MO

Backend security / Open source

Spring Boot Secure API

A production-grade REST API template that makes authentication, hardening, observability, and testability part of the foundation.

Role
Creator · Backend architecture
Year
2026
State
Open-source template

System / clustered

Scroll to examine

Project snapshot

Delivered70+ automated tests
EvidenceCI quality gates
System breadth6 core technologies

The condition

Challenge

Most API tutorials stop before the operational concerns a production service needs: token lifecycle, abuse controls, auditability, observability, and architectural enforcement.

The response

Architecture

A Spring Boot 3.4 reference service layers correlation, rate limiting, JWT verification, authorization, audited application logic, and PostgreSQL persistence into one documented request path.

What shaped it

Key decisions

  1. Rotating token families

    RS256 access tokens are paired with refresh-token rotation and family revocation to detect reuse.

  2. Security in the request path

    Argon2id, account lockout, Bucket4j limits, OWASP headers, and explicit authorization rules are first-class layers.

  3. Operational evidence

    Micrometer metrics, JSON logs, audit records, Testcontainers, ArchUnit, PIT, and JaCoCo make behavior observable and testable.

How it feels

Experience

The reference exposes registration, login, refresh, health, and Prometheus endpoints. OpenAPI can be enabled per environment, while structured errors and correlation IDs keep requests traceable.

What resolved

Outcome

A public MIT template backed by more than 70 unit and integration tests, architecture rules, mutation testing, coverage reporting, and automated CI checks.

  • 70+ automated tests
  • CI quality gates

System composition

Technology, deliberately chosen.

  • Java 21
  • Spring Boot 3.4
  • PostgreSQL 16
  • Gradle
  • JWT RS256
  • Prometheus