Build services
SaaS Developer: Build a SaaS Website or Product
I am a freelance SaaS developer. I build SaaS websites, products and customer portals for founders and hosting companies: a Laravel application with a Filament admin panel, Stripe, PayPal or Razorpay billing, roles, background jobs and an API, deployed to your server and handed over with the code.
By Shahid Malla, WHMCS developer and hosting infrastructure engineer · Updated
What does a SaaS build with me include?
It includes the application, an admin panel for your team, billing, deployment and a handover, delivered as one project. I take a product from a written scope to a live, paid-for service that your own staff can run. This site runs on the same stack: Laravel with Filament.
A hosting company often wants a customer portal or reseller dashboard next to WHMCS. In that case I connect the portal to WHMCS through its API, so client and billing records are not duplicated. See WHMCS API integration.
How do you scope an MVP?
I cut the product down to one type of user, one job they need done and one way they pay. Everything else goes on a deferred list. The written scope covers user roles, the core workflow, stored data, the billing model and what is deliberately left out.
| Stage | What is delivered |
|---|---|
| Scope | Written scope: roles, core workflow, data entities, billing model and the deferred list. |
| Design | Database schema, main screens and an API outline, reviewed with you before code. |
| Core build | Sign-up, login, the core workflow and the Filament admin panel running in staging. |
| Billing | Plans, checkout, webhook handling, receipts and states for failed payments. |
| Hardening | Automated tests on billing and permissions, rate limits, error tracking and backups. |
| Launch | Production deployment, live payment keys, queue workers, scheduler and a real test payment. |
| Handover | Repository, environment notes, deployment and restore steps, and a walkthrough call. |
Which stack do you build SaaS products with?
My main stack is Laravel with Filament admin panels, Livewire where it fits, and MySQL for data. One framework covers authentication, validation, queues, scheduling, mail and testing, so the budget goes to your product's own logic.
- Laravel and Filament: the application, plus the internal panel for users, subscriptions, refunds and settings.
- Livewire: interactive screens such as dashboards and forms, without a separate JavaScript application.
- Next.js, React or Astro: added when the project calls for them, such as a public marketing site.
- Node.js or NestJS: an API service for real-time connections, an existing TypeScript team, or a component that does not belong in PHP.
I do not add a second language where one is enough. Every extra service is another thing to deploy, monitor and pay for.
How is subscription billing built?
The payment provider is the source of truth for money, and your database follows it through webhooks. A browser redirect alone never proves a payment succeeded.
Providers send events such as invoice.paid and customer.subscription.deleted (Stripe) or subscription.charged and subscription.halted (Razorpay). The webhook endpoint has to handle them safely:
- Verify the signature on every request, using the
Stripe-SignatureorX-Razorpay-Signatureheader, before trusting the body. - Store each event ID and skip repeats, because providers retry and can deliver events twice or out of order.
- Hand the real work to a queued job and answer the provider quickly.
- Model the states you need: trialing, active, past due and cancelled, with a grace period for failed cards.
Plan limits stay in your own code, so a second provider can be added without a rewrite. With the provider's hosted checkout or card fields, card numbers never touch your server.
How do roles, queues and the API fit together?
They are three separate layers, designed up front instead of bolted on later.
Roles and permissions. I separate platform staff, account owners and team members. Access rules live in Laravel policies, so users reach only their own account's records, and sensitive actions such as refunds go into an audit log.
Queues and scheduled jobs. Emails, webhook processing, report exports and calls to outside APIs run as queued jobs with retries and a failed-jobs table you can inspect. Recurring work such as renewal reminders runs from Laravel's scheduler, which needs one cron entry:
* * * * * cd /path/to/app && php artisan schedule:run >> /dev/null 2>&1
API. If customers need an API, I version it from the first route (/api/v1), use token authentication, set per-key rate limits, return one consistent error format and sign outgoing webhooks.
Which multi-tenancy option fits my product?
None is correct for every product. The choice depends on how much isolation customers need and how many of them you expect. Many early products need less than their founders think.
| Option | How it works | Fits when | Trade-off |
|---|---|---|---|
| Shared database, tenant column | Every table carries an account ID and queries are scoped to it. | Many small customers and a fast start. | A scoping bug can expose another customer's data, so tests must cover it. |
| Database per tenant | Each customer has a database, selected on every request. | Strong isolation, per-customer restores, data residency rules. | Migrations and monitoring run once per tenant. |
| Separate install per customer | Each customer gets their own copy of the app and database. | A few high-value customers with custom changes, similar to hosting. | Every update must be rolled out to each copy, so automation is needed. |
Packages such as stancl/tenancy and spatie/laravel-multitenancy cover parts of the database-per-tenant route. I settle the choice in the scope document, because changing it later means rewriting the data layer.
Where can the product be deployed?
It can run on a VPS or on a cPanel host, and I choose by workload. A small first version often fits cPanel. A product with constant background work fits a VPS better.
On a VPS I set up Nginx or Apache, PHP-FPM, MySQL, a Supervisor-managed queue worker, TLS and backups, as described under server setup. On cPanel I point the domain's document root at Laravel's public directory, add the scheduler cron above and run the queue from cron with php artisan queue:work --stop-when-empty. Each release runs php artisan migrate --force, rebuilds the config and route caches and restarts workers with php artisan queue:restart.
What should a first version leave out?
A first version should leave out anything no paying customer has asked for yet. Each extra feature adds code to test and support, and delays the day you learn whether anyone will pay.
- Native mobile apps. A responsive web app tests the idea faster.
- Single sign-on (SAML) and custom role builders, until an enterprise buyer requires them.
- Usage-based metering and complex proration, unless usage is what you sell.
- Many languages and currencies beyond your first two or three markets.
- Reporting dashboards with many charts. Start with the three numbers you check daily.
- A public API, plugin system, white-labelling, referral schemes and in-app chat.
These stay on the deferred list, planned for but not built.
What do I get at handover, and who owns the code?
At handover you receive the repository, environment variables, deployment and rollback steps, backup restore instructions and a walkthrough call. Who holds the rights to the custom code is written into the quote before work starts. Open-source and premium packages keep their own licenses. See how I work for how a project runs.
Which SaaS projects do I decline?
I do not copy another company's product or use nulled or pirated scripts. I am not a brand design studio, so I expect a logo and colors from you or your designer. I do not certify products against standards such as PCI DSS or SOC 2. I keep card data with the payment provider and follow sound security practice, but certification is a separate process.
How long does a SaaS build take, and what does it cost?
It depends on scope. I quote a fixed price after the scoping call, or work hourly at $55 to $65 per hour. If you already run WHMCS and want the product to bill through it, a custom WHMCS module may be the shorter route. For an assistant inside the product, see AI agent development.
Who this is for
- Founders who need a first version that real customers can pay for, not a prototype
- Hosting companies that want a customer portal, reseller dashboard or add-on service next to WHMCS
- Agencies and small teams that need a Laravel developer for one product rather than a retainer
- Owners of an existing PHP or WordPress tool that has to become a subscription product
What is included
- Written scope with roles, core workflow and a list of deferred features
- Laravel application with a Filament admin panel for your team
- Subscription billing with signed, repeat-safe webhook handling
- Roles, permissions and an audit log for sensitive actions
- Queues and scheduled jobs configured and documented
- Automated tests on billing, permissions and the core workflow
- Production deployment on your VPS or cPanel host
- Repository transfer, deployment notes and a handover call
How the work runs
-
1
Scope
In a free call of about 30 minutes I ask who uses the product, what they do first and how they pay. You get a written scope with a short feature list and a longer list of things that wait.
-
2
Design the data
I draw the database schema, roles and main screens and share them for one review round. Changing a diagram is cheap. Changing a billing table after launch is not.
-
3
Build in slices
I work in a staging copy and ship working slices, starting with sign-up and the core workflow. You get a daily progress update and can click through each slice yourself.
-
4
Launch
I deploy to production, connect the live payment keys, make a real test payment and watch the first queue runs and webhooks arrive.
-
5
Hand over
You receive the repository, environment notes and deployment steps. Two weeks of support follow, covering defects in the delivered scope.
Frequently asked questions
How long does it take to build a SaaS MVP?
It depends on scope. A product with one core workflow, sign-up, a single billing plan and a basic admin panel sits at the short end. Each extra role, integration or report adds time. I give a date after the scoping call, once the feature list is written down, and not before.
Why Laravel and Filament for a SaaS product?
Laravel has authentication, queues, scheduling, validation and testing built in, so the budget goes into your product instead of plumbing. Filament gives your team an admin panel for users, subscriptions and support lookups quickly. This website runs on Laravel and Filament. If your team already works in another stack, I will say so and we can weigh the trade-off before you commit.
Which payment provider should I use for subscriptions?
Choose by where your customers pay. Stripe suits card payments in many countries. Razorpay suits customers paying in India by UPI, card or net banking. PayPal suits buyers who trust it more than a card form. I keep plan logic separate from the provider, so adding a second one later is a smaller job. Availability depends on your business country and each provider's approval.
Can the product run on cPanel shared hosting?
Often yes, for a small first version. Laravel needs a current PHP version, the right extensions and a document root pointing at its public folder, and background jobs run from cron instead of a permanent worker. A VPS is the better choice once you need always-running queue workers, Redis or heavier traffic. I recommend based on your workload, not by habit.
Can you add billing or features to an app I already have?
Yes, for a defined piece of work such as subscription billing, a customer portal or a new module. I read the code first and tell you what I find before I quote. I work on a staging copy, and I do not work on pirated or unlicensed scripts. Where the codebase is too fragile to extend safely, I say so and explain the options.
Who owns the code and the customer data?
Who holds the rights to the custom code is written into the quote before work starts. The repository is transferred to you at handover, the database sits on your server and the payment provider accounts are in your name, so you hold the customer data and the credentials. Open-source packages keep their own licenses. I ask for temporary access to your servers where possible.
What does a SaaS build cost?
I quote a fixed price for a written scope, or work hourly at $55 to $65 per hour. The price follows the number of roles, billing rules, integrations and screens. Hosting, domain and payment provider fees are billed to you directly by those companies. The scoping call is free and the quote arrives within one business day.
Related services
-
WHMCS API Integration and Automation
I connect WHMCS to your CRM, Slack or Telegram, SMS, accounting and control panels with the API, localAPI() an...
-
AI Agent Development: Hire an AI Agent Developer
AI agent development for hosting and SaaS teams: agents that answer tickets from your knowledge base, update W...
-
WHMCS Custom Module Development
I build custom WHMCS modules for provisioning, addon, gateway and registrar jobs. Specced in writing, tested i...
-
Linux Server Setup and Management
I set up, secure, migrate, back up and monitor Linux servers, with cPanel and WHM or with no control panel. Ev...
Ready to talk about your project?
Send the details and I reply within one business day with questions, an estimate and a plan.