Private routes
App and admin routes are noindex and session protected.
Security and responsibilities
BookFast documents which component holds access, billing, booking data, and operational state.
Account
Organization
Device
App and admin routes are noindex and session protected.
Production keys use Cloudflare secret bindings, not source.
Android uses a device session and private RLS.
Every protected request checks the session and active business. Billing, membership, and admin mutations have separate authorization.
Pairing creates a device-scoped session. Android performs no administrative delete, sees no other queue, and requests no inbound SMS access.
Create the account, choose a plan, and follow the guided setup.