Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)

    Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)

    Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)
    1. Docs
    2. /Architecture
    3. /Security

    Updated Jun 22, 20263 min listen

    Ring Platform Logo

    Завантаження документації...

    Підготовка контенту платформи Ring

    1. Docs
    2. /Architecture
    3. /Security

    Updated Jun 22, 20263 min listen

    Ring Platform Logo

    Завантаження документації...

    Підготовка контенту платформи Ring

    1. Docs
    2. /Architecture
    3. /Security

    Updated Jun 22, 20263 min listen

    Ring Platform Logo

    Завантаження документації...

    Підготовка контенту платформи Ring

    Security Model

    Use Founder / Developer tabs in the docs sidebar. This page covers the architecture-level security model; operational hardening and compliance depth live in Security & Compliance.

    Ring Platform defense is layered: Auth.js establishes identity, layout-level gates enforce role access before Server Actions run, JSONB rows carry visibility flags, and API routes apply Zod validation plus rate limits. There is no single middleware that replaces domain checks — each layer adds a narrow guarantee.

    Security layers at a glance

    LayerFounder viewDeveloper anchor
    IdentityMagic link, Google, Apple, wallet sign-inAuth.js v5 — Authentication
    RolesVisitor → Subscriber → Member → Confidential → Adminusers.data.role lowercase enum
    Route gatesPaid tiers unlock posting & confidential readsAuthenticated route layouts call auth()
    Data visibilityConfidential entities/opportunities hidden from public listsvisibility fields + cache tags by role
    API surfaceWebhooks verified server-side onlyZod + RBAC in route handlers
    TransportHTTPS everywhere; secrets never in MDXCORS + rate limiting on /api/*

    What founders configure

    Role ladder (typical clone)

    Subscriber

    Can browse and receive notifications — baseline community access.

    Member

    Can create entities and post public opportunities.

    Confidential

    Access to confidential listings and deal-room style content.

    Admin

    Moderation, analytics, store ERP, news kingdom controls.

    Implementation map

    Request authorization path

    Role enum (SSOT)

    Persisted on users.data.role — lowercase strings validated in Zod:

    Permission matrices live in features/auth/types.ts (canViewconfidentialOpportunities, etc.). Prefer typed role checks over ad-hoc boolean flags in new code.

    Layout-level auth gates

    proxy.ts handles locale only — not authentication (v1.6.0 architecture). Protected routes use App Router layouts that call auth() and redirect unauthenticated users before children render. See Authentication and Proxy & intl.

    Confidential routes

    RouteConstant
    Confidential entities/confidential/entities
    Confidential opportunities/confidential/opportunities

    Defined in . List caches are role-scoped; discovery sync minimizes path churn for confidential hubs ().

    Related documentation

    Data Validation (deep dive)

    Zod schemas, route-boundary patterns, webhook HMAC verification, and business data safety.

    Security & Compliance (deep dive)

    Auth.js config, GDPR, PCI notes, Firebase rules legacy paths.

    Authentication architecture

    Sessions, Postgres adapter, multi-provider setup.

    PaymentConductor

    HMAC webhook verification, idempotent order references.

    Security Model

    Use Founder / Developer tabs in the docs sidebar. This page covers the architecture-level security model; operational hardening and compliance depth live in Security & Compliance.

    Ring Platform defense is layered: Auth.js establishes identity, layout-level gates enforce role access before Server Actions run, JSONB rows carry visibility flags, and API routes apply Zod validation plus rate limits. There is no single middleware that replaces domain checks — each layer adds a narrow guarantee.

    Security layers at a glance

    LayerFounder viewDeveloper anchor
    IdentityMagic link, Google, Apple, wallet sign-inAuth.js v5 — Authentication
    RolesVisitor → Subscriber → Member → Confidential → Adminusers.data.role lowercase enum
    Route gatesPaid tiers unlock posting & confidential readsAuthenticated route layouts call auth()
    Data visibilityConfidential entities/opportunities hidden from public listsvisibility fields + cache tags by role
    API surfaceWebhooks verified server-side onlyZod + RBAC in route handlers
    TransportHTTPS everywhere; secrets never in MDXCORS + rate limiting on /api/*

    What founders configure

    Role ladder (typical clone)

    Subscriber

    Can browse and receive notifications — baseline community access.

    Member

    Can create entities and post public opportunities.

    Confidential

    Access to confidential listings and deal-room style content.

    Admin

    Moderation, analytics, store ERP, news kingdom controls.

    Implementation map

    Request authorization path

    Role enum (SSOT)

    Persisted on users.data.role — lowercase strings validated in Zod:

    Permission matrices live in features/auth/types.ts (canViewconfidentialOpportunities, etc.). Prefer typed role checks over ad-hoc boolean flags in new code.

    Layout-level auth gates

    proxy.ts handles locale only — not authentication (v1.6.0 architecture). Protected routes use App Router layouts that call auth() and redirect unauthenticated users before children render. See Authentication and Proxy & intl.

    Confidential routes

    RouteConstant
    Confidential entities/confidential/entities
    Confidential opportunities/confidential/opportunities

    Defined in . List caches are role-scoped; discovery sync minimizes path churn for confidential hubs ().

    Related documentation

    Data Validation (deep dive)

    Zod schemas, route-boundary patterns, webhook HMAC verification, and business data safety.

    Security & Compliance (deep dive)

    Auth.js config, GDPR, PCI notes, Firebase rules legacy paths.

    Authentication architecture

    Sessions, Postgres adapter, multi-provider setup.

    PaymentConductor

    HMAC webhook verification, idempotent order references.

    Security Model

    Use Founder / Developer tabs in the docs sidebar. This page covers the architecture-level security model; operational hardening and compliance depth live in Security & Compliance.

    Ring Platform defense is layered: Auth.js establishes identity, layout-level gates enforce role access before Server Actions run, JSONB rows carry visibility flags, and API routes apply Zod validation plus rate limits. There is no single middleware that replaces domain checks — each layer adds a narrow guarantee.

    Security layers at a glance

    LayerFounder viewDeveloper anchor
    IdentityMagic link, Google, Apple, wallet sign-inAuth.js v5 — Authentication
    RolesVisitor → Subscriber → Member → Confidential → Adminusers.data.role lowercase enum
    Route gatesPaid tiers unlock posting & confidential readsAuthenticated route layouts call auth()
    Data visibilityConfidential entities/opportunities hidden from public listsvisibility fields + cache tags by role
    API surfaceWebhooks verified server-side onlyZod + RBAC in route handlers
    TransportHTTPS everywhere; secrets never in MDXCORS + rate limiting on /api/*

    What founders configure

    Role ladder (typical clone)

    Subscriber

    Can browse and receive notifications — baseline community access.

    Member

    Can create entities and post public opportunities.

    Confidential

    Access to confidential listings and deal-room style content.

    Admin

    Moderation, analytics, store ERP, news kingdom controls.

    Implementation map

    Request authorization path

    Role enum (SSOT)

    Persisted on users.data.role — lowercase strings validated in Zod:

    Permission matrices live in features/auth/types.ts (canViewconfidentialOpportunities, etc.). Prefer typed role checks over ad-hoc boolean flags in new code.

    Layout-level auth gates

    proxy.ts handles locale only — not authentication (v1.6.0 architecture). Protected routes use App Router layouts that call auth() and redirect unauthenticated users before children render. See Authentication and Proxy & intl.

    Confidential routes

    RouteConstant
    Confidential entities/confidential/entities
    Confidential opportunities/confidential/opportunities

    Defined in . List caches are role-scoped; discovery sync minimizes path churn for confidential hubs ().

    Related documentation

    Data Validation (deep dive)

    Zod schemas, route-boundary patterns, webhook HMAC verification, and business data safety.

    Security & Compliance (deep dive)

    Auth.js config, GDPR, PCI notes, Firebase rules legacy paths.

    Authentication architecture

    Sessions, Postgres adapter, multi-provider setup.

    PaymentConductor

    HMAC webhook verification, idempotent order references.

    Confidential tier — business value

    Confidential entities and opportunities let you run a two-speed marketplace: public discovery for reach, restricted listings for vetted partners (investors, government tenders, M&A). Membership upsell often maps directly to confidential access — see Membership.

    Operator rule

    Never expose production AUTH_SECRET, WayForPay keys, or service accounts in docs widgets, clone READMEs, or client bundles. Ring docs authoring rules forbid embedded secrets.

    Typical compliance scenarios

    • GDPR delete-my-data — account deletion flows through Auth.js + Postgres cascades (Privacy).
    • Payment PCI scope — card data stays on WayForPay/Stripe; Ring stores order references only (PaymentConductor).
    • Regional clone — wellness/gov rings add audit logging on top of the same RBAC core.
    constants/routes.ts
    Discovery mutation sync

    API hardening checklist

    1. 1

      Validate input with Zod at the route boundary

      Never trust client JSON — mirror Server Action schemas in /app/api/**.

    2. 2

      Authorize before DatabaseService calls

      Check session role + resource ownership (entity userId, opportunity poster).

    3. 3

      Rate-limit abuse-prone endpoints

      Apply limiting on auth, webhook, and public write routes — patterns in Security & Compliance.

    4. 4

      Structured errors

      Use Error.cause (ES2022) for nested failure context in services — aids logging without leaking internals to clients.

    CORS

    API routes set explicit CORS for trusted clone origins only — do not widen Access-Control-Allow-Origin for convenience in production.

    Privacy

    Data retention and export for GDPR-facing clones.

    Confidential tier — business value

    Confidential entities and opportunities let you run a two-speed marketplace: public discovery for reach, restricted listings for vetted partners (investors, government tenders, M&A). Membership upsell often maps directly to confidential access — see Membership.

    Operator rule

    Never expose production AUTH_SECRET, WayForPay keys, or service accounts in docs widgets, clone READMEs, or client bundles. Ring docs authoring rules forbid embedded secrets.

    Typical compliance scenarios

    • GDPR delete-my-data — account deletion flows through Auth.js + Postgres cascades (Privacy).
    • Payment PCI scope — card data stays on WayForPay/Stripe; Ring stores order references only (PaymentConductor).
    • Regional clone — wellness/gov rings add audit logging on top of the same RBAC core.
    constants/routes.ts
    Discovery mutation sync

    API hardening checklist

    1. 1

      Validate input with Zod at the route boundary

      Never trust client JSON — mirror Server Action schemas in /app/api/**.

    2. 2

      Authorize before DatabaseService calls

      Check session role + resource ownership (entity userId, opportunity poster).

    3. 3

      Rate-limit abuse-prone endpoints

      Apply limiting on auth, webhook, and public write routes — patterns in Security & Compliance.

    4. 4

      Structured errors

      Use Error.cause (ES2022) for nested failure context in services — aids logging without leaking internals to clients.

    CORS

    API routes set explicit CORS for trusted clone origins only — do not widen Access-Control-Allow-Origin for convenience in production.

    Privacy

    Data retention and export for GDPR-facing clones.

    Confidential tier — business value

    Confidential entities and opportunities let you run a two-speed marketplace: public discovery for reach, restricted listings for vetted partners (investors, government tenders, M&A). Membership upsell often maps directly to confidential access — see Membership.

    Operator rule

    Never expose production AUTH_SECRET, WayForPay keys, or service accounts in docs widgets, clone READMEs, or client bundles. Ring docs authoring rules forbid embedded secrets.

    Typical compliance scenarios

    • GDPR delete-my-data — account deletion flows through Auth.js + Postgres cascades (Privacy).
    • Payment PCI scope — card data stays on WayForPay/Stripe; Ring stores order references only (PaymentConductor).
    • Regional clone — wellness/gov rings add audit logging on top of the same RBAC core.
    constants/routes.ts
    Discovery mutation sync

    API hardening checklist

    1. 1

      Validate input with Zod at the route boundary

      Never trust client JSON — mirror Server Action schemas in /app/api/**.

    2. 2

      Authorize before DatabaseService calls

      Check session role + resource ownership (entity userId, opportunity poster).

    3. 3

      Rate-limit abuse-prone endpoints

      Apply limiting on auth, webhook, and public write routes — patterns in Security & Compliance.

    4. 4

      Structured errors

      Use Error.cause (ES2022) for nested failure context in services — aids logging without leaking internals to clients.

    CORS

    API routes set explicit CORS for trusted clone origins only — do not widen Access-Control-Allow-Origin for convenience in production.

    Privacy

    Data retention and export for GDPR-facing clones.