks and Refunds

An engineering guide to running buy now, pay later and card payments through one checkout in Saudi Arabia and the UAE: how Tabby, Tamara and Checkout.com differ on amounts, statuses, capture, webhooks and refunds, a TypeScript provider interface that hides those differences, and how to handle webhooks that arrive out of order or twice.

Read article
15 min read· October 2026

M-Pesa Daraja STK Push: The Production Failure Cases to Test

An engineering guide to M-Pesa Express (STK Push) on Safaricom Daraja for teams in Kenya: how the flow works, why the callback is untrusted, the six failure cases to test before production, an idempotent TypeScript callback handler keyed on CheckoutRequestID that confirms through the STK Push query, and a reconciliation job for callbacks that never arrive.

Read article
17 min read· October 2026

Paystack vs Flutterwave for a Next.js Checkout: Fees, Webhooks, Splits

An engineering comparison of Paystack and Flutterwave for teams building a Next.js checkout in Nigeria and across Africa: published fees and settlement, countries, amount units, split payments, webhook verification and test mode, plus an App Router route handler that verifies signatures on the raw body with a constant-time compare and confirms each payment exactly once.

Read article
12 min read· October 2026

FHIR API Integration for Startups: SMART on FHIR, Epic and Cerner Sandboxes

A practical guide to FHIR API integration for health startups: the R4 resources you will use, SMART on FHIR launch flows, the Epic and Oracle Health (Cerner) sandboxes, bulk data export, a TypeScript sample, and where the time really goes.

Read article
15 min read· October 2026

Double-Entry Ledger Database Design in PostgreSQL

A working double-entry ledger schema for PostgreSQL: accounts, journal entries and postings, a deferred trigger that rejects unbalanced entries, bigint minor units, idempotency keys, reversal-only corrections, balance strategies and multi-currency, plus a TypeScript posting function.

Read article
14 min read· October 2026

Building a payment orchestration layer: routing, retries, failover

A payment orchestration layer routes each payment to the right processor, retries and fails over without charging twice, keeps saved cards portable and normalises webhooks. Routing rules, a TypeScript router, buy-or-build options, and how RAITHub would build a thin layer.

Read article
14 min read· October 2026

Ecommerce site search: Postgres, Meilisearch, Typesense or Algolia

Start with Postgres full-text search and pg_trgm, move to Meilisearch or Typesense when you need facets and instant results, and pay for Algolia when merchandising tools matter more than cost. Pricing, relevance, typo tolerance, multilingual text and zero-result analytics, with working samples.

Read article
13 min read· October 2026

Building a Product Configurator for an Online Store: Rules, Pricing and 3D

A product configurator is a rules engine with a preview on top. This guide covers option compatibility and dependencies, a server-side price rules engine, 2D layers versus 3D with three.js or model-viewer, SKU and BOM generation, B2B quotes, performance, and when an off-the-shelf customizer is enough.

Read article
18 min read· October 2026

Usage-Based Billing for SaaS: Metering, Stripe Meters and Invoices

Usage-based billing works when every billable event is written once to your own database, rolled into hourly totals and sent to the billing system with an idempotency key. Event design, late events, Stripe Billing meters versus Metronome, Orb and Lago, credits, invoice previews, plan limits and overage alerts, with SQL and TypeScript.

Read article
12 min read· October 2026

Building a Next.js E-commerce Admin: Orders, Stock and Roles

The seven areas an ecommerce admin needs, the Next.js App Router patterns that keep it safe (server actions with permission checks, keyset pagination, optimistic UI), and when Shopify, Medusa or Payload admin is enough instead of a custom build.

Read article
14 min read· October 2026

FEFO Fulfilment: Shipping Short-Dated Stock First

FEFO (first expired, first out) ships the batch closest to expiry first. How to choose between FEFO and FIFO, allocate batches at order time or pick time, enforce a minimum remaining shelf life, split lines across partial batches, return goods to stock, print pick lists, and allocate safely in PostgreSQL with FOR UPDATE SKIP LOCKED.

Read article
14 min read· October 2026

Feature Flags for SaaS: Plans, Rollouts and Kill Switches

Feature flags in a SaaS do four jobs: release, experiment, plan entitlement and kill switch. Target by tenant, roll out with a stable hash, delete flags on a schedule, and test both paths. Here is how, with a TypeScript evaluator and a buy-or-build comparison.

Read article
12 min read· October 2026

SaaS Admin Panel: Build It or Buy It?

Buy an internal tool such as Retool or Appsmith when staff need simple data screens fast; build the admin into your app when it touches tenant data, money or customer accounts. Cited pricing and licences for Retool, Appsmith, Forest Admin and React-admin, and how to do RBAC, audit logs, impersonation and data export safely.

Read article
18 min read· October 2026

One Platform, Many Agencies: Tenant Isolation for Property Portals

A multi-agency property platform stays safe when the agency is the tenant: agency_id on every row, PostgreSQL row-level security on every table, co-broking as an explicit agreement, public search from a separate projection, and a cross-agency IDOR suite in CI.

Read article
11 min read· October 2026

Why Is My Next.js App So Slow in Production? Six Causes and Fixes

Most slow Next.js apps have one of six problems: pages rendering on every request by accident, uncached database reads, N+1 queries, too much client JavaScript, unoptimised images, or a server far from its database. How to tell which one you have from TTFB and LCP, and the fixes, with the ISR and cached queries this site uses to keep its database mostly asleep.

Read article
14 min read· September 2026

API Rate Limiting Explained: Fixed Window, Sliding Window and Token Bucket

How the three common rate limiting algorithms work, with code for each; why an in-memory counter fails on serverless; and the Postgres-backed limiter this website runs instead of Redis, including its trade-offs, its three-bucket login limit and the per-recipient cap on confirmation emails.

Read article
7 min read· April 2026

Next.js Production Checklist: 15 Things Teams Forget

From missing error boundaries to unconfigured ISR, here is a checklist for shipping Next.js apps that actually work in production.

Read article
8 min read· July 2026

Core Web Vitals: A Practical Optimization Guide (2026)

A practical, honest guide to Core Web Vitals in 2026: what LCP, INP and CLS mean, the thresholds Google uses, and the specific fixes that move the numbers.

Read article
7 min read· April 2026

JWT vs Session Authentication: Which Should You Use?

A clear, honest guide to JWT vs session authentication: how each works, the real trade-offs, security pitfalls, and a practical rule for choosing.

Read article
7 min read· April 2026

Monolith vs Microservices for Startups

A practical, honest guide to monolith vs microservices for startups — the real trade-offs, a side-by-side comparison, rough costs, and when splitting actually pays off.

Read article
7 min read· March 2026

Next.js vs React: Which Should You Choose in 2026?

An honest Next.js vs React comparison for 2026 — what each really is, when to pick which, and how the decision shapes SEO, cost and hiring for your product.

Read article
8 min read· March 2026

PostgreSQL Indexing: A Practical Guide for Developers

A practical PostgreSQL indexing guide: what indexes do, the main types, when to use each, how to read EXPLAIN, and the mistakes that quietly slow apps down.

Read article
8 min read· March 2026

PostgreSQL vs MongoDB for SaaS: A Practical Comparison

An honest, practical comparison of PostgreSQL and MongoDB for SaaS products, covering data models, transactions, scaling, cost and multi-tenancy.

Read article
7 min read· March 2026

React Server Components Explained (with Examples)

A plain-English guide to React Server Components: what they do, how they differ from client components, real code examples, and when they actually help your product.

Read article
7 min read· February 2026

What Are Webhooks and How to Build Them Reliably

A practical, honest guide to what webhooks are, how they differ from polling, and the engineering patterns (signing, retries, idempotency) that make them reliable in production.

Read article
8 min read· February 2026

What Is Idempotency in API Design (and Why It Matters)

A plain-English guide to idempotency in API design: what it means, why duplicate charges and orders happen, and how idempotency keys make retries safe.

Read article