Live platform and first steps
The platform is live on helsen-med.com. This page lists every public address, says plainly what works today and what does not yet, and walks the operator through the first day. It ends with short quick-starts for buyers, sellers, drivers and dispatchers.
Live addresses
| Address | What it is | Who uses it |
|---|---|---|
| helsen-med.com | The storefront. Arabic at /ar, English at /en; www.helsen-med.com redirects here. | Buyers |
| seller.helsen-med.com | Seller web console: orders, products, stock, staff, onboarding. | Seller owners and staff |
| delivery.helsen-med.com | Dispatch and delivery web console: tasks, assignment, routes, shifts, cash. | Dispatchers (see the note on administrators below) |
| api.helsen-med.com | The API at /api/v1; interactive Swagger UI at /docs. | All apps; developers and operators |
| docs.helsen-med.com | This documentation site. | Everyone |
| Buyer, seller and driver apps | Android apps distributed as APK files by the team — not on Google Play yet. They talk to api.helsen-med.com and pin its TLS certificate's public key. | Buyers, sellers, drivers |
The admin console web app exists in the repository but is not published on a public address yet; exposing it is pending a decision. Until then, administrative actions are made through the API — the Swagger UI at api.helsen-med.com/docs lets a signed-in administrator call every admin endpoint.
What works today, and what does not yet
| Area | Status |
|---|---|
| Browsing, search, cart, checkout | Live Guests browse and build a cart; checkout needs a signed-in buyer. |
| Cash on delivery | Live The only payment method. Prices in Qatari riyal (QAR). |
| Card payments | Off Neither Stripe nor Paymob is configured. See Money, tax & commission. |
| Shipping | Live Qatar nationwide: Standard 25.00 QAR (2–4 working days), Express 50.00 QAR (next working day), carried by the platform's own drivers. No free-shipping threshold. |
| Tax | Live Qatar 0%, prices tax-inclusive. |
| Email, SMS and push | Off The drivers are set to none: every email, SMS and push notification is queued, not sent, until a provider is configured. In-app notifications (the bell on the website and in the apps) work. |
| Catalogue | Imported The Amr Effendi catalogue: 3 categories (fashion & textiles, beauty & care, home & lifestyle), 8 products, 20 variants, 5 sellers (the makers). Opening stock 25 per variant; commission plan 10%. |
| Imported sellers | No owners The five sellers have no user accounts, so nobody can accept or fulfil their orders yet. Their legal names and warehouse address are placeholders. |
| Admin console | Not deployed Use the API through Swagger meanwhile. |
| Product images | Originals The image resizer (imgproxy) is not deployed, so images are served at their original size. |
Anything that relies on a message reaching someone does not reach them yet: email sign-in codes, email-verification codes, password-reset links, seller staff invitations and order emails all wait in the queue. Buyers can still register with a password and sign in with it. The delivery code a driver needs at the door is also sent by SMS, but it is delivered in-app as well, so the recipient can read it from their notifications.
First-day checklist for the operator
- Sign in as the administrator. There is one super-admin account; its credentials are held by the team, never on this site. With the admin console not deployed, sign in through the Swagger UI: call
POST /api/v1/auth/login, then use Authorize with the returned access token. - Turn on two-factor authentication for that account. Administrators must pass a second factor: until one is set up, every call other than signing in, signing out and enrolling is refused with
auth.MFA_REQUIRED. CallPOST /api/v1/auth/mfa/enroll, add the returned key to an authenticator app, confirm withPOST /api/v1/auth/mfa/confirmand a current code. From then on, sign-in takes the password and a code (themfaTokenfield of the login call). - Give each imported seller an owner account. Until a seller has an owner, its orders cannot be accepted. There is no screen or endpoint yet that attaches an owner to an existing seller (staff invitations create staff, not owners, and are emailed), so this is an open item for the team to settle before those products take real orders.
- Correct the sellers' details and stock. The legal names and the warehouse address are placeholders. Warehouses and stock levels can be edited through the inventory endpoints; a seller's legal name has no edit endpoint after application, so that correction also needs the team. Set the real stock per variant — the opening figure of 25 is not a count.
- Configure email. Set the email driver to SMTP with the provider's settings in the server environment and restart the API and worker (the runbook is in
infra/deploy/README.md). Queued notifications then go out; codes in that backlog will long have expired, so users should ask for a fresh one. SMS and push follow the same pattern when accounts exist. - Review tax and shipping. Confirm Qatar 0% tax-inclusive, and the Standard and Express prices. The delivery windows (2–4 working days, next working day) were taken from the development defaults and have not been confirmed as a business decision — confirm them.
- Check delivery zones and staff. Drivers are only assigned stops inside their delivery zones, so at least one zone must cover Qatar. Create a dispatcher account (grant the
DISPATCHERrole) and approve at least one test driver with a zone and a cash limit — see Delivery & drivers. - Install the APKs on test phones. Install the buyer, seller and driver APKs from the team (Android asks to allow installing apps from that source). Sign in with a password: SMS codes are not sent yet.
- Place a test cash-on-delivery order and walk it end to end, on a product whose seller has an owner:
- Buyer: sign in, add to cart, choose a Qatar address and a shipping method, pay cash on delivery.
- Seller: accept the order group, pack it and mark it ready for pickup (seller web).
- Dispatch: check the delivery task was created and assigned; assign by hand if needed (delivery web).
- Driver: accept, pick up, go in transit, request the delivery code, enter the code the buyer reads from their in-app notifications, record the cash, complete.
- Confirm the order shows as delivered to the buyer, and that the driver's cash appears for settlement.
Quick-starts
Buyer
- Open helsen-med.com (or the buyer app) and choose Arabic or English.
- Browse or search, pick a variant, add to cart. A guest cart is kept and merged when you sign in.
- Create an account with email and password (choose Sign in with a password instead on the sign-in page) — email codes are not sent yet.
- Check out: choose a delivery address in Qatar, a shipping method per seller, and cash on delivery.
- Follow the order from your account. When the driver arrives, read them the delivery code from your notifications.
Seller
- Sign in at seller.helsen-med.com or in the seller app.
- Set up two-factor sign-in with an authenticator app — it is required before you can add a bank account.
- Watch the order queue and accept new orders before their deadline; then pack and mark ready for pickup.
- Keep stock and prices right. Details: Seller guide.
Driver and dispatcher
- Driver: install the driver APK and sign in with email and password. Once approved you see your tasks and route; for each drop, request the delivery code, enter the code the recipient reads out, record cash on COD orders, and complete.
- Dispatcher: sign in at delivery.helsen-med.com with a dispatcher account. Watch unassigned tasks, assign or rebuild routes when needed, manage shifts and record drivers' cash hand-ins.
The delivery web's sign-in form asks only for email and password — it has no field for an authenticator code, and administrators must pass a second factor. An administrator account therefore cannot work there today; use a dispatcher account.
When something does not behave as expected, see Troubleshooting & FAQ.