Engineering

Python Backend Development

Design and ship a production quality backend service in Python, complete with authentication, testing and a real deployment pipeline.

7 Weeks4 Sessions/WeekIn PersonBeginner-friendly
REST APIsAuthenticationUnit Testing

What you'll be able to do

Graduates can design and ship a production-quality backend service.

  • Write typed, tested, packaged Python
  • Design a normalised relational schema and manage it with migrations
  • Build a documented, validated REST API
  • Implement authentication, role-based access control and object-level authorisation
  • Add background jobs, caching and defensive third-party integrations
  • Write unit, integration and API tests that run in CI
  • Containerise a service and deploy it through a pipeline
  • Diagnose production issues from structured logs and error tracking

Who it's for

  • Beginners with logical aptitude and no professional coding experience
  • Graduates from any discipline
  • Students intending to move into AI, machine learning or data work who need an engineering foundation first
  • QA engineers moving toward development

Prerequisites

  • None beyond computer literacy

This is the designated entry-level programming course, and it satisfies the Python prerequisite for the Generative AI and Applied Machine Learning courses.

All students complete the two-session Engineering Onboarding module before Module 1.

Tools and technologies

Python 3.12 with type hintsFastAPI (primary)Django and Django REST Framework (comparative)PostgreSQLSQLAlchemyAlembicPydanticpytestRedis with Celery or RQDockerDocker ComposeGitHub ActionsstructlogSentry

Target roles

Junior Backend DeveloperPython DeveloperAPI DeveloperSoftware Engineer I

Course curriculum

7 modules · 6-7 weeks

Concepts
data types and mutability; control flow; functions, arguments, scope and default-argument pitfalls; comprehensions; iterators and generators and their memory implications; exceptions covering precise catching, custom exception types and the cost of bare handlers; modules, packages and imports; virtual environments and dependency pinning; type hints and static checking; object-oriented design covering classes, composition over inheritance, dataclasses and magic methods, alongside when a plain function is the better choice; file, JSON and CSV handling; standard library essentials; style, linting and formatting; reading a traceback and using a debugger; writing a first test suite.
Lab
progressive katas from string handling to a small class-based domain model; refactor a 200-line procedural script into typed, tested modules; debug five faulty programs using the debugger rather than print statements; write tests for untested functions and locate two real bugs.
Project
Mini-project 1: a typed, tested, installable CLI application such as an expense tracker or log analyser, with argument parsing, file persistence, error handling and a README.

Concepts
relational design covering entities, relationships, cardinality, normalisation to third normal form and the deliberate denormalisation decision; keys and constraints as correctness guarantees; SQL covering joins, aggregation, subqueries, indexes, execution plans and transactions; ORM concepts covering models, relationships, lazy against eager loading and the N+1 problem, plus when to write raw SQL; migrations as versioned, reviewable, reversible schema history; seeding; connection pooling; timestamps, soft deletes and audit trails; parameterisation and SQL injection.
Lab
model a domain from a written client specification, compare it against alternatives, then implement it with migrations and realistic seed data; write fifteen queries by hand before using the ORM; create an N+1 problem, detect it in query logs and fix it; write a migration, roll it back, and write a data migration.
Project
the capstone data layer with schema, migrations, seeds and an entity-relationship diagram, reviewed before API work begins.

Concepts
HTTP covering methods, status codes, headers, content negotiation and idempotency; REST design covering resource naming, nesting, pagination, filtering, sorting and versioning; request and response validation with schemas separated from database models; consistent error contracts and exception handlers; dependency injection; project structure that survives growth across routers, services and repositories; automatic OpenAPI documentation as a deliverable; file upload handling; CORS; a comparative session on Django and Django REST Framework covering the batteries-included trade-off, the admin interface as a business asset, serializers and viewsets, and a framework selection framework.
Lab
build a validated, paginated, filterable CRUD API with a consistent error contract and published documentation; return deliberately incorrect status codes and have a classmate audit against the specification; implement two endpoints in Django REST Framework and write a comparison.
Project
Mini-project 2 begins: the documented core API for the capstone domain.

Concepts
password storage covering hashing, salting and algorithm choice, plus the common failures; sessions against JWTs and their trade-offs in revocation, size and statelessness; refresh tokens and rotation; OAuth2 and social login flows; email verification and password reset with secure single-use tokens; authorisation covering role-based access control, object-level ownership checks, permission dependencies and administrative boundaries; the OWASP Top 10 applied to a Python API, covering broken access control, injection, mass assignment, insecure direct object references, secrets handling, SSRF, misconfiguration and data exposure; rate limiting and brute-force defence; input sanitisation; secure headers; configuration per environment; audit logging; dependency vulnerability scanning.
Lab
implement the full authentication lifecycle; implement role-based access control plus per-object ownership checks; attack a classmate's API for broken access control, insecure direct object references and mass assignment, file the findings, then fix and retest your own; run a dependency audit and remediate.
Project
Mini-project 2 completes: the API is authenticated, authorised, rate-limited and security-reviewed, with an authorisation matrix in the README.

Concepts
asynchronous Python covering the event loop, concurrency against parallelism and the blocking-call pitfall; background work covering task queues, workers, retries with backoff, idempotent task design, scheduled jobs and dead-letter handling; caching covering what to cache, invalidation strategies, cache stampede and common Redis patterns; email and notification delivery; defensive third-party integration covering timeouts, retries, circuit-breaker behaviour and sandbox against production credentials; payment integration as the worked example; webhook receipt with signature verification and replay protection; integrating an LLM into a backend with server-side key handling, streaming, cost ceilings, timeouts and fallback behaviour; object storage; report and export generation; feature flags.
Lab
move slow report generation into a background job with status polling and retry on failure; add caching to an expensive endpoint and measure the latency change; consume a signed webhook and prove a replayed request is rejected; add a streaming AI feature with a token budget and a graceful failure path; disable an external dependency and verify the service degrades rather than fails.
Project
the capstone gains background processing, caching, an external integration and an AI feature.

Concepts
backend testing covering unit tests for domain logic, integration tests against a real test database, API-level tests through the client, fixtures and factories, isolation and transaction rollback, mocking external services while never mocking your own database, coverage as a signal, and regression tests written from real bugs; Docker for Python covering multi-stage builds, excluded development dependencies, non-root users and small base images; Compose for application, database, cache and worker; environment configuration; CI/CD covering lint, typecheck, test, build, migrate and deploy stages, branch protection, migration strategy and rollback; production operations covering worker sizing, health endpoints, structured JSON logging with correlation identifiers, error tracking, uptime monitoring and basic metrics; database backups; profiling and bottleneck identification.
Lab
build the test suite to meaningful coverage of business logic and all endpoints; containerise the stack so it starts with one command; build the pipeline with a required green check to merge; deploy to production; diagnose a deliberately broken deployment from logs and error tracking alone, then roll back; profile and fix the slowest endpoint.
Project
the capstone is tested, containerised, pipeline-deployed, logged and monitored.

Concepts
Agile practice covering backlog, user stories with acceptance criteria, estimation, sprint, standup, review and retrospective; issue tracking and definition of done; code review as a craft; refactoring under test cover; technical debt as a recorded decision; documentation covering README, API reference, architecture decision records and onboarding guide; handover; reading and contributing to an unfamiliar codebase; expectations for a developer's first ninety days.
Lab
a two-day sprint on a shared client backlog with full ceremonies; each student reviews two classmates' pull requests against a rubric; contribute a fix to an unfamiliar repository; write an onboarding guide and have a classmate follow it without assistance.

Capstone project

A production-quality backend service for a real domain. Options include a clinic booking and records API, a school fee and attendance system, a microfinance loan management API, or a logistics dispatch and tracking API.

Requirements

  • Normalised PostgreSQL schema with migrations and an entity-relationship diagram
  • Documented, validated, paginated REST API with OpenAPI reference
  • Full authentication with role-based and object-level authorisation
  • Rate limiting and a completed security review
  • Background jobs with retry handling
  • Caching
  • One external integration with defensive error handling
  • One AI-assisted feature
  • Unit, integration and API tests green in CI
  • Docker Compose local environment
  • CI/CD pipeline with branch protection and migration handling
  • Deployed live URL
  • Structured logging, error tracking and a health endpoint
  • README covering architecture, setup, API reference, trade-offs and known limitations
  • Complete incremental pull request history

Assessment

30%Weekly labs and mini-projects
20%Code review participation
35%Capstone
15%Demo Day presentation and technical questioning

Pathway

Also serves as the feeder course for the Generative AI and Applied Machine Learning programs.

Out of scope

  • Substantial frontend work beyond a minimal interface
  • Microservices architecture
  • Advanced asynchronous internals
  • Data science libraries

Enquire about this course

Ask about the next cohort, schedule or prerequisites and our team will get back to you.

Python Backend Development
Keep learning

Related Courses.

Generative AI & Agent Engineering
EngineeringIntermediate

Generative AI & Agent Engineering

Design, build and ship LLM applications that work against real documents and real tools, proven with an evaluation suite, not just a demo.

RAG PipelinesAI AgentsLLM Evaluation
8 Weeks3-4 Sessions/WeekIn Person
View course
AI & Machine Learning
EngineeringIntermediate

AI & Machine Learning

Take a business problem from raw data to a deployed, monitored model, with honest evaluation and real production practice throughout.

Feature EngineeringModel TrainingMLOps
8 Weeks4 Sessions/WeekIn Person
View course
Full-Stack Web Development
EngineeringBeginner-friendly

Full-Stack Web Development

Build, test, containerise and deploy a complete multi-user web application in TypeScript, and defend every layer of it under questioning.

TypeScriptDatabase DesignDocker
8 Weeks4 Sessions/WeekIn Person
View course
Software QA & Test Automation
EngineeringBeginner-friendly

Software QA & Test Automation

Take an unfamiliar web application and build a complete, maintainable quality strategy, from risk based test design to automated pipelines.

Risk-Based TestingTest AutomationAPI Testing
7 Weeks4 Sessions/WeekIn Person
View course
AWS Cloud Engineering
EngineeringIntermediate

AWS Cloud Engineering

Stand up a full production environment on AWS, from networking and compute to monitoring, and defend the monthly cost with confidence.

VPC NetworkingTerraformCost Optimisation
7 Weeks4 Sessions/WeekIn Person
View course
DevOps Engineering
EngineeringIntermediate

DevOps Engineering

Build and operate the delivery platform for a multi-service application, from containers and Kubernetes to incident response and postmortems.

KubernetesCI/CDIncident Response
8 Weeks4 Sessions/WeekIn Person
View course