PluginBench
Skill
Review
Audit score 70

python-backend

jiatastic/open-python-skills

Production-ready Python backend patterns for FastAPI, SQLAlchemy, and Upstash integrations.

What is python-backend?

Expert guidance for building secure, async-first REST APIs with FastAPI, implementing authentication, managing databases with SQLAlchemy, and integrating Redis/Upstash caching. Use this skill when building production backends, refactoring AI-generated code, or designing API patterns.

  • Build REST APIs with FastAPI using async/await patterns
  • Implement JWT/OAuth2 authentication and security best practices
  • Set up SQLAlchemy async databases with proper transaction handling
  • Integrate Redis/Upstash for caching and rate limiting
  • Refactor and optimize AI-generated Python code (deslopification)
  • Design scalable API project structures and patterns

How to install python-backend

npx skills add https://github.com/jiatastic/open-python-skills --skill python-backend
Prerequisites
  • Python 3.8+
  • FastAPI installed
  • SQLAlchemy 2.0+
  • Upstash account (for Redis/QStash features)
Claude Code
Cursor
Windsurf
Cline

How to use python-backend

  1. 1.Review the project structure template in the skill to organize your code into modules (auth, posts, etc.)
  2. 2.Use async/await patterns for all I/O operations; avoid blocking calls in async functions
  3. 3.Define Pydantic models for request/response validation in schemas.py files
  4. 4.Implement dependency injection with FastAPI's Depends() for authentication and database sessions
  5. 5.Set up SQLAlchemy AsyncSession with async_sessionmaker for database operations
  6. 6.Integrate Upstash Redis for caching using redis.get/setex or rate limiting with Ratelimit
  7. 7.Reference the included pattern documents for detailed implementations of security, databases, and Upstash

Use cases

Good for
  • Building a FastAPI REST API with async database operations and JWT authentication
  • Implementing rate limiting and caching for high-traffic endpoints using Upstash Redis
  • Refactoring AI-generated backend code to follow production patterns and async best practices
  • Setting up a multi-module FastAPI project with dependency injection and Pydantic validation
  • Adding OAuth2 authentication and CORS security to an existing API
Who it's for
  • Backend engineers building Python APIs
  • Full-stack developers implementing FastAPI services
  • Teams refactoring AI-generated code for production
  • Developers integrating Upstash Redis for caching and rate limiting
  • Engineers designing scalable API architectures

python-backend FAQ

When should I use async vs sync functions in FastAPI?

Use async functions for I/O operations (database, API calls, Redis). Use sync functions only for CPU-bound work or blocking operations like time.sleep(). Never use blocking calls in async functions—use asyncio.sleep() instead.

How do I validate user input safely?

Use Pydantic models with field validators (EmailStr, Field with constraints, regex patterns). Define schemas in separate schemas.py files and use them in route parameters. Pydantic validates automatically and raises HTTPException on invalid input.

What's the recommended project structure?

Organize by feature (auth/, posts/, etc.) with each module containing router.py (endpoints), schemas.py (Pydantic models), models.py (database models), service.py (business logic), and dependencies.py (dependency injection).

How do I implement rate limiting with Upstash?

Use Upstash Ratelimit with SlidingWindow, pass Redis.from_env() for credentials, and call ratelimit.limit(identifier) in your route. Return 429 HTTPException if not allowed.

How do I cache data with Upstash Redis?

Use Redis.from_env() to connect, check redis.get(key) for cached data, and use redis.setex(key, ttl_seconds, value) to cache. Common pattern: check cache → fetch from DB → cache result.

Full instructions (SKILL.md)

Source of truth, from jiatastic/open-python-skills.


name: python-backend description: > Python backend development expertise for FastAPI, security patterns, database operations, Upstash integrations, and code quality. Use when: (1) Building REST APIs with FastAPI, (2) Implementing JWT/OAuth2 authentication, (3) Setting up SQLAlchemy/async databases, (4) Integrating Redis/Upstash caching, (5) Refactoring AI-generated Python code (deslopification), (6) Designing API patterns, or (7) Optimizing backend performance.

python-backend

Production-ready Python backend patterns for FastAPI, SQLAlchemy, and Upstash.

When to Use This Skill

  • Building REST APIs with FastAPI
  • Implementing JWT/OAuth2 authentication
  • Setting up SQLAlchemy async databases
  • Integrating Redis/Upstash caching and rate limiting
  • Refactoring AI-generated Python code
  • Designing API patterns and project structure

Core Principles

  1. Async-first - Use async/await for I/O operations
  2. Type everything - Pydantic models for validation
  3. Dependency injection - Use FastAPI's Depends()
  4. Fail fast - Validate early, use HTTPException
  5. Security by default - Never trust user input

Quick Patterns

Project Structure

src/
├── auth/
│   ├── router.py      # endpoints
│   ├── schemas.py     # pydantic models
│   ├── models.py      # db models
│   ├── service.py     # business logic
│   └── dependencies.py
├── posts/
│   └── ...
├── config.py
├── database.py
└── main.py

Async Routes

# BAD - blocks event loop
@router.get("/")
async def bad():
    time.sleep(10)  # Blocking!

# GOOD - runs in threadpool
@router.get("/")
def good():
    time.sleep(10)  # OK in sync function

# BEST - non-blocking
@router.get("/")
async def best():
    await asyncio.sleep(10)  # Non-blocking

Pydantic Validation

from pydantic import BaseModel, EmailStr, Field

class UserCreate(BaseModel):
    email: EmailStr
    username: str = Field(min_length=3, max_length=50, pattern="^[a-zA-Z0-9_]+$")
    age: int = Field(ge=18)

Dependency Injection

async def get_current_user(token: str = Depends(oauth2_scheme)) -> User:
    payload = decode_token(token)
    user = await get_user(payload["sub"])
    if not user:
        raise HTTPException(401, "User not found")
    return user

@router.get("/me")
async def get_me(user: User = Depends(get_current_user)):
    return user

SQLAlchemy Async

from sqlalchemy.ext.asyncio import AsyncSession, async_sessionmaker, create_async_engine

engine = create_async_engine(DATABASE_URL, pool_pre_ping=True)
SessionLocal = async_sessionmaker(engine, expire_on_commit=False)

async def get_session() -> AsyncGenerator[AsyncSession, None]:
    async with SessionLocal() as session:
        yield session

Redis Caching

from upstash_redis import Redis

redis = Redis.from_env()

@app.get("/data/{id}")
def get_data(id: str):
    cached = redis.get(f"data:{id}")
    if cached:
        return cached
    data = fetch_from_db(id)
    redis.setex(f"data:{id}", 600, data)
    return data

Rate Limiting

from upstash_ratelimit import Ratelimit, SlidingWindow

ratelimit = Ratelimit(
    redis=Redis.from_env(),
    limiter=SlidingWindow(max_requests=10, window=60),
)

@app.get("/api/resource")
def protected(request: Request):
    result = ratelimit.limit(request.client.host)
    if not result.allowed:
        raise HTTPException(429, "Rate limit exceeded")
    return {"data": "..."}

Reference Documents

For detailed patterns, see:

DocumentContent
references/fastapi_patterns.mdProject structure, async, Pydantic, dependencies, testing
references/security_patterns.mdJWT, OAuth2, password hashing, CORS, API keys
references/database_patterns.mdSQLAlchemy async, transactions, eager loading, migrations
references/upstash_patterns.mdRedis, rate limiting, QStash background jobs

Resources