Engineering showcase · 2026
Qashio Expense Tracker
Production-grade finance API: transactional outbox, idempotent writes and race-safe auth.
This started as a take-home brief for a simple expense tracker. I built it as I'd build a real fintech backend: wallets with opening balances, budgets with 80% and 100% alerts, multi-currency, email OTP sign-up, notifications and activity logs, on a hexagonal architecture with a reliable event pipeline. Domain events never get lost and no side effect runs twice.
Flows I’ve written up
How specific parts of Qashio Expense Tracker work under the hood, with code you can reuse.
Refresh-token rotation that doesn't log out users with five tabs open
Rotating refresh tokens on every use is good security, but a naive implementation turns parallel requests into random logouts. Here's the Redis lock, grace-replay cache and client-side single flight I use so concurrent refreshes all get the same new tokens.
Saving a transaction exactly once: idempotency keys from the form to the database
A double click, a timeout retry or two racing requests can each record the same expense twice. Here's how an Idempotency-Key that the client derives from the form, a strict server-side replay and a soft lookalike check together make 'Save' safe to press again.
Domain events that never get lost: a transactional outbox fanned out to BullMQ
Saving a row and publishing an event are two writes, and one of them will eventually fail. Here's the outbox → relay → one-job-per-handler pipeline I built so budget alerts fire exactly once, even through crashes and retries.