- A code on each table opens the menu with the table’s number in the address. The menu comes from the server, with each item’s options and whether it is sold out.
- The phone sends the items, the options and a key it made for this order. The server looks the prices up in its own menu, so the total is the server’s. The same key sent again, after a double tap or a lost answer, returns the order that is already stored.
- The kitchen’s screen and the guest’s phone keep a WebSocket to the café’s server, a Durable Object that sleeps while nothing happens. The server sends them a new order when it is stored, and it sends a change of status or an item marked sold out the same way.
- A screen that loses its connection tries again after a pause that doubles up to 8 seconds. When it is back, it reads every open order, so it shows the orders placed while it was away.
- Payment opens Stripe Checkout with the server’s prices. Only Stripe’s webhook marks the order paid. The server checks its HMAC-SHA256 signature with the endpoint’s secret and refuses a signature older than 5 minutes. The amount must match the order, and an event sent twice changes nothing.
- Anyone behind the portfolio’s login can open the kitchen’s screen. A café would sign the screen in with a passkey, as the club in P15 does.