Skip to content
CAI
Software that uses CAICheck a score

fastapi/full-stack-fastapi-template

72.8

Strong · 20 September 2026

7.8k

lines of production code

TypeScript

with Python

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a full-stack web application scaffold built with a FastAPI backend and a React frontend, designed to provide a secure, modern foundation for user management and item tracking. It features JWT-based authentication, role-based access control, and transactional email workflows, all orchestrated via Docker Compose for local development and deployment. The codebase emphasizes developer experience through automated linting, type-safe API client generation, and comprehensive end-to-end testing infrastructure.

How it got here

2019 — Initial scaffolding and legacy cleanup

9 changes.

The project was initialized with a modern development stack using Docker Compose, Bun, and uv, replacing the previous cookiecutter-based workflow. This period involved stripping out legacy Couchbase backend code, Vue frontend sources, and outdated Docker build scripts to establish a clean, FastAPI-centric foundation.

2020–2026 — Full-stack modernization and security hardening

19 changes.

This period involved a comprehensive overhaul of both the backend and frontend to modernize the technology stack and enhance security. The backend migrated to UUIDs, centralized configuration, and robust authentication using PyJWT and Argon2, while the frontend was rebuilt with Vite, React, TypeScript, and Shadcn UI. Comprehensive test suites and automated tooling were established to support these structural changes.

Features

Added agent skills for FastAPI and SQLModel

Agent skills for the FastAPI and SQLModel libraries are now available in both the \.agents/skills\ and \.claude/skills\ directories. These changes introduce symlinks pointing to the skills bundled within the installed packages (\fastapi\ and \sqlmodel\) and include the \library-skills\ tool skill definition, enabling agents to automatically discover and utilize these library-specific capabilities.

.agents, .claude · high confidence

Frontend application bootstrap and core infrastructure setup

The frontend application is initialized with a new entry point (\main.tsx\) that configures TanStack Query for data fetching and TanStack Router for navigation, including logic to redirect users to the login page upon receiving 401/403 errors. The visual layer is established via a new \index.css\ file defining Tailwind CSS theme variables for both light and dark modes, while TypeScript support for Vite environment variables is added through \vite-env.d.ts\.

frontend/src · high confidence

Initial project scaffolding with Docker Compose, Bun, and pre-commit hooks

The repository is initialized with a complete development and deployment structure. Local development is supported via Docker Compose (compose.yml, compose.override.yml) which orchestrates the backend, PostgreSQL, Mailpit, and a Traefik proxy, alongside a Bun-based frontend build system (bun.lock). Deployment is configured for both self-hosted servers (compose.deploy.yml) and FastAPI Cloud (deployment.md, .fastapicloudignore). The developer experience is enhanced by a comprehensive pre-commit configuration (.pre-commit-config.yaml) that enforces linting with Ruff and Biome, type checking with MyPy and Ty, and automated frontend SDK generation. Configuration defaults are provided in .env, and infrastructure is ignored appropriately via .dockerignore.

(repo-wide) · high confidence

Removals

Frontend application source code removed

The entire frontend source code directory has been deleted, including all Vue components, Vuex store modules, routing configuration, API client logic, and build assets. This removes the client-side application from the project.

_{{cookiecutter.project\slug}}/frontend · high confidence

Removal of Couchbase-based backend implementation

The application's backend implementation, which relied on Couchbase for data storage and Celery for background tasks, has been completely removed. This change deletes the API endpoints for user and role management, the authentication and password recovery logic, the SQLAlchemy models and CRUD operations, the database initialization scripts, and the email templates. The system no longer supports the previous Couchbase architecture.

_{{cookiecutter.project\slug}}/backend/app/app · high confidence

Removal of legacy Docker Compose build and deployment scripts

The shell scripts responsible for building, pushing, and deploying the application via Docker Compose have been removed. This includes \build.sh\ and \build-push.sh\ (which generated \docker-stack.yml\ and executed \docker-compose\ commands), \deploy.sh\ (which orchestrated the stack deployment with Traefik labels), and \test.sh\ and \test-local.sh\ (which managed test environment builds and execution). Users relying on these specific scripts for CI/CD or local development workflows will need to adopt the new simplified Docker Compose and deployment structure introduced in this change.

_{{cookiecutter.project\slug}}/scripts · high confidence

Removal of legacy Dockerfiles and .gitignore

The legacy Docker build files (backend.dockerfile, celeryworker.dockerfile, tests.dockerfile) and the .gitignore file have been removed from the backend directory. This indicates a shift away from the previous manual Docker image construction approach, likely in favor of a different build or deployment mechanism (such as Poetry-based builds or a unified Dockerfile not shown in this specific diff excerpt).

_{{cookiecutter.project\slug}}/backend · high confidence

Removal of legacy linting script

The \lint.sh\ script, which previously executed autoflake, isort, and black to format Python code, has been removed from the backend application scripts. This change eliminates the manual linting entry point, implying that code formatting is now handled by other tooling or integrated development workflows rather than this standalone shell script.

_{{cookiecutter.project\slug}}/backend/app/scripts · high confidence

Behavioural changes

Admin route access restricted to superusers and dashboard displays logged-in user

The admin route now enforces superuser-only access by redirecting non-superusers to the home page, ensuring that only authorized administrators can manage user accounts. Additionally, the dashboard page has been updated to display a personalized greeting using the currently logged-in user's full name or email, improving the welcome experience for returning users.

_frontend/src/routes/\layout · high confidence

Alembic now reads database configuration from the centralized settings

The Alembic environment has been updated to retrieve the database connection URL directly from the application's centralized configuration settings (via \settings.DATABASE\_URL\) rather than relying on the \sqlalchemy.url\ value defined in the Alembic \.ini\ file. This ensures that database migrations consistently use the same connection parameters as the rest of the application, simplifying configuration management by removing the need to maintain separate database connection strings in the migration config.

backend/app/alembic · high confidence

Centralized API dependency injection and router configuration

The API layer now uses a dedicated dependency injection module (deps.py) to handle database sessions and JWT-based user authentication, replacing previous inline or scattered implementations. The main router (main.py) explicitly aggregates all route modules (login, users, utils, items) and conditionally includes the private router only in development environments, providing a clearer and more maintainable structure for API endpoint registration.

backend/app/api · high confidence

Core configuration and security infrastructure overhaul

The backend core module has been restructured to enforce stricter security and modernize dependencies. Configuration is now centralized in a Pydantic-based \Settings\ class that requires an explicit \SECRET\_KEY\ (rejecting the default 'changethis' value in production), uses a unified \DATABASE\_URL\ with automatic psycopg driver injection, and simplifies CORS by including the frontend host by default. Security has been upgraded by migrating from python-jose to PyJWT for token handling and adopting pwdlib with Argon2 as the default password hasher, while maintaining backward compatibility with existing Bcrypt hashes. Additionally, the codebase now uses \datetime.now(UTC)\ instead of the deprecated \utcnow()\ and enforces \EmailStr\ types for email fields.

backend/app/core · high confidence

Database schema modernization and security hardening

The backend database schema has been updated to use UUIDs instead of integer IDs for Users and Items, with a migration that preserves existing data. A new \created\_at\ timestamp field has been added to both models. To improve data integrity, string fields (email, name, title, description) now have explicit 255-character limits, and deleting a User will automatically cascade-delete their associated Items. Security has been strengthened by implementing constant-time password verification to prevent timing attacks during authentication.

backend/app · high confidence

Frontend components migrated to Shadcn UI and TanStack Query

The frontend components in this area have been rewritten to use the Shadcn UI component library (imported from @/components/ui) and TanStack Query for data fetching and mutations, replacing the previous Chakra UI and React Query implementations. This change updates the visual design and interaction patterns for user and item management (Add, Edit, Delete dialogs and tables), as well as common layout elements like the sidebar, footer, and theme switcher, to align with the new Shadcn-based design system.

frontend/src/components · high confidence

Frontend scaffolded with Vite, React, TypeScript, and Bun

The frontend has been restructured into a modern Vite + React + TypeScript application using Bun as the package manager. This change introduces a new build configuration (vite.config.ts) that serves the frontend from the FastAPI backend, sets up path aliases for cleaner imports, and integrates Tailwind CSS and TanStack Router. It also establishes a new code quality workflow using Biome for linting and formatting, configures an auto-generated OpenAPI client via @hey-api/openapi-ts, and adds initial Playwright end-to-end testing infrastructure.

frontend · high confidence

Introduce release automation and update development scripts

The scripts directory now includes new automation tools for managing releases, specifically \prepare\_release.py\ which handles version bumping and release note extraction, and \add\_latest\_release\_date.py\ to ensure release headers contain dates. The \generate-client.sh\ script has been updated to regenerate the frontend client from the backend OpenAPI spec using Bun. Additionally, local and CI test scripts (\test-local.sh\, \test.sh\) have been refined to better manage Docker containers, and legacy cookiecutter-related scripts (\discard-dev-files.sh\, \generate\_cookiecutter\_config.py\) have been removed.

scripts · high confidence

Migrate frontend routing to TanStack Router with new auth flows

The frontend routing system has been replaced with TanStack Router, introducing a new root layout that integrates React Query and TanStack Router developer tools in development builds. Authentication pages (login, signup, recover-password, reset-password) now use file-based routing with built-in validation via Zod schemas and enforce access control through \beforeLoad\ guards that redirect unauthenticated users. The login form specifically requires a valid email address and a password of at least 8 characters, while the signup flow adds full name collection and password confirmation matching. Meta titles are now explicitly defined for each route to improve SEO and browser tab clarity.

frontend/src/routes · high confidence

Migrated frontend API client to @hey-api/openapi-ts

The frontend API client has been regenerated using the @hey-api/openapi-ts library instead of the previous openapi-typescript-codegen tool. This update refreshes the generated TypeScript types and service classes (such as UsersService and ItemsService) to align with the latest OpenAPI specification, ensuring improved type safety and consistency for all API interactions.

frontend/src/client · high confidence

New React-based email templates for account and password workflows

The system now uses React components (via react-email) to render transactional emails, replacing the previous static HTML approach. This change introduces new, styled templates for the 'new account' welcome email (displaying credentials and a dashboard link), the 'reset password' recovery email (with an expiration notice), and a 'test email' for verifying delivery configuration. These templates share a consistent visual identity, including a branded header, a callout section for details, and a standardized footer.

backend/app/email-templates, packages/react-email · high confidence

New authentication and utility hooks introduced

The frontend now includes a new \useAuth\ hook that manages user sessions, login, registration, and logout using TanStack Query and TanStack Router, replacing previous implementations. Additionally, new utility hooks have been added: \useCustomToast\ for displaying success and error notifications via Sonner, \useCopyToClipboard\ for handling clipboard operations, and \useIsMobile\ for detecting mobile viewports based on a 768px breakpoint.

frontend/src/hooks · high confidence

Removal of legacy Docker Compose and cookiecutter scaffolding

The project has discarded the cookiecutter-based generation approach in favor of a plain git clone/fork workflow. This change removes the \cookiecutter-config-file.yml\ and a large set of legacy Docker Compose files (including \docker-compose.\*.yml\ variants, \.env\, and shell scripts like \backend-start.sh\), effectively stripping out the previous multi-stage Docker build, Traefik v1 proxy, and Couchbase dependencies from this location.

_{{cookiecutter.project\slug}} · high confidence

Restructured API routes and introduced private user creation endpoint

The API route files have been moved from the nested \app/api/api\_v1\ directory to \app/api/routes\, updating the project's internal module structure. This change introduces a new private, local-only API endpoint (\/private/users/\) in \private.py\ designed for use in E2E tests to create users directly, bypassing standard registration flows. Additionally, the \users.py\ route now includes a \DELETE /me\ endpoint allowing non-superuser accounts to delete their own profiles, and the \items.py\ route enforces 403 Forbidden responses for users attempting to access items they do not own.

backend/app/api/routes · high confidence

Rework backend script structure and tooling

The backend scripts have been reorganized into a dedicated \backend/scripts\ directory, replacing the previous layout. The new structure introduces specific shell scripts for formatting (\format.sh\), linting (\lint.sh\), pre-start initialization (\prestart.sh\), and testing (\test.sh\). Formatting and linting now utilize \ruff\ and \ty\ instead of previous tools, while the test script integrates \coverage\ reporting. The pre-start script handles database migrations and initial data population, and the test runner has been consolidated to use the new \test.sh\ entry point.

backend/scripts · high confidence

Fixes

Fix Windows line endings in generated shell scripts

The project generation hook now automatically converts Windows-style CRLF line endings to Unix-style LF endings for all generated shell scripts. This ensures that shell scripts run correctly on Unix-like systems without requiring manual line-ending fixes.

hooks · high confidence

Test coverage

Added backend API and CRUD test suites; Initial Playwright end-to-end test suite for frontend; New test utilities for E2E user flows and email verification.

Dependencies

Migrate to uv workspaces and Bun with modernized dependency stacks

The project has replaced its legacy package management and build tooling with a modern stack. The backend now uses \uv\ for dependency management (defined in \pyproject.toml\) instead of the deprecated \Pipfile\, upgrading Python requirements to 3.14 and updating core libraries like FastAPI, Pydantic, and SQLAlchemy/SQLModel. The frontend has migrated from Vue CLI to a Bun-based Vite setup, utilizing \package.json\ workspaces to manage the main frontend and a new \react-email\ package. This shift brings the frontend dependencies up to date with React 19, TanStack Query/Router, and Tailwind CSS v4, while removing the old Vue 2 and Vuetify codebase.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 73.

Lenses

  • Code Health 89
  • Architecture 96
  • Maturity 68
  • Readiness 73
  • Security 75
  • Accessibility 77

Changes since last survey

  • 300 commits — 297 feature/other, 3 fixes

By area

  • (root) — 246 commits
  • .github/workflows — 26 commits
  • backend/app — 6 commits
  • frontend/src — 6 commits
  • .github/dependabot.yml — 3 commits
  • frontend/biome.json — 2 commits
  • frontend/tests — 2 commits
  • packages/react-email — 2 commits
  • .agents/skills — 1 commit
  • .github/ISSUE_TEMPLATE — 1 commit
  • .github/labeler.yml — 1 commit
  • .github/pr-push.yml — 1 commit
  • .github/pr-submit.yml — 1 commit
  • .vscode/extensions.json — 1 commit
  • backend/Dockerfile — 1 commit

Notable commits

  • fix: ✅ Fix sign-up test race (#2422)
  • fix: 🐛 Fix Sonner toast theme sync (#2450)
  • fix: 🔒️ Add zizmor and fix audit findings (#2260)
  • change: Bump axios from 1.16.0 to 1.18.0 in /frontend (#2386)
  • change: Bump form-data from 4.0.5 to 4.0.6 in /frontend (#2337)
  • change: ☁️ Add FastAPI Cloud deployment (#2438)
  • change: ♻️ Add library-skills for FastAPI and SQLModel (#2354)
  • change: ♻️ Migrate to DATABASE_URL instead of separate variables (#2184)
  • change: ♻️ Refactor models to improve types (#2356)
  • change: ♻️ Remove Copier project generation (#2430)
  • change: ♻️ Replace Mailcatcher with Mailpit for local email testing (#2436)
  • change: ♻️ Require explicit SECRET_KEY (#2425)
  • change: ♻️ Require non-empty Compose configuration (#2418)
  • change: ♻️ Run database setup explicitly before startup (#2426)
  • change: ♻️ Serve frontend from FastAPI (#2393)
  • change: ♻️ Simplify CORS configuration (#2429)
  • change: ♻️ Simplify Copier environment configuration (#2416)
  • change: ♻️ Simplify Docker Compose deployment (#2435)
  • change: ♻️ Simplify Traefik deployment, make it part of the stack (#2412)
  • change: ♻️ Simplify database readiness checks (#2460)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

fastapi/full-stack-fastapi-template was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit cb740b656d7a0a6c5e12c7bf8e50343ec94ee9c7 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.