What Technologies Are Used in the Securo Backend API? A Complete Tech Stack Breakdown
The Securo backend API is built on Python with FastAPI as the web framework, SQLAlchemy with AsyncPG for database operations, Celery with Redis for background tasks, and Pydantic for configuration management.
Securo's backend is a production-ready, asynchronous Python service designed for financial data processing. According to the securo-finance/securo source code, the technology stack is explicitly declared in backend/pyproject.toml and documented in the README's Tech Stack section. This article breaks down every layer of the architecture with direct references to the codebase.
Web Framework and Server Layer
FastAPI for API Endpoints
The core web framework is FastAPI (>=0.109.0), chosen for its automatic OpenAPI documentation generation and native type checking. In backend/app/main.py, the application is instantiated with configuration-driven settings:
# File: backend/app/main.py
from fastapi import FastAPI, Depends
from app.api.accounts import router as accounts_router
from app.core.config import get_settings
settings = get_settings()
app = FastAPI(
title=settings.app_name,
openapi_url="/api/openapi.json",
docs_url="/api/docs",
)
# Mount routers
app.include_router(accounts_router, prefix="/api/accounts")
This pattern demonstrates modular router architecture — each domain (accounts, transactions, assets) lives in its own FastAPI router under app/api/ and is mounted centrally.
Uvicorn ASGI Server
Uvicorn (>=0.27.0) serves as the ASGI server for production deployments. The combination of FastAPI + Uvicorn enables full async/await support across all endpoints.
Database and ORM Technologies
SQLAlchemy 2.0 with AsyncPG
The data layer uses SQLAlchemy (>=2.0.0) paired with AsyncPG (>=0.29.0) for asynchronous PostgreSQL operations. This async-first design ensures non-blocking database queries throughout the API.
Alembic for Schema Migrations
Alembic (>=1.13.0) handles all database schema migrations, maintaining version control for structural changes.
Configuration and Settings Management
Pydantic Settings for Environment Variables
Pydantic (>=2.5.0) and Pydantic-Settings (>=2.5.0) provide strongly-typed configuration from environment variables. The backend/app/core/config.py file defines the central Settings class:
# File: backend/app/core/config.py
from pydantic_settings import BaseSettings
class Settings(BaseSettings):
app_name: str = "Securo"
frontend_url: str
database_url: str
redis_url: str
# … many more env‑vars
class Config:
env_file = ".env"
This pattern enables config-driven feature flags — optional capabilities like AI agents or OIDC login are gated at import time based on environment variables.
Authentication and Security Stack
Securo implements a multi-layered authentication system using four specialized libraries:
- Python-Jose (
>=3.3.0) — JWT token handling - Cryptography (
==46.0.7) — Low-level cryptographic operations - Passlib (
>=1.7.4) — Password hashing - FastAPI-Users (
>=13.0.0) — Ready-made user management integration
The backend/app/core/auth.py file configures FastAPI-Users with JWT authentication. Protected endpoints use FastAPI's dependency injection:
# File: backend/app/api/accounts.py
from fastapi import APIRouter, Depends
from app.core.auth import fastapi_users
router = APIRouter()
@router.get("/me")
async def read_current_user(user=Depends(fastapi_users.current_user())):
return {"email": user.email, "id": user.id}
Two-Factor and WebAuthn Support
Additional security layers include pyotp for TOTP-based 2FA and webauthn for passkey authentication.
Background Processing Architecture
Celery with Redis Broker
Celery (>=5.3.0) with Redis (>=5.0.0) powers the asynchronous task queue. The backend/app/worker.py file defines the Celery application, while backend/app/tasks/ contains domain-specific task definitions.
# File: backend/app/tasks/sync_tasks.py
from app.worker import celery_app
@celery_app.task(name="app.tasks.sync_tasks.sync_all_connections")
def sync_all_connections():
# Logic that iterates over connections and triggers provider refreshes
...
Celery handles heavy operations including:
- Bank connection synchronization
- Foreign exchange rate updates
- Asset growth calculations
- AI agent data ingestion
HTTP Client and External Integrations
HTTPX for Async HTTP Requests
httpx (>=0.26.0) serves as the async HTTP client for external API calls, particularly to bank providers and financial data services.
File Handling and Financial Data Processing
The backend includes specialized libraries for financial document processing:
| Library | Purpose |
|---|---|
| python-multipart | Form-data and file upload handling |
| ofxparse | OFX (Open Financial Exchange) file parsing |
| yfinance | Market data retrieval |
| pgvector | Vector search capabilities for embeddings |
| pypdf | PDF document parsing |
| pyzipper | Encrypted ZIP archive creation |
AI and Embedding Technologies
FastEmbed for Vector Embeddings
fastembed (>=0.4.0) provides optional knowledge-base embeddings for AI agents. When enabled via feature flag, this integrates with pgvector in PostgreSQL for semantic search capabilities.
Key Architectural Patterns in Securo's Backend
Based on the source code analysis, three patterns define the Securo backend API architecture:
-
Async-first design — All endpoints and database interactions leverage
asyncio,httpx, and SQLAlchemy's async engine. No synchronous I/O blocks the event loop. -
Dependency injection — FastAPI's
Dependssystem handles authentication, rate-limiting, and workspace resolution throughapp/core/modules. -
Modular domain separation — Each business domain (accounts, transactions, assets) implements its own router, models, and tasks, mounted centrally in
app/main.py.
Summary
- Core framework: FastAPI (
>=0.109.0) with Uvicorn ASGI server - Database layer: SQLAlchemy 2.0 + AsyncPG for async PostgreSQL operations, Alembic for migrations
- Configuration: Pydantic Settings for type-safe environment variable management
- Authentication: FastAPI-Users with JWT (Python-Jose), Passlib for hashing, plus pyotp and webauthn for 2FA/passkeys
- Background jobs: Celery (
>=5.3.0) with Redis broker for async task processing - HTTP client: httpx for external API integrations
- Financial data: Specialized libraries including ofxparse, yfinance, pypdf, and pgvector
- Optional AI: fastembed for knowledge-base embeddings when feature-enabled
Frequently Asked Questions
What Python version does Securo require?
The pyproject.toml specifies Python 3.11 or higher, leveraging modern asyncio features and type hint syntax that FastAPI and Pydantic v2 fully utilize.
How does Securo handle database migrations?
Securo uses Alembic (>=1.13.0) for schema migrations. Migration scripts are maintained alongside the SQLAlchemy model definitions, with revision history tracked in the repository.
Is Securo's backend fully asynchronous?
Yes. Every layer — from FastAPI endpoints through SQLAlchemy's async engine to httpx HTTP requests — uses async/await patterns. Even Celery tasks integrate with async code where beneficial, though Celery itself runs tasks in worker processes.
What caching and task queue system does Securo use?
Redis serves double duty: as the Celery message broker for background task distribution and as a general-purpose cache layer for session storage and rate limiting.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →