Backend service for a Deepfake Detection Platform that allows users to analyze images/videos and determine whether they are AI-generated or real.
- 🔐 User Authentication (JWT + API Key)
- 🔑 Per-user API Key system
- 🔄 API Key regeneration
- 📡 Deepfake detection (URL & file upload)
- 📜 Scan history tracking
- 🗄️ PostgreSQL (Supabase)
- ⚡ High-performance APIs with FastAPI
- Framework: FastAPI
- Database: PostgreSQL (Supabase)
- ORM: SQLAlchemy
- Auth: JWT (python-jose)
- Hashing: Passlib (bcrypt)
- Containerization: Docker
.
├── app/
│ │
│ ├── detectors/
│ │ ├── image_model.py
│ │ └── video_detector.py
│ │
│ ├── models/
│ │ ├── image_detect/
│ │ │ └── xception_deepfake_base.keras
│ │ └── video-detect/
│ │ ├── model.ipynb
│ │ └── video_model.keras
│ │
│ ├── routes/
│ │ ├── __pycache__/
│ │ ├── api.py
│ │ └── auth.py
│ │
│ ├── services/
│ │ ├── __pycache__/
│ │ ├── image_scraper.py
│ │ └── ytdlp_service.py
│ │
│ ├── auth.py
│ ├── db.py
│ ├── image_model.py
│ ├── main.py
│ ├── models.py
│ ├── schemas.py
│ └── utils.py
│
├── venv/
├── .env
├── .gitignore
├── cookies.txt
├── LICENSE
└── README.md
Run the backend without installing Python or dependencies.
- Install Docker Desktop
git clone <your-repo-url>
cd deepfake-backendDATABASE_URL=postgresql://username:password@host:port/database
use ipv4 instead of ipv6 in case of supabase
GEMINI_API_KEY=your_gemini_api_key
SECRET_KEY=your_secret_key_for_jwt
⚠️ Use Supabase Session Pooler if required.
docker compose up --build-
Backend: 👉 http://localhost:8080
-
Swagger Docs: 👉 http://localhost:8080/docs
docker compose downdocker compose up --build- First build may take time (Docker image build)
- Ensure port 8080 is free
.envfile is required- No need to install Python locally
The API supports two authentication methods:
Use the token received after login:
Authorization: Bearer YOUR_JWT_TOKENUse the API key received during registration/login:
x-api-key: YOUR_API_KEY- Creates a new user
- Returns API key
-
Returns:
- JWT token
- API key
- Generates a new API key
- Invalidates the old one
POST /auth/register→ Register userPOST /auth/login→ Login & get JWT + API keyPOST /auth/regenerate-key→ Generate new API key
POST /analyse/url→ Analyze media from URLPOST /analyse/analyse_upload→ Analyze uploaded fileGET /history→ Get user scan historyPOST /factcheck→ Fact-check a claim using Gemini API'
POST /analyse/url
Headers:
Authorization: Bearer YOUR_JWT_TOKEN
Body:
{
"url": "https://example.com/video.mp4"
}POST /analyse/url
Headers:
x-api-key: YOUR_API_KEY
Body:
{
"url": "https://example.com/video.mp4"
}- Swagger UI supports authentication via the 🔒 button
- JWT is recommended for frontend apps
- API keys are useful for scripts and external integrations
- 🤖 Model improvements
- ⏱️ Rate limiting (Redis)
- 🌐 Chrome extension
- 📊 Dashboard
- 🔐 Multiple API keys
- bcrypt limit: 72 characters
- Use URL-safe DB credentials
- Prefer Supabase Session Pooler for production
Built as part of a hackathon project — Sentinel AI
Pull requests are welcome. Open an issue for major changes.
If you want next-level polish, I can:
- add badges (Docker, FastAPI, stars, etc.)
- or make it look like a top-tier GitHub repo (with screenshots + demo GIF)