FastAPI REST Routes
Comprehensive overview of the FastAPI application, modular router architecture, all 22+ route modules, the Redis command bus, security middleware, and rate limiting.
The FastAPI backend (api/depthsight_api.py, ~2,220 lines) acts as the administrative control panel of the DepthSight platform. It manages user credentials, strategy definitions, exchange API keys, subscription billing, and issues process signals to bot workers via the Redis command bus.
Endpoint Architecture
The API is organized into modular APIRouters with a two-tier registration pattern:
Tier 1 โ Master api_router (line 1575)
Sources:Tier 2 โ include_application_routers() (lines 2185โ2215)
All routers are passed to a central registration function:
Sources:Conditional routers (hub, simulation, phantom) are loaded based on environment configuration.
Complete Route Module Reference
| Router Variable | Source File | Prefix | Auth |
|---|---|---|---|
public_router | routes/public.py | /api/v1/shared/... | Public |
auth_router | routes/auth.py | /api/v1/auth | Mixed |
strategies_router | routes/strategies.py | /api/v1/strategies | get_current_user |
backtests_router | routes/backtests.py | /api/v1/backtests | get_current_user |
payments_router | routes/payments.py | /api/v1/payments | get_current_user |
webhooks_router | routes/webhooks.py | /webhooks | Public |
admin_router | routes/admin.py | /api/v1/admin | require_admin_role |
affiliate_router | routes/affiliate.py | /api/v1/affiliate | Mixed |
model_lab_router | routes/model_lab.py | /api/v1/model-lab | get_current_user |
users_extra_router | routes/users.py | /api/v1/users | get_current_user |
notifications_router | routes/notifications.py | /api/v1/notifications | get_current_user |
support_router | routes/support.py | /api/v1/support | get_current_user |
admin_support_router | routes/support.py | /api/v1/admin/support | require_admin_role |
discovery_router | routes/discovery.py | /api/v1/discovery | get_current_user |
ai_meta_router | routes/ai.py | /api/v1/ai | get_current_user |
ai_core_router | routes/ai.py | /api/v1/ai | get_current_user + use_ai_assistant |
api_keys_router | routes/api_keys.py | /api/v1/config/api-keys | get_current_user |
account_router | routes/account.py | /api/v1/account | get_current_user |
portfolio_router | routes/portfolio.py | /portfolio/... | get_current_user |
config_router | routes/config.py | /config | get_current_user |
diagnostics_router | routes/diagnostics.py | /status | Mixed |
tasks_router | routes/tasks.py | /tasks | get_current_user |
gamification_router | routes/gamification.py | /gamification | get_current_user |
hft_router | hft_router.py | /hft (under /api/v1) | get_current_user |
Key Endpoint Actions
| Route Path | Method | Purpose |
|---|---|---|
/api/v1/auth/register | POST | User registration with default workspace, referral tracking |
/api/v1/auth/token | POST | JWT access + refresh token generation (OAuth2) |
/api/v1/strategies/save | POST | Saves/updates visual block JSON strategies to PostgreSQL |
/api/v1/strategies/start | POST | Publishes a start event to the Redis Command Bus |
/api/v1/strategies/stop | POST | Signals bot engine to exit/liquidate |
/api/v1/backtests/run | POST | Enqueues backtest via Celery task |
/api/v1/backtests/genetic | POST | Enqueues genetic optimization via Celery |
/api/v1/payments/invoice | POST | Creates Bitcart payment invoice |
/api/v1/ai/chat | POST | AI Co-Pilot chat with RAG context |
/api/v1/admin/users | GET | Admin panel user management |
/webhooks/tradingview | POST | TradingView webhook signal receiver |
/api/v1/hft/command | POST | High-frequency trading commands |
The Command Bus Control Flow
When a user initiates an action via the frontend (e.g., clicking "Start Bot"), the REST API does not execute the bot directly. It serializes the command and pushes it to Redis to maintain stateless architecture:
Frontend (Click Start)
|
|- HTTP POST /api/v1/strategies/start
|
v
FastAPI Backend
|
|- Redis PUBLISH to depthsight:commands
| {"command": "INITIALIZE_USER_CONTROLLER", "payload": {"user_id": 42}}
|
v
Redis Command Bus
|
v
bot_runner.py (listens on depthsight:commands)
|
|- Spawns isolated controller process
v
Active Bot Worker (user_id=42, TradingController)
Command Bus Helpers (api/live_runtime.py)
| Function | Command | Purpose |
|---|---|---|
build_initialize_user_controller_command(user_id) | INITIALIZE_USER_CONTROLLER | Start user trading controller |
build_activate_api_key_command(user_id, api_key_id) | ACTIVATE_API_KEY | Activate API key for live trading |
build_deactivate_api_key_command(user_id, api_key_id) | DEACTIVATE_API_KEY | Deactivate API key |
Plan Change Sync (_sync_live_runtime_for_plan_change, lines 532-616)
The API automatically manages bot state on plan transitions:
| Transition | Action |
|---|---|
| Free to Standard/Pro | Publish INITIALIZE_USER_CONTROLLER |
| Standard/Pro to Free | Deactivate non-Bybit API keys |
| No live to Live allowed | Initialize controller for all active keys |
Security Middleware and Rate Limiting
CORS Configuration (lines 1561-1573)
Sources:Security Headers (lines 1425-1450)
Every HTTP response includes:
X-Content-Type-Options: nosniffX-Frame-Options: DENYStrict-Transport-Security: max-age=31536000; includeSubDomainsContent-Security-Policywith allowed connect-src for Binance/Bybit APIs, Google OAuth
Rate Limiting (lines 1496-1512)
Uses slowapi.Limiter with Redis-backed storage (DB 1) in production:
| Endpoint Group | Limit |
|---|---|
| Backtest execution | 100/hour |
| Login attempts | 5/minute |
| Default | 600/minute |
Lifespan Management (lines 1243-1401)
The FastAPI lifespan context manager handles:
- Building and caching AI prompts for the Co-Pilot.
- Starting the aiohttp client session.
- Central Hub: auto-creating/migrating DB tables.
- Non-Hub nodes: background sync loop to Federation Hub (with Redis lock).
- Pre-loading the Oracle ML model for simulation.
- Graceful shutdown of the aiohttp session.
Redis Fan-Out and Data Consumer
Detailed analysis of the DataConsumer runtime โ dual ingestion modes, global connection registry, shared memory caches, real-time indicator processing pipeline, and warm snapshot restoration.
Multi-Tenant Auth & Quotas
Technical breakdown of JWT authentication, Role-Based Access Control, API key encryption, Redis Quota Manager, plan tiers, and bonus systems.