Platform teardown

Flutter, Node.js, and five masjid roles

How the production system is split so a member cannot start Azan, a Muezzin cannot rewrite the ledger, and iOS Live Activities still see the next Iqama.

By MyAlMasjid Engineering Published 18 August 2026 Stack we run in production, not a slide deck

The running stack

MyAlMasjid production architecture Flutter app Android + iOS Node.js API API + tokens Live audio WebRTC Azan / Khutbah Login + push Accounts & alerts Database Masjid, roles, sessions Payments Licensed processor Clients never publish media without a short-lived token from the API. Card data is never stored in MyAlMasjid databases.
Figure 1. App, API, live audio, login/push, database, and payments stay on separate rails.

Cross-platform clients

One codebase ships Google Play (com.myalmasjid) and the App Store. iOS-only surfaces — Live Activities / Dynamic Island — are feature-detected, not stubbed with a fake Android widget. Ads are role-gated: Imam and Muezzin screens stay clean while they are on duty.

  1. Shared domain models (masjid, session, role) live in the app and are mirrored on the API — we do not let the two drift silently.
  2. The API is the permission source. The UI hides buttons, but a forged HTTP call still 403s.
  3. Qibla and Tasbih work offline. Prayer times and live features require the network, which we state in FAQ copy so AI snippets stay accurate.

Why five roles, not one “admin” flag

Masjid politics is not a SaaS “owner vs user” checkbox. A Muezzin must start Azan without seeing donation ledgers. An Imam must answer Ask Imam without being the only person who can approve members.

Who can do what Member Listen to Azan Ask Imam Cannot publish live Muezzin Start Live Azan Publisher token Imam Azan + Khutbah Answer Ask Imam Mutawalli Members + roles Announcements Admin Full masjid settings
Figure 2. Role capabilities in production. Live publish rights are never granted to the Member role.
RoleTypical personMust haveMust not have
MemberWorshipperListen, Ask Imam, SadaqahLive publish, finance write
MuezzinCaller of AzanPublisher token for AzanFull ledger
ImamReligious leadAzan + Khutbah, answersSilent role changes for the whole committee
MutawalliTrusteeMembers, announcements, KYCNeed to be the microphone every Salah
AdminCommittee operatorSettings, staff snapshot restoreBypass KYC for Sadaqah

When a masjid is deactivated we snapshot the staff roster so reactivation does not force every Imam to re-onboard from zero. That is a community-ops detail you will not find on a generic “mosque app” landing page.

What lives on the server vs on-device

How we ship without a 20-person DevOps team

  1. The API and the live-audio server run as two separate services. Hostnames stay stable if the region changes.
  2. The API stays warm. Maghrib is not a cold start.
  3. Secrets are injected at runtime — media credentials never sit in the app or in Git.
  4. Website on Cloudflare Pages: static HTML, one CSS file, SVG diagrams. That is the Core Web Vitals strategy — less JavaScript, not more.

Related: Live Azan VoIP · Ask Imam · About.