Mobile app of a retailer crashing under Black Friday peak loads? Or API responding in 5 seconds instead of 200 ms? Most often the root cause is a backend that can't handle concurrent requests, unoptimized database queries, or weak authentication. We build backends on Java Spring Boot that work stably under load up to 150,000 users. Our experience: over 50 implementations in fintech, logistics, and retail.
Why Spring Boot for mobile API works better than alternatives
Enterprise sector — banking, insurance, logistics. Here the mobile client serves as the frontend to business logic already running on Java. Rewriting it to Go or Node for "fashion" is expensive and risky. Spring Boot allows you to expose REST API on top of existing services in weeks, not months. Our engineers have experience migrating legacy systems to a microservice architecture while preserving contracts. Integration time savings reach 30% thanks to ready starters and configurations.
How to speed up Spring Boot application startup?
Standard Spring Boot 3.x starts in 8–15 seconds — this is a problem for Kubernetes under auto-scaling. According to Spring Boot Reference Documentation, GraalVM Native Image reduces startup time to hundreds of milliseconds. Alternatives: Spring WebFlux (reactive model with Netty reduces memory footprint) or simply keep at least two pods always running. The choice depends on load and infrastructure budget. Infrastructure cost reduction after optimization can reach 40%.
API architecture for mobile client
Stack: Spring Boot 3.x (Java 17+), Spring Data JPA + PostgreSQL (or MongoDB), Spring Security with JWT, Spring Cache + Redis, Spring Boot Actuator for health-check.
For push notifications use FCM via firebase-admin SDK or APNs via pushy library with HTTP/2 connection pool. WebSocket — through STOMP over SockJS for real-time features.
Case study: fintech app, 150,000 users, backend on Spring Boot 2.7. Endpoint /transactions/history with pagination regularly timed out. Reason: Hibernate loaded related entities with separate queries (N+1). After refactoring to @Query with JOIN FETCH and adding second-level cache (EhCache), response time dropped from 900 to 45 milliseconds. The mobile client stopped showing a loader for more than half a second. Operational cost decreased due to lower database load.
Typical endpoints for mobile API
| Method | URL | Description |
|---|---|---|
| GET | /api/v1/users/{id} | Get user profile |
| POST | /api/v1/auth/login | Authentication, returns JWT |
| GET | /api/v1/transactions?page=0&size=20 | Transaction history with pagination |
| POST | /api/v1/payments | Process payment |
| PUT | /api/v1/users/{id}/push-token | Update push notification token |
Security and authentication
Spring Security 6 with SecurityFilterChain. Stateless authentication: JWT in Authorization header, refresh token in httpOnly cookie or Keychain. OAuth2 / Social Login — spring-security-oauth2-client supports Google, Apple (requires separate configuration of apple provider). For Apple, the non-standard flow with authorization_code and client_secret as JWT signed with ES256 is important.
Project structure
com.example.app ├── api — controllers, DTOs, mappers (MapStruct) ├── domain — entities, repository interfaces ├── service — business logic ├── infrastructure — JPA impl, Redis, FCM, S3 └── config — Spring configuration MapStruct for entity → DTO mapping generates code at compile time — no reflection overhead.
Deployment and operations
Docker image with layered JAR, Jib plugin for building without a Dockerfile. Kubernetes with readiness probe on /actuator/health/readiness and liveness probe on /actuator/health/liveness. HikariCP: maximumPoolSize calculated as (core_count * 2) + effective_spindle_count. For a 4-core instance with SSD, 10 connections per pod are sufficient.
More about CI/CD setup
- Use GitLab CI or GitHub Actions with Maven/Gradle.
- Build with code check via SonarQube.
- Automatic deployment to Kubernetes after successful tests.
- Monitoring via Prometheus/Grafana based on Actuator metrics.
What's included in the work
| Component | Result |
|---|---|
| Documentation | OpenAPI (Swagger) API specification, README for startup |
| Source code | Repository with full backend code, unit tests (JUnit 5, Mockito) |
| Access | Dev/Staging/Prod environments, CI/CD pipeline |
| Support | 30-day warranty for bug fixes after delivery |
| Training | Demo session for client team, architecture walkthrough |
Development timeline
API with 15–20 methods, integration with one external system, authentication — 4–7 weeks. Full backend with realtime (WebSocket), notifications, analytics and CI/CD — 10–16 weeks. Contact us to discuss your project details and get an estimate. Request a consultation — we will analyze your task and offer the optimal solution. We guarantee operational stability and timely delivery.







