dotnet-ecommerce-api
An e-commerce backend API template built on .NET 10. Layered architecture, Autofac DI, SqlSugar ORM, Redis cache and queue, and Hangfire jobs are already wired up, and adding a payment gateway means writing one provider.
- Middlewares / FiltersRequest logging, exceptions, validation
- ControllersRouting, model validation, ViewModel ⇄ DTO
- ServicesBusiness logic, transactions, caching
- Payment ProviderECPay, Newebpay, one interface
- RepositoriesData access with SqlSugar
- MySQL / SQL Server · RedisData, cache, queue, jobs
Public Wi-Fi and travel, handled by NordVPN
One tap encrypts everything, with servers in 137 countries. 10 devices per account, 30-day money-back guarantee.
Contains affiliate links
What it saves you
The first two weeks of a new store backend usually go to exactly these.
Building the layers from scratch
Controllers, services and repositories each live in their own project, with interfaces split from implementations (IServices / IRepository). New features go into the matching layer by naming convention, so nobody has to re-argue where code belongs.
Registering DI by hand
Autofac registers services and repositories by naming convention, so adding a class never means editing registration code, and Castle DynamicProxy is there for AOP.
Rewriting checkout for every gateway
Every payment gateway implements the same IPaymentProvider and a factory builds it from the payment type. Adding one means one provider and one config section; callers do not change.
Bolting on jobs and queues
Hangfire (Redis or MySQL storage) and a Redis message queue are already wired in, so async work like mail and reconciliation has an obvious home.
Secrets scattered in config
appsettings.json is only a template with placeholder values. Use appsettings.Development.json locally (already git-ignored) and environment variables with __ separators in containers.
Payment code nobody dares touch
The payment module has its own xUnit test project using ECPay's public test merchant and fake Newebpay data, so tests never hit production.
What's inside
The usual e-commerce plumbing is done, so you can start on business logic.
Layered architecture
Controller → Service → Repository → Database, interfaces separated from implementations.
Autofac DI
Convention-based registration of services and repositories, with AOP via Castle DynamicProxy.
SqlSugar ORM
Switch between MySQL / MariaDB and SQL Server through config.
JWT auth
JWT Bearer with custom authorization policies.
Redis cache and queue
Redis caching plus a Redis message queue (InitQ).
Hangfire jobs
Background jobs and a dashboard, stored in Redis or MySQL.
Payment providers
One IPaymentProvider interface plus a factory, with ECPay and Newebpay built in.
Everything else
Swagger, NLog + Seq structured logging, AutoMapper, MiniProfiler, Turnstile / reCAPTCHA, and a CRUD code generator.
Payments: one provider per gateway
EC226.Payment uses strategy plus factory, and every gateway implements the same interface.
public interface IPaymentProvider
{
PaymentProviderType ProviderType { get; }
PaymentResponse CreatePayment(PaymentRequest request);
PaymentCallbackResult ValidateCallback(IFormCollection form);
PaymentCallbackResult ValidateCallback(string encryptedData);
string GenerateCallbackResponse(bool success);
}
var provider = _providerFactory.Create(PaymentType.ECPAY);
var response = provider.CreatePayment(request);Adding a gateway
- 1
Implement IPaymentConfig and IPaymentProvider under Providers/{Name}/.
- 2
Add the creation logic to PaymentProviderFactory.
- 3
Add a config section under Payment:Providers in appsettings.json.
- 4
Inherit PaymentServiceBase in EC226.MemberSite.Services to build the service.
Supported today
ECPay
Credit card, ATM, convenience-store code, cash on pickup (CheckMacValue SHA256 signing)
Newebpay
Credit card, WebATM, ATM transfer (AES-256-CBC + SHA256 TradeSha)
Stripe / PayPal / Amazon Pay
Configured through Payment:PaymentOptions
Project layout
One solution split into projects that each do one job.
EC226.MemberSite.Api
Web API entry point: controllers, Program.cs, config, mail templates
EC226.MemberSite.Services / IServices
Business logic and its interfaces
EC226.MemberSite.Repository / IRepository
Data access (SqlSugar) and its interfaces
EC226.MemberSite.Model
Entities, view models, DTOs, constants
EC226.Payment
Payment module: abstractions, factory, providers
EC226.Auth
JWT authentication and authorization
EC226.Core
DI, SqlSugar, Redis and Swagger registration
EC226.Caching
Cache abstraction (Redis / memory)
EC226.RedisMQ
Redis message queue consumers
EC226.Task
Hangfire background jobs
EC226.Filter / Middlewares
Action and exception filters, request logging, IP tracking
EC226.CodeGenerator
CRUD code generator templates
Tech stack
Mature, well-documented packages from the .NET ecosystem.
Before you start
Up front, so you don't find out after cloning.
- 1
The architecture is open; the secrets are yours to fill in
All keys, passwords, connection strings and internal hosts have been removed and appsettings.json holds placeholders only. Database, Redis, JWT, AES, SMTP and payment HashKey / HashIV all need your own values before it runs.
- 2
You need the .NET 10 SDK, a database and Redis
MySQL 5.7+ / MariaDB 10.4+ (or SQL Server) plus Redis. The repo ships a script for local Redis and a MariaDB Dockerfile, so Docker is the fastest route.
- 3
Import the sample database separately
Once the database is up, import the schema and seed SQL under EC226.MemberSite.Api/initMariadb/. The account created by init.sql defaults to the password change_me; change it and update the connection string.
Run it from source
- 1
Clone https://github.com/markku636/dotnet-ecommerce-api and enter the project directory.
- 2
Start Redis with build-local-redis-de.ps1 and MariaDB with the Dockerfile in EC226.MemberSite.Api/initMariadb, then import the sample schema.
- 3
Copy EC226.MemberSite.Api/appsettings.json to appsettings.Development.json and fill in connection strings and keys.
- 4
Run dotnet restore and dotnet build, then dotnet run --project EC226.MemberSite.Api.
- 5
Open http://localhost:<port>/doc for Swagger. To deploy, build the image from EC226.MemberSite.Api/Dockerfile and inject secrets as environment variables.
Check that it builds first (no database needed):
License
Apache License 2.0. Commercial use, modification and redistribution are allowed as long as the license and copyright notices are kept. This is an architecture template with no production config or data; payment tests use only the gateways' public test merchants.
Read the full licenseStart your next store backend here
Fork it, replace the placeholders, and put your business logic in the service layer. If it helps, a star helps other people find it.
Every tool here is free and open source
No paywall, no sign-up, and the source is public on GitHub. If one of them saved you time, buy me a coffee so the updates and the next tool keep coming.
Deal
The network you code on is rarely your own
NordVPN encrypts the whole connection: café and hotel Wi-Fi stop being someone else's listening post, and while you travel your bank app, your company dashboards and the streaming services back home still work. One tap in the app, and the NordLynx protocol keeps it fast enough that you forget it is on. One account covers 10 devices, with a 30-day money-back guarantee.
- Public Wi-Fi encrypted end to end
- Servers in 137 countries, reach home services abroad
- 10 devices per account, 30-day refund
Contains affiliate links

