Backend API service for FacilPay - Stellar-based multi-chain payment gateway. Handles payment processing, webhook management, settlement operations, and merchant integrations.
Backend API built with NestJS.
- Docker and Docker Compose for the fastest local setup
- Node.js 18+ and npm for running without Docker
Start the API and PostgreSQL with hot reload:
docker compose up --buildThe API will be available at http://localhost:3000.
Run database migrations inside the API container:
docker compose run --rm api migrateRun E2E tests against a throwaway PostgreSQL database:
docker compose -f docker-compose.test.yml run --rm api test:e2eStop and remove local containers, networks, and volumes:
docker compose down -v- Install dependencies
npm installcp .env.example .envnpm run start:devnpm run dev
npm test
npm run test:e2e
npm run migrate
npm run docker:dev
npm run docker:test:e2eTo verify the API is running correctly, use the liveness probe β it never fails due to an external dependency and is safe for orchestrator restart checks:
curl -i http://localhost:3000/v1/health/liveExpected response (200 OK):
{
"status": "ok",
"statusCode": 200,
"timestamp": "2026-01-26T10:00:00.000Z",
"uptime": 3600
}To check whether all dependencies (database, Stellar, Redis) are ready:
curl -i http://localhost:3000/v1/health/readyTrimmed example response (200 OK β all healthy):
{
"status": "ok",
"statusCode": 200,
"timestamp": "2026-01-26T10:00:00.000Z",
"uptime": 3600,
"services": {
"database": { "status": "healthy", "message": "Database connection is healthy" },
"stellar": { "status": "healthy", "message": "Stellar network is reachable" },
"queue": { "status": "healthy", "message": "Redis connection is healthy" }
}
}See docs/HEALTH_CHECKS.md for full probe semantics and deployment examples.
The API includes a JWT-based authentication system with the following endpoints:
curl -X POST http://localhost:3000/v1/auth/register \
-H "Content-Type: application/json" \
-d '{"email":"user@example.com","password":"password123"}'curl -X POST http://localhost:3000/v1/auth/login \
-H "Content-Type: application/json" \
-d '{"email":"user@example.com","password":"password123"}'curl -X GET http://localhost:3000/v1/users/me \
-H "Authorization: Bearer YOUR_JWT_TOKEN"src/ βββ modules/ β βββ auth/ β β βββ auth.controller.ts β β βββ auth.service.ts β β βββ auth.module.ts β β βββ jwt.strategy.ts β β βββ guards/ β β βββ decorators/ β βββ users/ β β βββ user.entity.ts β β βββ dto/ β β βββ users.module.ts β βββ health/ β βββ health.controller.ts β βββ health.service.ts β βββ health.module.ts βββ app.controller.ts βββ app.service.ts βββ app.module.ts βββ main.ts
The server runs on port 3000 by default.
The port can be configured using the PORT variable in the .env file
Logging is structured with Pino and writes rotating files under the log directory.
Environment variables:
- LOG_LEVEL (default: info in production, debug in development)
- LOG_DIR (default: logs)
- LOG_PRETTY (default: true in development, false in production)
- LOG_MAX_SIZE (default: 10m)
- LOG_RETENTION_DAYS (default: 14)
- LOG_BODY (default: false)
- LOG_BODY_MAX_LENGTH (default: 2048)
- LOG_RESPONSE_BODY (default: false)
-
JWT token-based authentication
-
Password hashing with bcrypt
-
Protected routes with guards
-
Public route decorator
-
Current user decorator
-
Role-based access control (ready for implementation)
-
Telegram: https://t.me/+afM9uh7GGtVkYmZk
βββ modules/
β βββ auth/
β βββ stellar/ <-- New Module
β β βββ stellar.service.ts
β β βββ stellar.module.ts
β βββ users/
β βββ health/
- Contributing β setup, conventions, PR checklist
- Sessions β session listing and revocation
- Refunds β refund system and maker-checker approval flow
- Disputes β dispute lifecycle and evidence uploads
- Webhooks β webhook endpoints and event types
- RBAC β role-based access control
- Audit Log β audit logging
- Settlements β settlement processing
- Payment Splits β payment splitting
- Payment Links β payment link generation
- Merchant Rate Limiting β rate limiting
- Merchant Access Controls β merchant ACL
- Idempotency β idempotency for safe retries
- Ledger β ledger and accounting
- Rates β currency rates and conversion
- Stellar β Stellar network integration
- Two-Factor Auth β 2FA implementation
- Password Reset β password reset flow
- Environment β environment variable reference