You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Star13 (13)You must be signed in to star a repository
About
A modern web application that provides a comprehensive financial dashboard interface, built with Flask and designed to work with banking APIs. This application offers transaction tracking, expense management, savings goals, and family account oversight.
SimpleCrew is a comprehensive financial dashboard that connects to Crew Banking to provide enhanced money management features. Built with a focus on usability and modern design, it offers real-time transaction tracking, intelligent expense management, family account oversight, and a beautiful dark mode experience.
Why SimpleCrew?
Enhanced Visibility - See your Safe-to-Spend, bills, and pockets all in one place
Family Management - Easily monitor and manage your children's accounts and cards
Smart Categorization - Automatic bill detection and expense tracking
Modern UI/UX - Clean, responsive design with dark mode support
PWA Ready - Install on any device for an app-like experience
Features
💰 Financial Dashboard
Feature
Description
Safe-to-Spend
Real-time calculation of available spending money
Transaction History
Searchable, filterable list with smart categorization
Balance Tracking
Historical data with trend analysis
Money Transfers
Seamlessly move funds between accounts and pockets
📊 Expense Management
Feature
Description
Bill Tracking
Automatic reservations and funding schedules
Progress Visualization
Visual progress bars for each expense
Smart Funding
Estimated next funding amounts and dates
Variable Bills
Support for bills with fluctuating amounts
🎯 Savings Pockets
Feature
Description
Goal-Based Saving
Create pockets with target amounts
Group Organization
Organize pockets into custom groups
Quick Transfers
One-click funding from Safe-to-Spend
Activity History
View all transactions per pocket
💳 Card Management
Feature
Description
Physical & Virtual Cards
Full visibility of all card types
Spend Source Control
Assign cards to specific pockets
Bill-Attached Cards
Visual indicator for bill-linked cards
Family Card Support
View and manage children's cards
👨👩👧👦 Family Accounts
Feature
Description
Kids Dashboard
Dedicated view for each child's account
Balance Monitoring
Real-time checking balances
Card Overview
See all cards assigned to each child
Allowance Tracking
View scheduled allowance information
💳 Credit Card Integration
Feature
Description
SimpleFin Support
Connect external credit cards
Auto-Sync
Automatic transaction synchronization
Balance Tracking
Monitor credit card balances
Pocket Linking
Dedicated pockets for credit card payments
🔐 Security & Authentication
Feature
Description
Passkey Authentication
Passwordless login with Face ID, Touch ID, or security keys (WebAuthn/FIDO2)
Password Authentication
Secure username/password login with session management
Add, rename, and remove passkeys from account settings
🎨 User Experience
Feature
Description
Dark Mode
Beautiful dark theme with auto-detection
Responsive Design
Optimized for desktop, tablet, and mobile
PWA Support
Install as a native-like app
Splash Screen
Branded loading experience
Screenshots
Dashboard and transaction views with dark mode support
Screenshots coming soon - the app features a clean, modern interface with support for both light and dark themes.
Quick Start
Prerequisites
Docker and Docker Compose (recommended)
Or: Python 3.9+ for manual installation
Docker Installation (Recommended)
# Clone the repository
git clone https://github.com/Nerdykidtech/SimpleCrew.git
cd SimpleCrew
# Start the application
docker-compose up -d --build
# Open in browser
open http://localhost:8080
Manual Installation
# Clone the repository
git clone https://github.com/Nerdykidtech/SimpleCrew.git
cd SimpleCrew
# Install dependencies
pip install -r requirements.txt
# Create data directory
mkdir -p data
# Run the application
python app.py
# Open in browser
open http://localhost:8080
First-Time Setup
Navigate to http://localhost:8080
Create your account (first-time only):
Enter a username and password
Email is optional
Password must be at least 8 characters
Complete the onboarding flow:
Select Crew Banking as your provider
Enter your Crew bearer token
(Optional) Configure passkeys for passwordless login:
Navigate to Account Settings → Passkey Configuration
Set your RP_ID (domain) and Origin URL
For localhost: Use localhost and http://localhost:8080
For production: Use your domain and HTTPS URL
Click "Add Passkey" in the Passkeys section to register your device
Start managing your finances!
Getting Your Bearer Token: Log into Crew, open browser DevTools (F12), go to Network tab, and find the authorization header in any API request.
Security Note: Only one user account can be created per installation. Registration is automatically disabled after the first user signs up.
Passkey Support: Passkeys work on Chrome 67+, Safari 14+, Firefox 60+, and Edge 18+. HTTPS required in production (localhost works for development).
Authenticate user with password and create session
/api/auth/logout
POST
End user session
/api/auth/register
POST
Create user account (first-time only)
/api/auth/change-password
POST
Update user password
/api/auth/webauthn/register/options
POST
Generate passkey registration options
/api/auth/webauthn/register/verify
POST
Verify and save new passkey credential
/api/auth/webauthn/authenticate/options
POST
Generate passkey authentication options
/api/auth/webauthn/authenticate/verify
POST
Verify passkey and create session
/api/auth/passkeys
GET
List user's registered passkeys
/api/auth/passkeys/<id>
DELETE
Remove a passkey credential
/api/auth/passkeys/<id>
PATCH
Update passkey nickname
/api/account/webauthn/config
GET
Get WebAuthn configuration (RP_ID and ORIGIN)
/api/account/webauthn/update-config
POST
Update WebAuthn configuration
/api/account/webauthn/test
POST
Test WebAuthn configuration validity
Note: All API endpoints below require authentication. Unauthenticated requests will be redirected to /login.
Financial Data
Endpoint
Method
Description
/api/savings
GET
Account balances and savings info
/api/transactions
GET
Transaction history with filtering
/api/transaction/<id>
GET
Individual transaction details
/api/expenses
GET
Monthly expenses and bills
/api/goals
GET
Savings goals and pockets
/api/trends
GET
Monthly spending trends
Account Management
Endpoint
Method
Description
/api/subaccounts
GET
List all subaccounts
/api/family-subaccounts
GET
All family pockets (grouped)
/api/move-money
POST
Transfer funds between accounts
/api/create-pocket
POST
Create new savings pocket
/api/delete-pocket
POST
Delete savings pocket
/api/create-bill
POST
Create new expense bill
/api/delete-bill
POST
Delete expense bill
Family & Cards
Endpoint
Method
Description
/api/family
GET
Family member information
/api/cards
GET
Physical and virtual cards
/api/set-card-spend
POST
Update card spend source
Credit Cards
Endpoint
Method
Description
/api/credit/accounts
GET
Connected credit accounts
/api/credit/transactions/<id>
GET
Credit card transactions
/api/credit/sync/<id>
POST
Sync credit card data
Configuration
Database-Stored Credentials
All credentials and configuration are securely stored in the SQLite database:
Credential
Configuration
User Account
Created during first-time setup
SECRET_KEY
Auto-generated on first run for session encryption
Crew Bearer Token
Set during onboarding or in Account Settings
SimpleFin Access URL
Set in Credit Cards section
LunchFlow API Key
Set in Credit Cards section
Splitwise API Key
Set in Account Settings
Environment Variables (Optional)
Variable
Description
Default
DB_FILE
Database file path
data/savings_data.db
BEARER_TOKEN
Legacy token support (auto-migrated to DB)
-
RP_ID
WebAuthn Relying Party ID (domain for passkeys) - configurable via UI
localhost
ORIGIN
WebAuthn origin URL (must match your deployment URL) - configurable via UI
http://localhost:8080
Note: No environment variables are required. SECRET_KEY is automatically generated and stored in the database on first run.
Passkey Configuration: WebAuthn settings (RP_ID and ORIGIN) can be configured through the Account Settings page under "Passkey Configuration". The UI provides validation and testing to ensure correct configuration. Environment variables are used as fallback only.
Development
Local Development
# Install dependencies
pip install -r requirements.txt
# Run in debug mode
python app.py
Docker Development
# Build and run
docker-compose up --build
# View logs
docker-compose logs -f simplecrew
# Rebuild after changes
docker-compose up -d --build
Deployment
Production Recommendations
HTTPS Required: Use HTTPS with SSL/TLS termination (mandatory for passkeys)
Passkey Configuration: Configure RP_ID and ORIGIN through Account Settings → Passkey Configuration
Alternative: Set RP_ID and ORIGIN environment variables (UI configuration takes precedence)
Set up regular database backups
Configure a reverse proxy (nginx/traefik)
Monitor API rate limits
Implement log aggregation
Docker Production
# Build for production
docker-compose -f docker-compose.prod.yml up -d
# With custom configuration
docker-compose up -d --build
Security
Aspect
Implementation
Passkey Authentication
WebAuthn/FIDO2 protocol with public key cryptography
User Authentication
Flask-Login with session-based authentication
Password Security
PBKDF2-SHA256 hashing with salt
Challenge-Response
Cryptographically secure 32-byte challenges with 15-minute expiration
Sign Count Verification
Detects cloned authenticators via incrementing counter
Session Management
Auto-generated SECRET_KEY, HttpOnly cookies
Route Protection
All API endpoints require authentication
Credential Storage
Securely stored in SQLite database
API Tokens
Validated before storage
Data Directory
Excluded from version control
SQL Injection
Parameterized queries throughout
Best Practices
Recommended: Set up passkeys for secure, passwordless login
Register multiple passkeys (phone, laptop, security key) for redundancy
Use a strong password (8+ characters) if using password authentication
Change your password regularly via Account Settings
Always use HTTPS in production deployments (required for passkeys)
Regularly rotate API credentials
Backup your data/ directory
Keep Docker images updated
Review access logs periodically
Production Security Recommendations
For production deployments, consider adding:
Passkey Authentication: Enable passwordless login for better security and UX
Rate Limiting: Prevent brute-force attacks on login endpoint
A modern web application that provides a comprehensive financial dashboard interface, built with Flask and designed to work with banking APIs. This application offers transaction tracking, expense management, savings goals, and family account oversight.