FaithChurch Pro
v1.5.2
This manual is written for a buyer who may never have installed a PHP website before. Follow it from top to bottom for your first installation, then use the configuration sections whenever you need to connect a payment provider, change colours, publish content, configure partners or move the site to another server.

What you need before you upload anything
Prepare these items first. Doing this before extraction prevents the most common cPanel installation problems.
Hosting
PHP 8.2 or newer, MySQL/MariaDB, HTTPS, and the required PHP extensions.
Domain
A domain or subdomain already pointing to the hosting account where FaithChurch will run.
DevWeb purchase
Your FaithChurch license key and the same email address used for the DevWeb Themes purchase.
Empty database
A new MySQL/MariaDB database, a database user and that user's password.
Required PHP extensions
| Extension | Why FaithChurch needs it |
|---|---|
pdo + pdo_mysql | Database connection and prepared SQL queries. |
curl | DevWeb licensing, payments, OAuth and remote demo packages. |
openssl | Secure HTTPS integrations and cryptographic operations. |
mbstring | Safe handling of Unicode and long text fields. |
fileinfo | Server-side MIME checking for uploaded files. |
sodium | Verification of signed DevWeb demo-content packages. |
Connect the domain and identify the document root
FaithChurch can run on a normal domain, a subdomain, or a supported subfolder. For a first-time buyer, a normal domain or subdomain is easiest.
Option A: the domain already exists in cPanel
Find the domain you want to use and open its management screen.
This is the exact folder that serves files for the domain. It might look like /home/account/public_html, /home/account/example.com, or a hosting-provider-specific path.
This is where the FaithChurch buyer ZIP must be extracted for the direct shared-hosting installation.
Option B: create a new domain or subdomain
In cPanel's Domains interface, create the registered domain or subdomain and give it its own document root. Do not accidentally share the document root with another live website unless that is intentional.
Enable HTTPS before payment or social-login testing
Use cPanel SSL/TLS Status or your host's AutoSSL interface and confirm that https://yourdomain.com loads without a certificate warning. Payment webhooks and OAuth callbacks should use HTTPS in production.
Create the empty MySQL database correctly
Example: faithchurch. cPanel may automatically prefix it, for example cpuser_faithchurch. The installer needs the full final database name.
Use a strong, unique password and save it. The web admin password and database password are different credentials.
Grant the privileges needed to create and manage the FaithChurch tables. On a new dedicated application database, choose All Privileges.
Database host, database name, database username and database password. You enter these in Installer Step 3.
| Installer field | Typical cPanel value | Important note |
|---|---|---|
| Host | 127.0.0.1 or localhost | The installer defaults to 127.0.0.1. If your host uses a remote DB host, use the hostname supplied by the host. |
| Port | 3306 | Use the host's actual port if different. |
| Database | cpuser_faithchurch | Include the cPanel prefix when cPanel shows one. |
| Username | cpuser_fcuser | Include the full prefix. |
| Password | Your generated password | Case-sensitive. Do not reuse your cPanel or admin password. |
Upload and extract the FaithChurch ZIP
Do not guess. Use the path confirmed in the Domain section above.
The file is normally named FaithChurch-Pro-v1.5.2-DevWebThemes.zip.
Extract directly into the document root.
The document root itself must contain index.php, .htaccess, bootstrap.php, app/, public/, views/, database/, storage/ and documentation/.
your-domain-document-root/ ├── .htaccess ├── index.php ├── bootstrap.php ├── app/ ├── database/ ├── documentation/ ├── public/ ├── server/ ├── storage/ └── views/
public_html/FaithChurch-Pro-v1.5.2-DevWebThemes/index.php. If your domain points to public_html, move the package contents one level up so public_html/index.php is the FaithChurch front controller.Permissions
Start with normal hosting permissions: directories 0755 and files 0644. The storage/ directory must be writable by the PHP process. If ownership on your host requires it, the host may recommend 0775 for writable directories. Avoid using 0777 as a permanent fix.
Complete the four-step installation wizard
After extraction, visit the domain in your browser. A fresh installation automatically redirects to /install.
Step 1 of 4: Verify your DevWeb Themes purchase
Your customer area includes Purchases, Downloads and Licenses. The license page is at /customer/licenses when you are signed in.
The installer expects your DevWeb license/purchase code and the email used for the purchase.
FaithChurch sends the license code, purchase email, product slug faithchurch, domain and version to the DevWeb Themes license API. The commercial installer does not contain an offline bypass.
Step 2 of 4: Server check
The installer checks pdo, pdo_mysql, curl, openssl, mbstring, fileinfo, sodium, and whether storage/ is writable. Do not continue by editing source code to bypass a missing extension; enable the missing module in cPanel/PHP Selector or contact the host.
Step 3 of 4: Connect the database
Enter the database values created earlier. On success FaithChurch writes the environment configuration, generates an application key when required, and creates the database tables from database/schema.sql.
Step 4 of 4: Create the church and administrator
| Field | What to enter |
|---|---|
| Church / website name | The public organisation name. You can change it later in Admin → Settings. |
| Tagline | Short statement used by the public layout and metadata. |
| Admin name | Name of the first Super Administrator. |
| Admin email | A real email address controlled by the site owner. |
| Admin password | At least 10 characters. Use a unique password, preferably much longer. |
super_admin, seeds base design/settings, ensures the default pages exist, writes storage/installed.lock, then sends you to the login page.Do these things immediately after installation
- Open
https://yourdomain.com/loginand sign in with the administrator you created. - Open
/adminand confirm the dashboard loads. - Go to Admin → Settings and replace the example church contact details.
- Go to Admin → Appearance and set your colours, homepage copy and hero.
- If you want starter content, use Admin → Demo Import before creating a large amount of your own content.
- Configure payment gateways in test/sandbox mode and complete a real end-to-end test transaction.
- Configure Google/Facebook login only after HTTPS and the final domain are correct.
- Review every starter legal page and adapt it to the laws and procedures of your organisation.
- Back up the new database and application once the first configuration is complete.
Where the buyer finds the ZIP and license
| Customer area | Purpose | Path after sign-in |
|---|---|---|
| Purchases | Orders, invoices and purchased products. | /customer/purchases |
| Downloads | Generate a protected download for the purchased FaithChurch release. | /customer/downloads |
| Licenses | Copy the DW license key, view license type, see domain seats, activate or deactivate a domain. | /customer/licenses |
The installer activates against the current site hostname automatically. If you later move the production installation to a different domain, deactivate the old domain in the DevWeb customer license page before activating the new production domain.
Import official demo content safely
FaithChurch provides three official presets:
Modern Church
Contemporary worship, sermons, events and ministries.
Global Ministry
Livestream, missions, campaigns and international ministry presentation.
Community Church
Families, local events, groups and first-visit journeys.
How the import works
The application downloads structured JSON from the configured DevWeb demo-content service. It verifies the package with the included Ed25519 public key before changing the database. Existing demo records with the same type and slug are updated instead of duplicated.
Change colours and typography without editing CSS
| Control | Default | What it changes |
|---|---|---|
| Primary | #155EEF | Main buttons, active states and prominent brand accents. |
| Navy | #0B1F3A | Dark brand surfaces and strong contrast areas. |
| Accent | #5EA1FF | Secondary blue highlights and decorative accents. |
| Background | #F8FAFC | Primary public-page background token. |
| Text | #162033 | Main body/heading text token. |
Font choices included
- Modern System / Inter style – the default modern UI stack.
- Aptos – a softer office/system presentation.
- Editorial Serif – Georgia/Cambria style for a more traditional editorial feel.
Configure the hero and homepage copy
Hero media
| Field | Use |
|---|---|
| Hero style | Choose the built-in FaithChurch graphic or an uploaded church photograph. |
| Hero image | JPG, PNG or WebP. The upload service accepts images up to 8 MB and validates MIME type and dimensions server-side. |
| Hero image alt text | Describe meaningful image content for accessibility and search context. |
| Hero card heading / supporting text | The small contextual message displayed in the hero media treatment. |
Editable homepage text
The same Appearance screen lets you edit the Hero heading/text, Welcome heading/text, Giving heading/text, Giving quote/reference, Community heading/text and Visit heading/text.
Motion controls
Premium preloader controls the branded loading screen. Smooth reveal animations controls public reveal motion. Disable animation if the organisation prefers a more static presentation.
Set the church identity and service details
| Field | Where it appears / why it matters |
|---|---|
| Site name | Public header/footer branding and several default labels. |
| Tagline | Footer copy and default page description when a page-specific description is not supplied. |
| Organisation contact identity stored in settings. | |
| Phone | Displayed in the public footer visit/contact area. |
| Address | Displayed in the public footer visit area. |
| Main service day | Used by homepage/service presentation. |
| Main service time | Used by homepage/service presentation. |
Click Save all settings after editing this screen. Payment, social login, storage and AdSense settings are on the same page and are explained separately below.
Publish sermons, events, ministries and other content
The admin sidebar has dedicated managers for Sermons, Events, Ministries, Leadership, Testimonies, Pages & Policies, and Blog.
Shared editor fields
Every content editor provides Title, Slug, Short description, Main content, Status, Publish date and Featured image. Draft content remains out of the published public queries until you publish it.
| Content type | Additional fields |
|---|---|
| Sermon | Speaker, Scripture, Video URL and Audio URL. Media URLs must be valid HTTP/HTTPS URLs. |
| Event | Date, Time and Venue. |
| Ministry | Leader / Role. |
| Leadership | Leader / Role. |
| Testimony | Uses the shared title, description, body, image and publication controls. |
| Blog | Uses the shared content fields in v1.5.2. |
Featured-image rules
JPG, PNG and WebP images are accepted up to 8 MB. The server reads the real MIME type instead of trusting the filename and rejects invalid image dimensions.
Edit pages, menus, legal policies and search metadata
FaithChurch installs core pages such as About, Give, Prayer, Contact, Privacy Policy, Terms, Donation & Refund Policy, Cookie Policy and Accessibility. Core URLs are protected from accidental slug changes and deletion, but their public content remains editable.
Page settings
| Control | Meaning |
|---|---|
| Page category | Standard page or Legal / Policy page. |
| Navigation label | Short label used when the page is shown in navigation. |
| Show in header | Adds a published custom page to the header's custom page positions. The public header loads up to 3 of these custom page links before the fixed Sermons/Events/Ministries links. |
| Show in footer | Adds the page to appropriate footer navigation. Legal pages marked for footer display are shown in the Legal & Policies column. |
| Hide from search engines | Adds a noindex directive for that page. |
| SEO title | Optional search/social title for the page. |
| SEO description | Optional short description, up to 320 characters. |
Simple page formatting
## Section heading ### Smaller heading - First bullet item - Second bullet item Normal paragraph text.
FaithChurch safely escapes page content; it is not a raw HTML editor. Use the simple heading and list syntax above.
Sitemap and robots
The public application exposes /sitemap.xml and /robots.txt. After launch, submit the sitemap URL to the search engines you use and confirm that pages you intentionally set to noindex are not submitted as important landing pages.
Understand member accounts and staff roles
Public users can register and manage a member account. Staff accounts have additional capabilities based on their role.
| Role | Capabilities in v1.5.2 |
|---|---|
| Super Admin / Admin | All administrator capabilities. |
| Pastor | Dashboard, content, messages, partners and system-health access. |
| Editor | Dashboard and content management. |
| Finance | Dashboard, donations and partner-view access. |
| Member | Normal signed-in public account experience. |
Connect payment gateways correctly
Only gateways with the required credentials appear on the public giving form. Configure one provider at a time, test it, then move to the next provider.
How FaithChurch protects the payment result
FaithChurch creates a pending donation record before redirecting to the gateway. On callback/webhook it verifies with the provider and compares the returned amount and currency with the local donation before marking the record paid. Webhook deliveries are signature-checked where the provider supplies signatures, then the transaction is re-verified through the provider API.
Default currency
Enter a three-letter currency code such as ZAR, USD or another currency supported by the gateway and your merchant account. A syntactically valid three-letter code does not guarantee that every provider/account supports that currency.
Paystack
Official Paystack docs ↗FaithChurch requires: Paystack Secret Key. The same secret key is also used to validate the x-paystack-signature webhook signature.
In Paystack, open the API Keys & Webhooks area and copy a test secret key first. Paystack documents secret keys as server-side credentials and says they should not be exposed in client code.
Admin → Settings → Payments → Paystack secret. Save settings.
Use https://YOUR-DOMAIN/webhooks/paystack. FaithChurch listens for a successful charge event and re-verifies the transaction by reference.
Open the public Give page, choose Paystack, complete a test payment and confirm Admin → Donations changes the donation to paid.
Replace the test secret with the live secret only after your Paystack business is activated and the test flow works. Re-test the live webhook with a small real transaction.
Webhook URL https://YOUR-DOMAIN/webhooks/paystack Automatic callback used by FaithChurch https://YOUR-DOMAIN/payment/callback/paystack
Flutterwave
Official Flutterwave docs ↗FaithChurch requires: Flutterwave Secret Key and Flutterwave Webhook Secret/Secret Hash.
Use Flutterwave's test environment first. Keep the secret server-side.
Flutterwave recommends a random secret hash for verifying incoming webhook requests. Use a long random value that is not reused elsewhere.
Admin → Settings → Payments → Flutterwave secret and Flutterwave webhook secret.
Use https://YOUR-DOMAIN/webhooks/flutterwave and use the exact same secret hash you entered in FaithChurch.
After webhook signature validation, FaithChurch verifies the transaction by Flutterwave transaction ID or reference before marking it paid.
Webhook URL https://YOUR-DOMAIN/webhooks/flutterwave Automatic callback used by FaithChurch https://YOUR-DOMAIN/payment/callback/flutterwave
Stripe Checkout
Official Stripe docs ↗FaithChurch requires: Stripe Secret Key and a webhook endpoint signing secret that begins with whsec_.
Copy the test secret key from Stripe's API keys area.
Admin → Settings → Stripe secret.
Endpoint: https://YOUR-DOMAIN/webhooks/stripe. FaithChurch handles checkout.session.completed when the session is paid.
Stripe assigns a separate signing secret to each webhook endpoint. Copy the endpoint's whsec_... value, not another API key.
Save settings, then test Stripe Checkout from the public Give page.
Webhook URL
https://YOUR-DOMAIN/webhooks/stripe
Event FaithChurch expects
checkout.session.completed
Automatic success callback
https://YOUR-DOMAIN/payment/callback/stripe?session_id={CHECKOUT_SESSION_ID}PayPal
Official PayPal docs ↗FaithChurch requires: PayPal Client ID, PayPal Secret, mode (Sandbox/Live), and PayPal Webhook ID.
Use the Sandbox environment first. Copy the app's Client ID and Secret.
Admin → Settings → PayPal Client ID, PayPal Secret, and set PayPal mode = Sandbox.
Use https://YOUR-DOMAIN/webhooks/paypal. Subscribe to events that cover PAYMENT.CAPTURE.COMPLETED and/or CHECKOUT.ORDER.COMPLETED.
Paste it into the FaithChurch PayPal Webhook ID field. This is not the same thing as the Client ID.
FaithChurch verifies PayPal's webhook signature through PayPal and then verifies the order before changing the donation status.
Switch the PayPal app/dashboard to Live, use the live Client ID/Secret, create or select the live webhook and use its live Webhook ID, then change FaithChurch mode to Live.
Webhook URL https://YOUR-DOMAIN/webhooks/paypal Automatic return URL https://YOUR-DOMAIN/payment/callback/paypal Recommended events PAYMENT.CAPTURE.COMPLETED CHECKOUT.ORDER.COMPLETED
Connect Google and Facebook sign-in
Use Google Cloud/Google Auth Platform and configure the consent/app information required for your account.
https://YOUR-DOMAIN/auth/google/callback. Google requires the redirect URI in the request to match an authorised redirect URI.
Paste them into Admin → Settings → Google Client ID / Google Client Secret.
FaithChurch requests openid email profile, exchanges the authorisation code server-side and reads the user's Google profile.
Use the app ID and app secret supplied by Meta.
https://YOUR-DOMAIN/auth/facebook/callback. Meta also checks redirect URI matching.
Admin → Settings → Facebook App ID / Facebook App Secret.
FaithChurch requests email and public_profile. If a Facebook account does not provide an email, the application cannot complete a normal email-based account flow reliably.
Google callback https://YOUR-DOMAIN/auth/google/callback Facebook callback https://YOUR-DOMAIN/auth/facebook/callback
Choose local uploads or Amazon S3 / S3-compatible storage
Local storage
This is the simplest option. Uploaded media is stored below public/uploads/ in folders such as content, hero, avatars and credentials. The application creates required upload folders as needed.
S3 storage
Select Amazon S3 / S3 compatible in Admin, but place infrastructure credentials in .env. FaithChurch intentionally does not expose S3 access keys through the normal admin form.
AWS_ACCESS_KEY_ID="YOUR_ACCESS_KEY" AWS_SECRET_ACCESS_KEY="YOUR_SECRET_KEY" AWS_DEFAULT_REGION="af-south-1" AWS_BUCKET="your-bucket-name" AWS_ENDPOINT="" AWS_USE_PATH_STYLE=false
| Variable | Meaning |
|---|---|
AWS_ACCESS_KEY_ID | Access key for the IAM/service credential allowed to put objects in the selected bucket. |
AWS_SECRET_ACCESS_KEY | Secret for that access key. Keep it private. |
AWS_DEFAULT_REGION | S3 signing region. Default in the package is af-south-1. |
AWS_BUCKET | Bucket name used for standard Amazon S3 host construction. |
AWS_ENDPOINT | Optional S3-compatible endpoint. In v1.5.2 the signer uses the endpoint host directly for object paths, so use the bucket-specific HTTPS endpoint required by your compatible provider. |
SMTP configuration and the current mail status
FaithChurch v1.5.2 includes an SMTP service and environment variables, but the core contact/prayer workflows currently store submissions in Admin → Messages & Prayer rather than automatically emailing them. There is also no SMTP settings form in Admin in this release.
If you are extending the bundled SMTP service or a later update connects it, the packaged environment keys are:
MAIL_DRIVER=smtp MAIL_HOST=mail.yourdomain.com MAIL_PORT=587 MAIL_USERNAME=no-reply@yourdomain.com MAIL_PASSWORD="YOUR_MAILBOX_PASSWORD" MAIL_ENCRYPTION=tls MAIL_FROM_ADDRESS=no-reply@yourdomain.com MAIL_FROM_NAME="Your Church Name"
The bundled mailer supports STARTTLS when MAIL_ENCRYPTION=tls. Port 587 + STARTTLS is the safest documented choice for this implementation. Do not assume implicit TLS on port 465 works without testing or code changes.
Google AdSense settings
You can enable AdSense and enter the publisher client ID such as ca-pub-.... When enabled with a client ID, the public layout loads the Google AdSense script.
<ins class="adsbygoogle"> ad unit from that stored slot. Enabling AdSense loads the provider script; placement of actual ad units still requires a compatible theme section/update. Review consent requirements before serving personalised advertising.Configure Family and Covenant partnerships
The Partner area is more than a donation tier. It includes partner profiles, contribution state, care requests, prayer workflow, sessions/meetings, resources and Covenant formation tools.
Core partner settings
Administrators with partners.manage can configure partner currency, Family minimum amount, Covenant minimum amount, suggested contribution values, Covenant grace days, public headings/descriptions, benefit lists, formation copy, credential notes, integrity copy and partnership FAQs.
Operational sections
Family prayer
Track prayer items and ministry follow-up for Family Partners.
Meetings / sessions
Create scheduled partner sessions and attach secure HTTPS meeting links.
Resources
Publish resources for all, Family or Covenant audiences with HTTPS links.
Care requests
Move requests through new, reviewed, in prayer, contacted, completed or archived states.
Covenant training
Create modules and record individual progress.
Standing & credentials
Manage formation standing and issue verifiable ministry credentials.
Training, standing and ministry credentials
Covenant training modules support title, description, category, display order, HTTPS resource URL and draft/published status. Admin can record each Covenant Partner as not started, in progress or completed, together with a mentor note.
Formation standing values
formation, mentoring, ready_for_review, released, ordained or paused. Badge status can be active or suspended.
Credential types
Completion, Release, Ordination and Recognition. Issuing a credential creates a certificate number and random verification code. The public verification route is /credential/verify/{code}.
Optional uploaded certificate files use the normal storage driver. If you use S3, read the direct-object-URL warning in the Storage section before storing sensitive certificates there.
Manage contact messages and prayer requests
Public Contact and Prayer forms create message records that appear in this admin screen. Staff with messages.manage can change message status to New, Reviewed or Archived.
This is the primary built-in inbox in v1.5.2. As noted in the Email section, the current core flows do not automatically send these records by SMTP.
Read donation records
The donations table shows Reference, Donor, Amount, Gateway, Status and Date. Payment attempts begin as pending, can become paid only after provider verification, or become failed when initiation/verification fails.
Apache/LiteSpeed shared hosting and Nginx/VPS
cPanel / Apache / LiteSpeed
The commercial package includes a root .htaccess for buyers who extract the full package directly into the domain document root. It blocks direct web access to application internals such as app/, database/, storage/, server/, views/ and documentation/; public assets are internally mapped from public/.
Nginx / VPS preferred layout
On a server where you control the virtual host, keep the application outside the public web root and set the virtual host root to the package's /public directory. An example configuration is included at server/nginx.conf.example.
server {
listen 80;
server_name example.com;
root /var/www/faithchurch/public;
index index.php;
location / {
try_files $uri $uri/ /index.php?$query_string;
}
location ~ \.php$ {
include fastcgi_params;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
fastcgi_pass unix:/run/php/php8.4-fpm.sock;
}
location ~ /\. { deny all; }
}Subfolder installation
The routing helpers detect a mount path such as https://example.com/church. OAuth, payment and webhook URLs must then include that same subfolder, for example https://example.com/church/webhooks/stripe. For less experienced buyers, a dedicated domain/subdomain is easier to configure and troubleshoot.
Production security checklist
- Use HTTPS before accepting logins, payments or OAuth callbacks.
- Keep
APP_ENV=productionandAPP_DEBUG=false. - Never publish or email your
.env, database password, gateway secrets, OAuth secrets or S3 secret. - Keep the DevWeb license mode remote. Do not create a local bypass.
- Use a unique administrator password and remove/restrict staff access when personnel change.
- Keep PHP, MySQL/MariaDB and the web server updated through your host/server maintenance process.
- Use real payment webhooks and test failed, cancelled, duplicate and successful payment cases.
- Back up before theme/source updates and test restore procedures.
- Keep normal file permissions and correct ownership; do not leave the whole site writable.
- Review every starter legal policy for your jurisdiction before launch.
FaithChurch v1.5.2 includes CSRF protection for state-changing forms, login/payment rate limiting, prepared PDO queries, secure password hashing, strict session settings, upload MIME/size validation, upload execution protections, Content Security Policy, HSTS on HTTPS, X-Frame-Options and other browser security headers.
Back up before every update
Minimum backup set
- Export the FaithChurch MySQL/MariaDB database.
- Download or archive the application files, especially
.env,storage/andpublic/uploads/. - If using S3, confirm the bucket has the retention/versioning/backup policy appropriate to your organisation.
- Keep backups outside the public website directory and preferably off the hosting server as well.
Applying future DevWeb updates
Read the update notes first. A safe update package should tell you exactly which files it replaces and whether a database change is required. Never overwrite your production .env with an example environment file.
Fix the most common installation and configuration problems
| Problem | What to check |
|---|---|
| 404 immediately after extraction | Confirm the FaithChurch index.php is directly in the domain's document root, not inside an extra ZIP folder. Confirm Apache rewrite support and the supplied .htaccess. |
| 403 on the whole website | Check file/directory ownership and permissions. Confirm the domain points to the directory where FaithChurch was extracted. |
| Installer says extension missing | Use cPanel PHP Selector/Select PHP Version to enable the named module, or ask the host. The installer intentionally refuses to skip required modules. |
| Database connection failed | Use the full prefixed cPanel database/user names, verify password, add the user to the database, grant privileges, and try localhost if your host does not accept 127.0.0.1. |
| License cannot be verified | Confirm the purchase email and license key, HTTPS/DNS, outbound cURL access and that the domain is within your license allocation. Check DevWeb Themes availability. |
| Images will not upload | Use JPG/PNG/WebP under 8 MB; verify PHP upload limits and that public/uploads can be created/written by PHP. |
| Payment gateway does not appear | The required gateway credentials are blank. PayPal needs both Client ID and Secret. Save settings and reload Give. |
| Payment returns but remains pending/failed | Check the webhook URL, provider secret/signing secret, event delivery logs, currency/amount, and that your server can call the provider API over HTTPS. |
| Google redirect_uri_mismatch | The authorised redirect URI in Google must exactly match the callback displayed by FaithChurch, including scheme, hostname, subfolder and path. |
| Facebook login fails after domain move | Update the Valid OAuth Redirect URI in Meta and then verify the new domain is allowed by the app's settings. |
| S3 upload fails | Check access key, secret, region, bucket, endpoint, IAM/object permission and outbound HTTPS. For compatible providers use the correct bucket-specific endpoint expected by the v1.5.2 signer. |
| Changes appear not to save | Confirm you are not using the read-only official DevWeb demo. Production installations do not set DEVWEB_DEMO_MODE=true. |
Important URLs and configuration paths
| Purpose | URL / path |
|---|---|
| Public website | / |
| Login | /login |
| Register | /register |
| Member account | /account |
| Admin | /admin |
| Appearance | /admin/appearance |
| Settings | /admin/settings |
| Demo import | /admin/demo-import |
| Partners | /admin/partners |
| System health | /admin/system |
| Give | /give |
| Paystack webhook | /webhooks/paystack |
| Flutterwave webhook | /webhooks/flutterwave |
| Stripe webhook | /webhooks/stripe |
| PayPal webhook | /webhooks/paypal |
| Google callback | /auth/google/callback |
| Facebook callback | /auth/facebook/callback |
| Sitemap | /sitemap.xml |
| Robots | /robots.txt |
| Environment file | /.env (server-private; root .htaccess blocks direct access on shared hosting) |
| Install lock | /storage/installed.lock |
| Local uploads | /public/uploads/ |
| Nginx example | /server/nginx.conf.example |
Environment variables shipped in .env.example
APP_NAME APP_ENV APP_DEBUG APP_URL APP_KEY APP_TIMEZONE SESSION_NAME DB_CONNECTION DB_HOST DB_PORT DB_DATABASE DB_USERNAME DB_PASSWORD DEVWEB_PRODUCT_SLUG DEVWEB_LICENSE_MODE DEVWEB_LICENSE_ENDPOINT DEVWEB_DEMO_BASE_URL DEVWEB_DEMO_PUBLIC_KEY MAIL_DRIVER MAIL_HOST MAIL_PORT MAIL_USERNAME MAIL_PASSWORD MAIL_ENCRYPTION MAIL_FROM_ADDRESS MAIL_FROM_NAME GOOGLE_CLIENT_ID GOOGLE_CLIENT_SECRET GOOGLE_REDIRECT_URI FACEBOOK_CLIENT_ID FACEBOOK_CLIENT_SECRET FACEBOOK_REDIRECT_URI AWS_ACCESS_KEY_ID AWS_SECRET_ACCESS_KEY AWS_DEFAULT_REGION AWS_BUCKET AWS_ENDPOINT AWS_USE_PATH_STYLE
Final launch checklist
- The final domain resolves to the correct hosting document root.
- HTTPS loads without warnings and HTTP redirects according to your hosting policy.
- The DevWeb license is active on the correct domain.
- Administrator and member login work.
- Primary, Navy, Accent, Background and Text colours have been reviewed on desktop and mobile.
- Hero image/copy, service information, church address, phone and email are correct.
- Demo/sample content has been replaced or intentionally retained.
- Sermons, Events, Ministries and public pages open correctly.
- Privacy, Terms, Donation & Refund, Cookie and Accessibility wording has been reviewed for the organisation's jurisdiction.
- Every enabled gateway has been tested end-to-end, including webhook delivery.
- Google/Facebook callbacks point to the production domain.
- Storage uploads work and any S3 object-access policy is intentional.
- Prayer/contact messages reach Admin → Messages & Prayer.
- Partner registration, dashboard, meetings/resources and Covenant tools have been tested if enabled operationally.
/sitemap.xmland/robots.txtload correctly.APP_DEBUG=falseand production secrets are not exposed.- A complete post-configuration database/file backup exists off the public web root.
Official service documentation
Third-party dashboards change over time. If a menu label in this manual moves, use the provider's official documentation below and keep the FaithChurch-specific values (webhook paths, callback paths and fields) exactly as documented above.
| cPanel File Manager | docs.cpanel.net/cpanel/files/file-manager/ |
| cPanel Domains | docs.cpanel.net/cpanel/domains/domains/ |
| cPanel Database Wizard | docs.cpanel.net/cpanel/databases/database-wizard/ |
| cPanel SSL/TLS Status | docs.cpanel.net/cpanel/security/ssl-tls-status/ |
| Paystack API keys | paystack.com/docs/api/authentication/ |
| Paystack webhooks | paystack.com/docs/payments/webhooks/ |
| Flutterwave webhooks | developer.flutterwave.com/docs/webhooks |
| Stripe API keys | docs.stripe.com/keys |
| Stripe webhooks | docs.stripe.com/webhooks |
| PayPal REST production | developer.paypal.com/api/rest/production |
| PayPal webhooks | developer.paypal.com/api/rest/webhooks |
| Google OAuth web server apps | developers.google.com/identity/protocols/oauth2/web-server |
| Meta/Facebook Login manual flow | developers.facebook.com/documentation/facebook-login/guides/advanced/manual-flow |
| Amazon S3 permissions | AWS S3 policies and permissions |
| DevWeb Themes License Agreement | devwebthemes.com/page/license-agreement |