Waiverly · Quickstart
Waiverly Quickstart, as shipped in the download
The QUICKSTART.txt in the download — the same steps your delivery email carries.
WAIVERLY — QUICKSTART
=====================
Waiver signing with tamper-evident records — self-hosted PHP + MySQL/SQLite.
REQUIREMENTS
------------
- PHP 8.0+ with extensions: pdo, pdo_sqlite (or pdo_mysql), mbstring, openssl, curl, json
- MySQL 5.7+ OR SQLite 3 (SQLite requires no extra setup — the default)
- A web server (Apache with mod_rewrite — the shipped .htaccess does the routing — or Nginx with try_files)
- No Composer packages, no Node, no build step, no external services.
SHARED HOSTING / CPANEL (RECOMMENDED FOR MOST BUYERS)
------------------------------------------------------
1. Upload the contents of the `app/` folder to your web root (e.g. public_html/)
or a subdirectory (e.g. public_html/waiverly/).
2. Make sure this directory is writable by PHP (it holds the SQLite file, uploads and backups):
data/
Via cPanel File Manager: right-click -> Permissions -> set to 755 or 775.
(If data/ is missing, Waiverly creates it on first run.)
3. Visit https://yourdomain.com/install/ in your browser.
4. Fill in the installer:
- Database: choose MySQL (host, database name, user, password) or SQLite (no setup;
the file is data/waiverly.sqlite)
- Business name
- Timezone
- Your name, email and password (the first admin)
5. The installer writes config.php and sends you to the login page.
FIRST STEPS (what to do in the first ten minutes)
-------------------------------------------------
1. Create a template: the wording people sign, and how long a signed waiver stays valid.
2. Two ways to sign, both without an account: send a link (https://yourdomain.com/w/{token}) or put a tablet at the desk in kiosk mode (/k/{token}).
3. Sign one yourself, then verify it at /verify — the record proves it was not altered afterwards.
4. Set SMTP in Settings so the signer's copy (with their verification link) goes out; without mail it is not sent.
5. Statuses are valid, expired or superseded — a re-signed waiver supersedes the old one.
The manual (docs/MANUAL.md in this download, or the product page on the store) covers every
screen and every rule above, each with the line of source it comes from.
VPS / SELF-HOSTED
-----------------
Requirements same as above. Apache example:
<VirtualHost *:80>
DocumentRoot /var/www/waiverly/app
<Directory /var/www/waiverly/app>
AllowOverride All
Require all granted
</Directory>
</VirtualHost>
Run the web installer as above. Demo data on a FRESH install only (it wipes what is there):
php bin/demo.php
DOCKER (QUICK TEST)
-------------------
The app/ folder ships a Dockerfile (Apache + PHP 8.3, mod_rewrite on):
docker build -t waiverly .
docker run --rm -p 8080:80 -v waiverly-data:/var/www/html/data waiverly
Then visit http://localhost:8080/install/
POST-INSTALL SECURITY CHECKLIST
--------------------------------
[ ] config.php, data/ and the *.sqlite file are blocked by the shipped .htaccess (Apache).
On Nginx, deny /data/, /src/, /bin/, /tests/, /controllers/, /views/ and config.php yourself.
[ ] Open https://yourdomain.com/data/ once — it must answer 403, never a listing.
[ ] Use HTTPS in production.
[ ] Keep PHP updated.
[ ] If you ran bin/demo.php, change or delete the demo accounts before going live.
[ ] Back up data/ (Settings -> Backups writes to data/backups/).
NOTES
-----
* A calendar feed and scheduled backups are in the manual's last sections.
* REST API + MCP endpoint for agents: see API.md.
← Back to Waiverly · Manual · API · Test run