Saavo Starter / Features

The connected foundation behind a production SaaS.

Saavo Starter connects eight production SaaS areas in one Cloudflare codebase: authentication, Stripe billing, access control, operations, analytics, secure delivery, localization, and infrastructure.

01 / 08

Authentication & account security

Built-in protection, without the patchwork.

Connect sign-in, account recovery, verification, and sensitive account changes through one security model.

Secure sign-in — Email and password flows with secure sessions and configurable verification.

Secure sign-in

Email and password flows with secure sessions and configurable verification.

Social login — Google and GitHub OAuth share the same account lifecycle.

Social login

Google and GitHub OAuth share the same account lifecycle.

Email lifecycle — Verify addresses, resend codes, and confirm email changes.

Email lifecycle

Verify addresses, resend codes, and confirm email changes.

Password recovery — Time-bounded reset sessions help users regain access safely.

Password recovery

Time-bounded reset sessions help users regain access safely.

Two-factor security — TOTP setup, verification, recovery codes, and protected changes.

Two-factor security

TOTP setup, verification, recovery codes, and protected changes.

  • Recovery codes
  • Step-up verification
  • Turnstile escalation
  • Request rate limits
  • Account controls
02 / 08

Stripe billing & customer account

From checkout to customer history.

A connected Stripe lifecycle for one-time products, subscriptions, customer records, and purchase visibility.

Hosted checkout — Locale-aware Checkout for one-time payments and subscriptions.

Hosted checkout

Locale-aware Checkout for one-time payments and subscriptions.

Products after purchase — Customers can see products, plans, access periods, and documentation.

Products after purchase

Customers can see products, plans, access periods, and documentation.

Subscription lifecycle — Track plan status, billing period, trial, and current validity.

Subscription lifecycle

Track plan status, billing period, trial, and current validity.

Payment history — Clear references, dates, amounts, states, and available documents.

Payment history

Clear references, dates, amounts, states, and available documents.

Commerce operations — Separate purchase and subscription views for administrators.

Commerce operations

Separate purchase and subscription views for administrators.

  • Automatic tax
  • Promotion codes
  • Invoices and receipts
  • Billing portal
  • Webhook lifecycle
03 / 08

Access control & lifecycle automation

Turn payment into product access.

Map products to roles and entitlements, then grant, refresh, or revoke access as the commercial lifecycle changes.

Roles and capabilities — Keep broad roles separate from concrete business capabilities.

Roles and capabilities

Keep broad roles separate from concrete business capabilities.

Boolean entitlements — Represent whether a user owns a specific product right.

Boolean entitlements

Represent whether a user owns a specific product right.

Quota entitlements — Track limits, usage, remaining quantity, reset, and rollover.

Quota entitlements

Track limits, usage, remaining quantity, reset, and rollover.

Product access mapping — Configure access at the product plan instead of hard-coding callbacks.

Product access mapping

Configure access at the product plan instead of hard-coding callbacks.

Reliable lifecycle execution — Persist grants and revocations with idempotency, errors, and retry semantics.

Reliable lifecycle execution

Persist grants and revocations with idempotency, errors, and retry semantics.

  • Effective dates
  • Cycle refresh
  • Quota rollover
  • Idempotent execution
  • Grant and revoke
04 / 08

Admin operations & customer support

Operate the product you ship.

Use one administration surface for users, commerce, access, support, and operational evidence.

Operations overview — Understand the current system state without vanity totals.

Operations overview

Understand the current system state without vanity totals.

User management — Search users and review role, status, and account details.

User management

Search users and review role, status, and account details.

Payment operations — Review one-time purchases and subscriptions independently.

Payment operations

Review one-time purchases and subscriptions independently.

Support workbench — Prioritize, reply, add internal notes, resolve, and close tickets.

Support workbench

Prioritize, reply, add internal notes, resolve, and close tickets.

Logs and execution visibility — Trace system, alert, audit, event, and command outcomes.

Logs and execution visibility

Trace system, alert, audit, event, and command outcomes.

  • Role operations
  • OAuth clients
  • Ticket priority
  • Internal notes
  • Audit trails
05 / 08

Built-in product analytics

Understand how the product is used.

First-party analytics connect traffic, behavior, conversion, and performance without starting with another SaaS dependency.

Analytics overview — Pageviews, visitors, visits, bounce, and duration in context.

Analytics overview

Pageviews, visitors, visits, bounce, and duration in context.

Acquisition — Understand referrers, channels, and UTM sources.

Acquisition

Understand referrers, channels, and UTM sources.

Audience and devices — Explore location, language, device, browser, and operating system.

Audience and devices

Explore location, language, device, browser, and operating system.

Events and sessions — Inspect custom events and the sessions behind product behavior.

Events and sessions

Inspect custom events and the sessions behind product behavior.

Funnels and performance — Measure conversion steps alongside real Web Vitals.

Funnels and performance

Measure conversion steps alongside real Web Vitals.

  • First-party measurement
  • Do Not Track support
  • Retention cleanup
  • Referrer and UTM
  • Web Vitals
06 / 08

OAuth2 & secure template delivery

Authorize the client, protect the product.

Authorize public or confidential clients with explicit scopes, then deliver only the resources covered by the user’s entitlements.

Consent experience — Users can inspect the client, scopes, and requested access.

Consent experience

Users can inspect the client, scopes, and requested access.

PKCE authorization — Authorization Code with PKCE S256 protects public clients.

PKCE authorization

Authorization Code with PKCE S256 protects public clients.

OAuth client management — Configure clients, grant types, scopes, and status.

OAuth client management

Configure clients, grant types, scopes, and status.

Protected template catalog — Return catalog entries only when scope and entitlement agree.

Protected template catalog

Return catalog entries only when scope and entitlement agree.

Secure template download — Deliver through a temporary R2 URL and verify the result.

Secure template download

Deliver through a temporary R2 URL and verify the result.

  • Refresh token rotation
  • Single-use authorization codes
  • Client credentials
  • Token revocation
  • Scope-based access
07 / 08

Localization, content & privacy

Ready for more markets and clearer choices.

Ship localized routes, documentation, search metadata, legal pages, themes, and configurable privacy controls together.

12 locale routes and RTL-ready UI — Configured locale routing with RTL-ready layout support.

12 locale routes and RTL-ready UI

Configured locale routing with RTL-ready layout support.

Typed localization — Use shared client, component, and HTTP response localization contracts.

Typed localization

Use shared client, component, and HTTP response localization contracts.

Documentation — Publish structured product guides and reference content.

Documentation

Publish structured product guides and reference content.

SEO foundations — Canonical, alternate language, social metadata, sitemap, and schemas.

SEO foundations

Canonical, alternate language, social metadata, sitemap, and schemas.

Privacy controls — Versioned consent preferences and consent-aware third-party scripts.

Privacy controls

Versioned consent preferences and consent-aware third-party scripts.

  • Legal pages
  • Consent persistence
  • Script gating
  • Light and dark themes
  • Responsive and RTL UI
08 / 08

Cloudflare-native developer foundation

A foundation designed to stay understandable.

Keep runtime services, persistence, asynchronous work, configuration, and code ownership explicit as the product grows.

Workers runtime — Run Hono services and React surfaces on Cloudflare Workers.

Workers runtime

Run Hono services and React surfaces on Cloudflare Workers.

D1, R2, and KV storage — Use the right persistence primitive for relational, object, and TTL data.

D1, R2, and KV storage

Use the right persistence primitive for relational, object, and TTL data.

Queues and scheduler — Run background work, cleanup, and entitlement cycles.

Queues and scheduler

Run background work, cleanup, and entitlement cycles.

Transactional email — Send verification, recovery, billing, and security notifications.

Transactional email

Send verification, recovery, billing, and security notifications.

Typed, layered engineering — Validate configuration and preserve Schema → DB → Repository → Service → API → UI.

Typed, layered engineering

Validate configuration and preserve Schema → DB → Repository → Service → API → UI.

  • Durable Objects
  • Storage policy
  • Layered ownership
  • Automated tests
  • Schema validation

Own the foundation

Start with connected workflows, then make the product yours.

Saavo Starter gives you the source and the operational paths behind it, so the next change stays understandable.

Get Saavo Starter