A production-style fintech backend that simulates core payment platform behavior: authentication, user profile management, wallet operations, transfers, transaction history, and asynchronous notifications.
This project is designed to demonstrate real backend engineering practices for hiring review:
- Microservices architecture
- Clean architecture boundaries
- REST + gRPC communication
- Event-driven notifications
- Security, observability, and test coverage
Auth Service: register/login with JWT + bcrypt password hashingUser Service: CRUD user profiles with Redis read cacheWallet Service: create wallet, deposit, withdraw, transfer, transaction historyNotification Service: Kafka-based event consumer for mock email/SMS notificationsAPI Gateway: public entrypoint with JWT auth and rate limiting
Client (Web/Mobile/Postman/curl)
|
v
+------------------------------+
| API Gateway |
| REST, JWT, Rate Limiting |
+---------------+--------------+
|
| gRPC
+------------+------------+----------------+
| | |
v v v
+---------+ +-------------+ +------------+
| Auth | | User | | Wallet |
| Service | | Service | | Service |
+----+----+ +------+------+ +------+-----+
| | |
+-----------------------+-----------------+
|
v
+------------------+
| PostgreSQL |
+------------------+
|
v
+------------------+
| Redis |
+------------------+
Auth/Wallet events --> Kafka topic (notifications.v1) --> Notification Service
- Language:
Go 1.22 - HTTP framework:
Gin - RPC:
gRPC - Database:
PostgreSQL(pgx) - Cache:
Redis - Message broker:
Kafka(Redpanda in Compose) - Logging:
Zapstructured logs - Metrics:
Prometheusformat endpoints (/metrics) - Testing:
testing+testify - DevOps:
Docker,Docker Compose,GitHub Actions
.
├── services/
│ ├── api-gateway/
│ ├── auth-service/
│ ├── user-service/
│ ├── wallet-service/
│ └── notification-service/
├── shared/
│ ├── config/
│ ├── contracts/ # gRPC contracts/descriptors
│ ├── db/
│ ├── cache/
│ ├── events/
│ ├── middleware/
│ ├── metrics/
│ ├── security/
│ └── grpcx/
├── build/Dockerfile
├── docker-compose.yml
├── Makefile
├── scripts/
└── .github/workflows/ci.yml
- Docker Desktop (running)
docker compose up --build -d
docker compose psGateway will be available at:
http://localhost:8080
docker compose downYou need PostgreSQL, Redis, and Kafka running first.
go run ./services/auth-service/cmd
go run ./services/user-service/cmd
go run ./services/wallet-service/cmd
go run ./services/notification-service/cmd
go run ./services/api-gateway/cmdUse .env.example as reference.
Important variables:
JWT_SECRETPOSTGRES_URLREDIS_ADDRKAFKA_BROKERSAUTH_GRPC_ADDR,USER_GRPC_ADDR,WALLET_GRPC_ADDR
Base URL: http://localhost:8080/api/v1
POST /auth/registerPOST /auth/login
POST /users/GET /users/GET /users/:idPUT /users/:idDELETE /users/:id
POST /wallets/GET /wallets/:user_idPOST /wallets/:user_id/depositPOST /wallets/:user_id/withdrawPOST /wallets/transferGET /wallets/:user_id/transactions
curl -X POST http://localhost:8080/api/v1/auth/register \
-H "Content-Type: application/json" \
-d '{"email":"[email protected]","password":"SecurePass123"}'curl -X POST http://localhost:8080/api/v1/auth/login \
-H "Content-Type: application/json" \
-d '{"email":"[email protected]","password":"SecurePass123"}'curl -X POST http://localhost:8080/api/v1/users/ \
-H "Authorization: Bearer <JWT_TOKEN>" \
-H "Content-Type: application/json" \
-d '{"email":"[email protected]","full_name":"John Doe","phone":"989111111111"}'curl -X POST http://localhost:8080/api/v1/wallets/ \
-H "Authorization: Bearer <JWT_TOKEN>" \
-H "Content-Type: application/json" \
-d '{"user_id":"<AUTH_USER_UUID>","currency":"USD"}'curl -X POST http://localhost:8080/api/v1/wallets/<AUTH_USER_UUID>/deposit \
-H "Authorization: Bearer <JWT_TOKEN>" \
-H "Content-Type: application/json" \
-d '{"amount":"100.00","reference":"salary"}'curl -X POST http://localhost:8080/api/v1/wallets/transfer \
-H "Authorization: Bearer <JWT_TOKEN>" \
-H "Content-Type: application/json" \
-d '{"from_user_id":"<FROM_AUTH_UUID>","to_user_id":"<TO_AUTH_UUID>","amount":"25.00","reference":"p2p-transfer"}'- Bcrypt password hashing
- JWT authentication middleware in gateway
- Input validation with
validator/v10 - Rate limiting with
x/time/rate - Clear transport boundary between public REST and internal gRPC
Each service exposes:
GET /healthGET /metrics
This is Prometheus/Grafana-ready.
go test ./...make test
make coverageCoverage gate in CI: >= 70%.
GitHub Actions workflow:
go mod tidygo test ./...- Coverage suite + threshold check
go build ./...docker compose config
Validated on this machine:
go test ./...passed- Docker Compose stack starts successfully
- Services healthy and reachable
- End-to-end flow passed:
- register/login
- user create/get
- wallet create
- deposit/withdraw/transfer
- transaction history