7 hours, 14 minutes ago

API Developer

Context

Data is currently delivered to us through the API of a third-party tool, whose future is uncertain. We want to re-implement a subset of that API (or a very similar one) so that current users can transition with minimal friction. The API is not very complex and some documentation is available.

The API has two functional parts:

  • Metadata layer: exposes metadata to the caller (e.g. data collection structures).

  • Submission layer: allows submitting data for a given data collection and validates the submission.

The new implementation is built around the database of the ODS project, which plays two roles:

  • Source of the metadata: the metadata served by the metadata layer is already available in the ODS database.

  • Destination of the submissions: submitted data is consumed by the existing Python loading code of the ODS project.

Security is a design concern from the start. The security model (authentication, authorization, transport and data protection) may differ from the current API and must be defined.

Assignment

Implement the critical parts of the API (scope to be agreed at the start) to show that a compatible replacement is achievable. The work is delivered with production-quality code, tests and documentation for what is covered. The deliverable includes a concise summary of what was covered, what remains, and what is needed to reach production.

Tasks

  • Analyse the existing API and its documentation, and agree on the subset to cover

  • Analyse the ODS database and map its metadata to what the existing API exposes, identifying any gaps

  • Propose and implement a security approach (authentication, authorization, secure handling of submitted data), highlighting where it differs from the current API

  • Implement the metadata endpoints on top of the ODS database

  • Implement the submission endpoints, with validation of submitted data and meaningful error responses

  • Hand over submitted data to the ODS loading code (or store it in the form that code expects)

  • Write automated tests and concise technical documentation

  • Deploy and demonstrate the solution on Ubuntu Linux

  • Report on limitations, open questions and recommended next steps

Required skills

  • Python 3.12+ with FastAPI

  • SQLAlchemy and PostgreSQL (reading and mapping an existing schema)

  • REST API design

  • API security: authentication and authorization (e.g. OAuth2/OIDC, JWT, API keys), TLS, input validation

  • Automated testing (pytest)

Nice to have

  • Polars in combination with SQLAlchemy

  • uv for package management

  • Experience with API compatibility or migration projects

  • Experience handling sensitive data (e.g. health data) and GDPR requirements

  • Linux deployment experience

Soft skills

  • Autonomy and ability to work from incomplete documentation

  • Pragmatism: focusing on the critical parts first while keeping quality high on what is delivered

  • Clear communication of findings and limitations

Apply for this Job

This position was originally posted on Pro Unity.

It is publicly accessible, and we recommend applying directly through the Pro Unity website instead of going through third party recruiters.

Newsletter signup illustration