What Technologies Are Used in the Securo Backend API? A Complete Tech Stack Breakdown

The Securo backend API is built on Python with FastAPI as the web framework, SQLAlchemy with AsyncPG for database operations, Celery with Redis for background tasks, and Pydantic for configuration management.

Securo's backend is a production-ready, asynchronous Python service designed for financial data processing. According to the securo-finance/securo source code, the technology stack is explicitly declared in backend/pyproject.toml and documented in the README's Tech Stack section. This article breaks down every layer of the architecture with direct references to the codebase.

Web Framework and Server Layer

FastAPI for API Endpoints

The core web framework is FastAPI (>=0.109.0), chosen for its automatic OpenAPI documentation generation and native type checking. In backend/app/main.py, the application is instantiated with configuration-driven settings:


# File: backend/app/main.py

from fastapi import FastAPI, Depends
from app.api.accounts import router as accounts_router
from app.core.config import get_settings

settings = get_settings()

app = FastAPI(
    title=settings.app_name,
    openapi_url="/api/openapi.json",
    docs_url="/api/docs",
)

# Mount routers

app.include_router(accounts_router, prefix="/api/accounts")

This pattern demonstrates modular router architecture — each domain (accounts, transactions, assets) lives in its own FastAPI router under app/api/ and is mounted centrally.

Uvicorn ASGI Server

Uvicorn (>=0.27.0) serves as the ASGI server for production deployments. The combination of FastAPI + Uvicorn enables full async/await support across all endpoints.

Database and ORM Technologies

SQLAlchemy 2.0 with AsyncPG

The data layer uses SQLAlchemy (>=2.0.0) paired with AsyncPG (>=0.29.0) for asynchronous PostgreSQL operations. This async-first design ensures non-blocking database queries throughout the API.

Alembic for Schema Migrations

Alembic (>=1.13.0) handles all database schema migrations, maintaining version control for structural changes.

Configuration and Settings Management

Pydantic Settings for Environment Variables

Pydantic (>=2.5.0) and Pydantic-Settings (>=2.5.0) provide strongly-typed configuration from environment variables. The backend/app/core/config.py file defines the central Settings class:


# File: backend/app/core/config.py

from pydantic_settings import BaseSettings

class Settings(BaseSettings):
    app_name: str = "Securo"
    frontend_url: str
    database_url: str
    redis_url: str
    # … many more env‑vars

    class Config:
        env_file = ".env"

This pattern enables config-driven feature flags — optional capabilities like AI agents or OIDC login are gated at import time based on environment variables.

Authentication and Security Stack

Securo implements a multi-layered authentication system using four specialized libraries:

  • Python-Jose (>=3.3.0) — JWT token handling
  • Cryptography (==46.0.7) — Low-level cryptographic operations
  • Passlib (>=1.7.4) — Password hashing
  • FastAPI-Users (>=13.0.0) — Ready-made user management integration

The backend/app/core/auth.py file configures FastAPI-Users with JWT authentication. Protected endpoints use FastAPI's dependency injection:


# File: backend/app/api/accounts.py

from fastapi import APIRouter, Depends
from app.core.auth import fastapi_users

router = APIRouter()

@router.get("/me")
async def read_current_user(user=Depends(fastapi_users.current_user())):
    return {"email": user.email, "id": user.id}

Two-Factor and WebAuthn Support

Additional security layers include pyotp for TOTP-based 2FA and webauthn for passkey authentication.

Background Processing Architecture

Celery with Redis Broker

Celery (>=5.3.0) with Redis (>=5.0.0) powers the asynchronous task queue. The backend/app/worker.py file defines the Celery application, while backend/app/tasks/ contains domain-specific task definitions.


# File: backend/app/tasks/sync_tasks.py

from app.worker import celery_app

@celery_app.task(name="app.tasks.sync_tasks.sync_all_connections")
def sync_all_connections():
    # Logic that iterates over connections and triggers provider refreshes

    ...

Celery handles heavy operations including:

  • Bank connection synchronization
  • Foreign exchange rate updates
  • Asset growth calculations
  • AI agent data ingestion

HTTP Client and External Integrations

HTTPX for Async HTTP Requests

httpx (>=0.26.0) serves as the async HTTP client for external API calls, particularly to bank providers and financial data services.

File Handling and Financial Data Processing

The backend includes specialized libraries for financial document processing:

Library Purpose
python-multipart Form-data and file upload handling
ofxparse OFX (Open Financial Exchange) file parsing
yfinance Market data retrieval
pgvector Vector search capabilities for embeddings
pypdf PDF document parsing
pyzipper Encrypted ZIP archive creation

AI and Embedding Technologies

FastEmbed for Vector Embeddings

fastembed (>=0.4.0) provides optional knowledge-base embeddings for AI agents. When enabled via feature flag, this integrates with pgvector in PostgreSQL for semantic search capabilities.

Key Architectural Patterns in Securo's Backend

Based on the source code analysis, three patterns define the Securo backend API architecture:

  1. Async-first design — All endpoints and database interactions leverage asyncio, httpx, and SQLAlchemy's async engine. No synchronous I/O blocks the event loop.

  2. Dependency injection — FastAPI's Depends system handles authentication, rate-limiting, and workspace resolution through app/core/ modules.

  3. Modular domain separation — Each business domain (accounts, transactions, assets) implements its own router, models, and tasks, mounted centrally in app/main.py.

Summary

  • Core framework: FastAPI (>=0.109.0) with Uvicorn ASGI server
  • Database layer: SQLAlchemy 2.0 + AsyncPG for async PostgreSQL operations, Alembic for migrations
  • Configuration: Pydantic Settings for type-safe environment variable management
  • Authentication: FastAPI-Users with JWT (Python-Jose), Passlib for hashing, plus pyotp and webauthn for 2FA/passkeys
  • Background jobs: Celery (>=5.3.0) with Redis broker for async task processing
  • HTTP client: httpx for external API integrations
  • Financial data: Specialized libraries including ofxparse, yfinance, pypdf, and pgvector
  • Optional AI: fastembed for knowledge-base embeddings when feature-enabled

Frequently Asked Questions

What Python version does Securo require?

The pyproject.toml specifies Python 3.11 or higher, leveraging modern asyncio features and type hint syntax that FastAPI and Pydantic v2 fully utilize.

How does Securo handle database migrations?

Securo uses Alembic (>=1.13.0) for schema migrations. Migration scripts are maintained alongside the SQLAlchemy model definitions, with revision history tracked in the repository.

Is Securo's backend fully asynchronous?

Yes. Every layer — from FastAPI endpoints through SQLAlchemy's async engine to httpx HTTP requests — uses async/await patterns. Even Celery tasks integrate with async code where beneficial, though Celery itself runs tasks in worker processes.

What caching and task queue system does Securo use?

Redis serves double duty: as the Celery message broker for background task distribution and as a general-purpose cache layer for session storage and rate limiting.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →