FastAPI Forge
FastAPI Forge is a zero-runtime-dependency CLI that generates production-oriented FastAPI projects with PostgreSQL, Alembic migrations, JWT authentication, audit logging, and optional role-based access control (RBAC).
Generated features
- Access and rotating refresh tokens, revocation, and session management
- Password reset and email verification flows
- PostgreSQL with sync and async SQLAlchemy sessions
- Alembic migrations and an idempotent first-user seed command
- Structured logs, request IDs, rate limiting, CORS, trusted hosts, and security headers
- Liveness, readiness, and database health endpoints
- A multi-stage, non-root Docker image and local Compose stack
- Pytest tests, Ruff checks, and GitHub Actions CI
The RBAC variant adds hierarchical roles, permissions, per-user permissions, protected administration APIs, and RBAC seed data. The non-RBAC variant uses is_superuser for administrative authorization.
Requirements
- Python 3.12+ for the generator and generated applications
- PostgreSQL 14+ for generated applications
- Docker with Compose v2 for the optional container workflow
Installation
Install or upgrade the CLI from PyPI:
python -m pip install --upgrade fastapi-forge-cli
The PyPI distribution is named fastapi-forge-cli because fastapi-forge is
already used by another project. The installed terminal command remains
fastapi-forge, and the Python import remains fastapi_forge.
Quick start
Generate a production-oriented FastAPI project with RBAC:
fastapi-forge create "Inventory API" --with-rbac
cd inventory-api
Run fastapi-forge --help to see all commands and
fastapi-forge create --help to see every generation option.
Development installation
For development from a source checkout:
cd fastapi-forge
python3 -m venv .venv
source .venv/bin/activate
python -m pip install --upgrade pip
pip install -e .
For generator development, run pip install -e ".[dev]". On Windows PowerShell, activate with .venv\\Scripts\\Activate.ps1.
Generate a project
# With RBAC
fastapi-forge create "Inventory API" --with-rbac
# Without RBAC
fastapi-forge create "Inventory API" --without-rbac
# Select a parent directory
fastapi-forge create "Inventory API" --with-rbac --output-dir ./projects
The same generator is available as a Python library:
from pathlib import Path
from fastapi_forge import create_project
project = create_project(
name="Inventory API",
output_dir=Path("./projects"),
with_rbac=True,
)
print(project)
Generation is staged before installation at the destination. Existing projects are
preserved unless --force is explicitly supplied, and symbolic-link destinations
are never replaced.
If neither RBAC option is supplied, an interactive terminal asks which variant to use. Non-interactive environments default to RBAC. Existing destinations are protected; --force permanently replaces the matching generated-project directory.
usage: fastapi-forge create [-h] [--output-dir OUTPUT_DIR]
[--with-rbac | --without-rbac] [--force]
name
Getting help
Discover available commands:
fastapi-forge --help
See every project-generation option:
fastapi-forge create --help
Print copy-ready examples:
fastapi-forge examples
Common commands include:
fastapi-forge create "Inventory API" --with-rbac
fastapi-forge create "Public API" --without-rbac
fastapi-forge create "Billing API" --with-rbac --output-dir ./projects
Run a generated project
Python
Create the PostgreSQL database described by sample.env, then:
cd inventory-api
python3.12 -m venv .venv
source .venv/bin/activate
python -m pip install --upgrade pip
pip install -r requirements-dev.txt
cp sample.env .env
alembic upgrade head
python scripts/seed_first_user.py \
--email admin@example.com \
--password 'ChangeMe123!' \
--full-name 'System Administrator'
uvicorn app.main:app --reload
Open http://localhost:8000/docs. Run pytest and ruff check . before committing.
Docker
cd inventory-api
cp sample.env .env
docker compose up --build
In another terminal:
docker compose exec api python scripts/seed_first_user.py \
--email admin@example.com \
--password 'ChangeMe123!' \
--full-name 'System Administrator'
The Compose file is for local development; it uses development credentials and a bind mount.
Production deployment checklist
- Set
APP_ENV=production. - Supply a unique
SECRET_KEYof at least 32 characters from a secret manager. - Set explicit
ALLOWED_HOSTSand HTTPSALLOWED_ORIGINSvalues. - Use managed PostgreSQL credentials and
PG_SSLMODE=require,verify-ca, orverify-full. - Configure Redis when rate limits must be shared across replicas.
- Configure SMTP and
FRONTEND_URLfor account emails. - Run
alembic upgrade headas one release job before starting new replicas. - Terminate TLS at a trusted load balancer or reverse proxy.
- Send stdout/stderr to centralized logging. Enable file logs only with persistent storage.
- Monitor
/api/v1/health/liveand/api/v1/health/ready. - Back up PostgreSQL, test restores, rotate secrets, and define rollback procedures.
Production mode refuses startup with a default/short secret, wildcard hosts or origins, or a non-TLS database mode. Interactive API documentation is disabled.
docker build -t inventory-api:1.0.0 .
docker run --rm --env-file .env inventory-api:1.0.0 alembic upgrade head
docker run --rm --env-file .env -p 8000:8000 inventory-api:1.0.0
Do not run migrations independently from every application replica.
Generator development and release
pytest
python -m build
python -m twine check dist/*
Review generated output from both variants whenever templates change.
License
MIT
Metadata
Release files for fastapi-forge-cli 0.1.5
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| fastapi_forge_cli-0.1.5.tar.gz | 101.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| fastapi_forge_cli-0.1.5-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 250.5 kB
Release files / fastapi_forge_cli-0.1.5.tar.gz
| Download URL | fastapi_forge_cli-0.1.5.tar.gz |
|---|---|
| Size | 101.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
b259cc9a5bff36b2aaabab95f753ac5e710f4afc92beb6f5a855cb15521b3c51
|
|
BLAKE2b-256 checksum How to use checksums |
29e65b6a948873fee6c16870b5ee7616f2f8929a82010e98c9246ea2c48dec2e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 1, 2026.
Transparency logRelease files / fastapi_forge_cli-0.1.5-py3-none-any.whl
| Download URL | fastapi_forge_cli-0.1.5-py3-none-any.whl |
|---|---|
| Size | 149.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
a669561861b68d647b5f27b83f7bd9617a1c41bc674471dd4181b36f6cd8abec
|
|
BLAKE2b-256 checksum How to use checksums |
e4bff74ddb555f97c72cf8439759f4f41dcce24f688c7ef3523427e74e4553a7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 1, 2026.
Transparency log