Agent
AI in the stackA model that can take actions, not just produce text.
A language model given a set of tools it may call, allowed to loop: decide, act, look at the result, decide again. The important design question is not accuracy but blast radius: what the worst wrong action can reach.
See also Tool use, Blast radius, Prompt injection
API
BackendAn agreed set of messages two systems exchange.
The contract between two pieces of software: which requests are valid, and what shape the answers take. Both sides can be rewritten freely as long as the contract holds, which is what makes independent teams possible.
See also Endpoint, Contract, REST
Architecture
BackendWhich pieces exist and how they talk.
Every diagram contains only three things: boxes that remember, boxes that do work, and arrows showing who depends on whom. The boxes that remember are the ones that constrain your options.
See also State, Stateless
Async
InfrastructureStarted now, finished later.
Work that does not block the thing that requested it. The caller gets an acknowledgement rather than a result, and finds out the outcome some other way.
See also Background job, Queue
At-least-once
InfrastructureA delivery guarantee: your job may run more than once.
The normal promise made by queues. If a worker dies after finishing work but before recording completion, the job is handed to another worker and runs again. Jobs must therefore be safe to repeat.
See also Queue, Idempotency, Retry
Authentication
BackendEstablishing who someone is.
Proving identity: a password, a magic link, a sign-in with another provider. Distinct from authorization, which is about permission. Getting these confused is the source of a very common security hole.
See also Authorization, Session, OAuth
Authorization
BackendDeciding whether someone may do a thing.
Checking permission for a specific action on a specific record. Must be checked on the server, per request, per record. Being logged in is not permission to view record 41 just because you asked for it.
See also Authentication, IDOR
Backfill
Data & DatabasesFilling in historical data after adding a new column.
The step in a safe schema change where existing rows are given values for a newly added column. Usually done in batches so it does not lock the table or overwhelm the database.
See also Migration, Schema
Background job
InfrastructureWork done after the response is sent.
Work moved out of the request so the user is not left waiting: sending email, processing an upload, generating a report. Requires somewhere to report progress and somewhere to report failure.
See also Queue, Worker, Cron
Blast radius
AI in the stackHow much damage a wrong action can do.
The scope of what a component can affect when it misbehaves. Read-only access has a small radius; the ability to delete records or send messages on your behalf has a large one. The primary control is not granting the capability at all.
See also Agent, Authorization
Bounce
InfrastructureA message the receiving server refused.
A hard bounce means the address does not exist and never will; a soft bounce is temporary, such as a full mailbox. Sending again to a hard bounce is among the fastest ways to be judged a spammer, which is why providers keep a suppression list on your behalf.
See also Deliverability, Retry, Transactional email
Breaking change
BackendA change that makes existing valid usage stop working.
Removing a field, renaming one, making an optional input required, or changing a type. The problem is that you often cannot fix it by deploying again, because the broken caller is a phone app or a script you do not control.
See also Versioning, Deprecation, Contract
Build
InfrastructureTurning source code into something runnable.
Compiling, bundling and optimising your source into deployable output. A failed build is good news, because the pipeline caught a problem before any user did.
See also Deploy, CI/CD
Cache
InfrastructureA kept copy of something expensive to produce.
A stored result reused instead of being recomputed or refetched. The most effective performance tool available and the source of the most confusing bugs, because a copy can be out of date. Copies live in the browser, the CDN, and your server.
See also CDN, Invalidation, TTL
CDN
InfrastructureCopies of your files in many places worldwide.
A content delivery network keeps copies of static files at locations around the world so users are served from somewhere near them. Cheap, effective, and a place stale content loves to hide.
See also Cache, Edge, Latency
CI/CD
InfrastructureAutomation that tests and ships your changes.
Continuous integration runs checks on every change; continuous delivery deploys the ones that pass. The value is that the deploy path is exercised constantly rather than only on the day it matters.
See also Build, Deploy, Preview deployment
Client
FrontendThe side making the request, usually a browser.
Whatever asks for something: a browser, a mobile app, another server. Crucially it runs on a machine the user controls, so nothing it claims can be trusted without verification.
See also Server, Validation
Cold start
InfrastructureThe delay when no instance is running yet.
When a serverless function has no live instance, one must be created before your code runs. That startup delay is the price of paying nothing while idle, and it lands on whichever unlucky visitor arrives first.
See also Serverless, Stateless
Concurrency
Data & DatabasesMore than one thing happening at the same time.
Simultaneous operations touching the same data. Almost everything a database offers exists to make concurrency safe. Without it, a plain file would be fine.
See also Transaction, Integrity
Consent
BackendThe user agreeing to share something.
The step in a sign-in flow where the user approves what your app is allowed to see. Their agreement, not yours, and revocable by them at any time.
See also OAuth, Identity provider
Container
InfrastructureAn app packaged with everything it needs to run.
Your application plus its exact dependencies and configuration, sealed into one unit that runs identically anywhere. Largely kills "works on my machine" by removing the differences between machines.
See also Serverless, Environment
Context window
AI in the stackHow much a model can consider at once.
The total amount of text (input and output together) a model can have in front of it for a single call. A hard limit. When a conversation exceeds it, earlier messages must be dropped or summarised.
See also Token (model), Prompt caching
Contract
BackendThe agreed shape of messages between systems.
What each side promises the other about requests and responses. Exists whether or not anyone wrote it down. Shared types turn a broken contract into a build error instead of a production incident.
See also API, Breaking change
Cookie
BackendA small value the browser attaches to every request.
How a stateless protocol manages to remember you. The browser stores it and sends it automatically with each request to that site. Marking one HttpOnly prevents JavaScript from reading it, which stops an injected script stealing a session.
See also Session, HttpOnly, JWT
Cron
InfrastructureWork triggered by the clock.
A scheduled job: nightly cleanup, hourly reindex, the weekly digest. Named after a Unix utility from the 1970s. Fails silently by default, because nobody is waiting for it.
See also Scheduled job, Background job, UTC
CSS
FrontendHow a page looks.
Describes presentation: colour, size, spacing, layout. Separate from structure on purpose: remove it and the page is ugly but still works and still makes sense.
See also HTML, DOM
Dead letter queue
InfrastructureWhere jobs go after failing too many times.
A holding area for work that has repeatedly failed, so it stops consuming capacity and starts being visible. A queue system without one either retries forever or loses failures quietly.
See also Queue, Retry
Deliverability
InfrastructureWhether the mail you send reaches an inbox at all.
Sending is your side of it; delivering is the receiving provider’s decision, taken in a fraction of a second on the strength of what your domain says about you. Nothing in your code reports a failure here, which is why it is normally discovered by somebody who never got their password reset.
See also DNS, Transactional email, Bounce
Deploy
InfrastructureMaking new code live.
Build, upload, switch traffic, verify. During the switch two versions run simultaneously, which is why changes must be able to coexist with their predecessor for a few seconds.
See also Rollback, Build, CI/CD
Deprecation
BackendAnnouncing that something will be removed.
Marking a field or endpoint as going away while still supporting it, so callers have time to move. Only meaningful if you can measure who is still using it.
See also Breaking change, Versioning
DNS
FrontendThe system turning names into addresses.
Translates a domain name into the numeric address of a machine. Results are cached in many places you do not control, which is why a DNS change can take hours to be seen everywhere.
See also Latency, TLS
Document store
Data & DatabasesA database of flexible-shaped records.
Stores whole documents rather than rows with fixed columns. Related data is nested rather than joined. Suits genuinely independent records; fights you when your data is full of relationships.
See also NoSQL, SQL, Schema
DOM
FrontendThe browser’s live model of the page.
The structure the browser builds from your HTML and then keeps in memory. JavaScript changes the page by changing the DOM. What you see in the elements inspector is the DOM, not your original HTML.
See also HTML, Rendering
Draft persistence
FrontendSaving what someone typed before they submit.
Keeping long-form input in browser storage as it is written, so an expired session or an accidental navigation does not destroy four paragraphs of work.
See also State, Validation
Durability
Data & DatabasesA confirmed write survives a crash.
The guarantee that once the database says it saved something, that remains true even if the power goes out a millisecond later. Harder than it sounds and a large part of what you pay a database for.
See also Transaction, Concurrency
Edge
InfrastructureRunning code in many locations near users.
Executing in whichever of many worldwide locations is closest to the visitor. A large win for work needing no central data, and a trap for work that queries a database in one region.
See also CDN, Latency, Region
Embedding
AI in the stackText converted to numbers so similarity can be measured.
A numeric representation of meaning. Two passages about the same topic land near each other, which is how a retrieval system finds relevant documents without matching exact words.
See also RAG, Grounding
Empty state
FrontendWhat a user sees when there is genuinely nothing.
The screen shown when a request succeeded and returned no items. Must look different from an error, and is the first thing every new user experiences.
See also Loading state, Skeleton
Endpoint
BackendOne address on a server that does one thing.
A path and a method together. The same path with a different verb is a different endpoint doing something different: GET /orders lists them, POST /orders creates one.
See also API, HTTP, Idempotency
Environment
InfrastructureA complete running copy of your app.
Local, preview, and production are separate copies with their own configuration and usually their own data. The difference that causes the most surprises is data volume.
See also Environment variable, Preview deployment
Environment variable
InfrastructureConfiguration supplied from outside your code.
A value handed to your program when it starts, so the same build can point at a test database locally and the real one in production. Where secrets live, because they must never be in code.
See also Secret, Environment
Exponential backoff
InfrastructureWaiting longer between each retry.
Retrying after one second, then two, then four, with a little randomness added. Prevents everyone retrying in unison and turning a struggling service into a dead one.
See also Retry, Idempotency
Foreign key
Data & DatabasesA column pointing at another table’s row.
How a relationship is stored: an order holds the id of its customer. The database can enforce that the referenced row exists, making a whole class of corruption impossible.
See also Primary key, Join, Integrity
Full table scan
Data & DatabasesReading every row to answer one question.
What the database resorts to when no index supports your query. Instant with ten rows, catastrophic with ten million, which is why this problem never appears during development.
See also Index, Query
GraphQL
BackendAn API style where the client states what it wants.
One endpoint that accepts a description of the desired data. Fills a rich screen in one round trip with no unused fields, at the cost of much harder caching and rate limiting.
See also REST, RPC, API
Grounding
AI in the stackMaking a model answer from supplied sources.
Providing trusted passages in the prompt and instructing the model to answer only from them, then showing which were used. The main practical defence against confident fabrication.
See also RAG, Hallucination
Hallucination
AI in the stackA confident, fluent, false answer.
Fabricated output produced by exactly the same process as correct output, which is why it looks equally convincing. Inherent to how models work rather than a bug to be patched. Fluency carries no information about accuracy.
See also RAG, Grounding
HTML
FrontendThe structure and meaning of a page.
Declares what things are: a heading, a button, a list. Content that lives in the HTML is visible to search engines, screen readers, and slow connections; content built later by JavaScript is not, until it runs.
See also CSS, DOM, Rendering
HTTP
FrontendThe request-and-response protocol of the web.
The rules by which a client asks and a server answers. A request is a method, a path, headers, and maybe a body; a response swaps the method for a status code. Stateless by default.
See also Status code, Stateless, Endpoint
HttpOnly
BackendA cookie flag that hides it from JavaScript.
Marks a cookie unreadable by page scripts, so a single injected script cannot steal a session. Tokens stored in local storage have no equivalent protection.
See also Cookie, Session
Idempotency
InfrastructureDoing it twice has the same effect as doing it once.
A property that makes retrying safe. Usually achieved with a key the caller sends on every attempt; the server records processed keys and returns the original result instead of repeating the work. This is what prevents double charges.
See also Retry, At-least-once, Endpoint
Identity provider
BackendThe service that vouches for who someone is.
Google, GitHub, Apple, or a dedicated auth service. You delegate the password, the resets, the breach handling and the two-factor to them, and depend on their availability in return.
See also OAuth, Authentication
IDOR
BackendReading someone else’s data by changing an id.
Insecure direct object reference: checking that a user is logged in but not that the requested record belongs to them. Trivially exploitable by editing a URL, and extremely common in generated code.
See also Authorization, Authentication
Incident
InfrastructureSomething is broken for real users right now.
Stop the impact first, understand it second. "What changed recently" answers most incidents, and rolling back is the cheapest action available.
See also Rollback, Postmortem
Index
Data & DatabasesA lookup structure that makes one kind of query fast.
Like the index at the back of a book. Makes lookups on the indexed column fast, does nothing for other columns, costs storage, and slows down writes. Chosen per query pattern, not sprinkled everywhere.
See also Query, N+1, Full table scan
Integrity
Data & DatabasesRules the data cannot violate.
Constraints enforced by the database itself, such as an order having to belong to a customer that exists. Enforced there, they survive every future bug in every future code path.
See also Foreign key, Transaction
Invalidation
InfrastructureTelling a cache its copy is now wrong.
Actively clearing cached copies when the underlying data changes. Always fresh, but you own the job of finding every place a copy might live. Content-based filenames avoid needing it at all.
See also Cache, TTL, CDN
Join
Data & DatabasesAnswering a question that spans two tables.
Matching rows across tables using a key: orders with their customer names attached. Ordinary and fast when the columns involved are indexed, and very slow when they are not.
See also Foreign key, Index, Normalisation
JSON
BackendA text format of keys and values.
How systems usually exchange structured data. Readable by every language and by you. It carries a shape both sides agreed on, but nothing enforces that agreement at runtime, which is why validation exists.
See also API, Contract, Validation
JWT
BackendA signed token that carries its own data.
A token containing information, cryptographically signed so it cannot be altered. Needs no server lookup, which scales well, but cannot be revoked before it expires, so it must be short-lived.
See also Session, Cookie, Token
Key rotation
BackendReplacing a secret with a new one.
Issuing a new credential and revoking the old. The first thing to do when a secret leaks: bots scrape public repositories within minutes, so deleting the line changes nothing on its own.
See also Secret, Environment variable
Latency
InfrastructureTime spent waiting rather than working.
The delay before a response begins. Largely set by physical distance and the number of round trips, not by processing speed. London to Virginia is about 80ms round trip no matter how good your code is.
See also Round trip, Edge, CDN
Loading state
FrontendWhat is shown while a request is in flight.
One of four states every piece of loaded data has. Best delayed slightly so fast responses do not flicker, then held briefly once shown so it does not flash.
See also Empty state, Skeleton
localhost
InfrastructureThis machine, talking to itself.
The address a computer uses for itself. Reachable only from that machine, which is why your dev server is not visible to anyone else on the internet.
See also Port, Server
Logs
InfrastructureA record of individual events.
Detailed entries about specific things that happened. Excellent for investigating one failure, poor for spotting trends, and expensive at volume. Log identifiers, never raw request bodies.
See also Metrics, Tracing, Observability
Metrics
InfrastructureNumbers tracked over time.
Counts and durations: requests per minute, error rate, response time. Cheap to keep for a long time and the right tool for "is this worse than yesterday". Cannot tell you about one specific user.
See also Logs, Tracing
Migration
Data & DatabasesA recorded, ordered change to your data’s shape.
A versioned schema change applied identically in every environment. Needed because code can be rolled back in seconds and data cannot. Safe changes expand first, then contract days later.
See also Schema, Backfill, Rollback
N+1
Data & DatabasesOne query for the list, then one per item.
Fetching 50 posts and then fetching each post’s author separately: 51 round trips. Invisible with test data, ruinous with real data. A database call inside a loop is the tell.
See also Query, Index
Non-deterministic
AI in the stackThe same input can produce different output.
True of language models and untrue of most other APIs. Means tests cannot assert on exact strings, and that a bug may not reproduce on demand.
See also Hallucination, Streaming
Normalisation
Data & DatabasesStoring each fact in exactly one place.
Structuring tables so a customer email lives once and everything else points at it. Changing it is then one edit rather than a thousand. Deliberately duplicating for read speed is denormalisation, and you own keeping the copies in step.
See also Foreign key, Join
NoSQL
Data & DatabasesDatabases that are not table-and-row relational.
A loose family including document, key-value and graph stores. Flexible shape and easier extreme scale, at the cost that nothing prevents two records disagreeing about structure. The schema does not disappear; it moves into your code.
See also SQL, Document store, Schema
OAuth
BackendSigning in via another provider.
The user authenticates with Google or GitHub, who then tell your app who they are. You never see the password, so you cannot leak it. Has enough subtle failure modes that you should always use a library.
See also Authentication, Identity provider, Token
Observability
InfrastructureBeing able to tell what your system is doing.
The combination of logs, metrics and traces that lets you answer questions about a running system, including questions you did not anticipate when you built it.
See also Logs, Metrics, Tracing
Optimistic update
FrontendShowing the result before it is confirmed.
Updating the screen immediately on the assumption the request will succeed, reverting if it does not. Right for likes and checkboxes, wrong for payments and deletions. The revert path is the one nobody tests.
See also Pending state, Rollback
Overlap
InfrastructureA scheduled job starting before the last one finished.
An hourly job that takes seventy minutes will have two copies running. Whether that is harmless or catastrophic depends entirely on what the job does.
See also Cron, Scheduled job
Payload
FrontendThe amount of data being sent.
The size of what travels over the network. One of four unrelated kinds of slow, and the one that gets dramatically worse on mobile connections.
See also Latency, Rendering
Pending state
FrontendShown, but not yet confirmed.
The honest middle ground for an optimistic update: display the change immediately, but mark it as unconfirmed. A failure then becomes a change of state rather than a contradiction.
See also Optimistic update, Loading state
Port
InfrastructureWhich program on a machine you are talking to.
A number that lets one machine run many servers at once. The address finds the machine, the port finds the program: a web app on 3000, a database on 5432.
See also Server, localhost
Postmortem
InfrastructureA written account of an incident, without blame.
What happened, what the impact was, and what allowed it to reach users. The useful question is never who did it but which missing check would have caught it.
See also Incident, Rollback
Preview deployment
InfrastructureA temporary live copy of a proposed change.
A working URL for a change before it is accepted, so it can be clicked rather than described. Also means the deploy path is exercised constantly rather than only when it is scary.
See also Environment, CI/CD
Primary key
Data & DatabasesThe column that uniquely identifies a row.
The one value that picks out exactly one row in a table. Other tables refer to a row by holding its primary key, which is how relationships are built.
See also Foreign key, Table
Process
InfrastructureA running program.
One instance of your code, executing. A server is a process that is listening; when it exits, the server is gone even though the machine is still on.
See also Server, Port
Prompt caching
AI in the stackReusing an unchanged prefix across calls.
When the same large preamble is sent on every request, providers often charge a reduced rate for the repeated part. One of the cheapest available reductions in model cost.
See also Token (model), Context window
Prompt injection
AI in the stackHostile instructions hidden in content a model reads.
A web page, email or uploaded file containing text aimed at the model rather than the reader. There is no reliable filter, because instructions and data arrive through the same channel. Limit what the agent can do instead.
See also Agent, Blast radius, Tool use
Query
Data & DatabasesA question asked of the database.
A request for data. Cheap when an index supports it, ruinous when it forces a scan of every row. Which questions you ask should be a design decision, not an accident.
See also Index, N+1, Full table scan
Queue
InfrastructureA durable list of work waiting to be done.
Holds jobs until a worker picks them up, absorbing spikes by delaying work rather than dropping it. Survives crashes, and normally guarantees at-least-once delivery.
See also Worker, At-least-once, Dead letter queue
RAG
AI in the stackSearch first, then answer from what was found.
Retrieval-augmented generation: find relevant passages in trusted content, put them in the prompt, and have the model answer from them with citations. When results are bad the culprit is usually the search step, not the model.
See also Embedding, Grounding, Hallucination
Rate limit
BackendA cap on how often you may call something.
A restriction on request frequency, signalled by a 429 status. Exists to keep one caller from consuming a shared service. Respect it by backing off rather than retrying immediately.
See also Status code, Retry, Exponential backoff
Region
InfrastructureWhere in the world your machines physically are.
The geographic location of a datacentre. Determines the unavoidable minimum latency for users, and where your data legally resides.
See also Latency, Edge
Rendering
FrontendTurning content into pixels.
The browser converting HTML, CSS and JavaScript into a visible page. Server-side rendering does the first pass on the server so content exists in the HTML immediately rather than after scripts run.
See also HTML, DOM, Payload
REST
BackendAn API style organised around things.
Endpoints named after resources (/users, /orders) with HTTP verbs saying what to do to them. Highly cacheable and easy to inspect. A rich screen may need several calls.
See also GraphQL, RPC, Endpoint
Retry
InfrastructureTrying again after a failure.
Reasonable for 5xx errors and network failures, pointless for 4xx. Must be paired with increasing delays and with idempotency, or it turns a lost response into a duplicate action.
See also Idempotency, Exponential backoff, Status code
Rollback
InfrastructurePutting the previous version back.
The cheapest available response to a bad deploy and the correct first move in most incidents. Restores your code, not your data: deleted rows and sent emails do not come back.
See also Deploy, Migration, Incident
Round trip
FrontendOne journey there and back across the network.
The unit that actually determines perceived speed. Eight sequential round trips is slow no matter how fast the connection, which is why chattiness matters more than bandwidth.
See also Latency, DNS
RPC
BackendCalling a named function on another machine.
An API style where you invoke an action directly rather than modelling resources. With shared types, a contract break becomes a build error, which is why it suits an app talking to its own backend.
See also Server function, REST, API
Scheduled job
InfrastructureWork that runs because of the time, not a user.
A job triggered on a schedule. Fails in four classic ways: timezones, overlapping runs, missed runs, and growing workloads. Alert on the absence of success, not on failure.
See also Cron, Background job, UTC
Schema
Data & DatabasesThe declared shape of your data.
Which tables exist, which columns they have, and what is allowed in them. Changing it is a migration. In schemaless databases the schema still exists, just in your code instead of the database.
See also Migration, Table, NoSQL
Search params
FrontendThe part of a URL after the question mark.
Key-value pairs carrying page state: filters, queries, sorting. Putting state here makes it shareable, survivable across refreshes, and correct with the back button. Validating it means a hand-edited URL degrades instead of crashing.
See also State, Validation
Secret
BackendAny value that grants access.
A database password, an API key, a signing key. Never in code, never in a client bundle. If one leaks, revoke it first. Deleting the line comes second, and git history keeps it regardless.
See also Environment variable, Key rotation
Server
BackendA program that is open for business.
A running program listening for requests and answering them. Not a piece of hardware: one machine can run several, and it stops being a server the moment the program exits. Your laptop runs one every time you start a dev command.
See also Client, Port, Process
Server function
BackendA function you call from the client that runs on the server.
Written like a normal function, but the build replaces the body with a network call in the client bundle and the real implementation only ever exists on the server. You get a typed contract for free and the server code never ships to the browser.
See also RPC, Validation, Secret
Server state
FrontendData fetched from an API, held in the UI.
Not really your application’s state, but a cache of somebody else’s, which goes stale the moment anyone else changes it. Treating it as local state is what produces "I updated it but the list still shows the old value".
See also State, Cache
Serverless
InfrastructureYou ship a function; something else runs it.
The platform decides when to run your code, how many copies to run, and when to discard them. Costs nothing while idle, scales without thought, and gives you no persistent memory between requests.
See also Cold start, Stateless, Container
Session
BackendThe server-side record that you are logged in.
A stored record the server looks up on each request using an id from a cookie. Slower than a signed token because of the lookup, but logging out is instant and reliable.
See also Cookie, JWT, Authentication
Skeleton
FrontendA grey outline shown while content loads.
A placeholder in the shape of the coming content. Tells the user what to expect and prevents the page jumping when data arrives, which a spinner does neither of.
See also Loading state, Empty state
SQL
Data & DatabasesThe language for asking relational databases questions.
The query language of relational databases. Also used loosely to mean the relational family itself (Postgres, MySQL, SQLite) as opposed to NoSQL.
See also Query, NoSQL, Table
State
FrontendData that can change.
The real question is never what the state is but where the authoritative copy lives: the server, the URL, component memory, or browser storage. Two copies of the same fact will eventually disagree.
See also Server state, Search params
Stateless
BackendEach request starts from nothing.
The server remembers nothing about you between requests by default. Memory has to be added deliberately, which is exactly what cookies and sessions are for.
See also HTTP, Session, Serverless
Status code
BackendA three-digit verdict on a request.
The first digit is what matters: 2xx worked, 3xx moved, 4xx you asked wrong, 5xx they broke. The 4 versus 5 distinction decides whether retrying can possibly help.
See also HTTP, Retry, Rate limit
Streaming
AI in the stackSending a response in pieces as it is produced.
Delivering output progressively instead of waiting for all of it. Does not make anything faster; makes waiting tolerable, which is usually the real problem. Applies to slow page data as much as to model output.
See also Latency, Rendering
Table
Data & DatabasesA spreadsheet with a strict header.
Rows are things, columns are facts about them, and every row has the same columns with declared types. That strictness is what lets the database refuse bad data.
See also Primary key, Schema, SQL
Timeout
InfrastructureA hard limit on how long something may take.
Enforced by browsers, proxies, and serverless platforms. Work that exceeds one is killed partway through, leaving whatever it was doing half-finished.
See also Background job, Retry
TLS
FrontendThe encryption behind the S in HTTPS.
Makes the connection private and tamper-proof. Without it, anything between the user and your server can read and modify the page. Costs an extra handshake on the first connection.
See also DNS, Latency
Token
BackendA string that proves something about you.
A credential passed with requests to identify or authorise the holder. Anyone holding it can use it, which is why tokens are short-lived and kept out of reach of page scripts.
See also JWT, Session, OAuth
Token (model)
AI in the stackThe unit models read, write, and charge by.
Roughly three quarters of a word. Everything meters in tokens: cost, the context window, and how long a response takes to produce.
See also Context window, Prompt caching
Tool use
AI in the stackLetting a model call functions you define.
Giving a model a set of actions it may take: search, fetch, create. Turns a text generator into something that affects the world, which makes what you grant far more important than how well it reasons.
See also Agent, Blast radius
Tracing
InfrastructureFollowing one request across every system it touches.
A timed record of a single request as it moves between services. When four systems are involved and something is slow, a trace identifies the culprit in seconds instead of hours.
See also Logs, Metrics, Observability
Transaction
Data & DatabasesAll of these changes, or none of them.
A group of changes applied as one unit. Without it, "take money from A" can succeed while "give money to B" fails. Any operation touching two things at once needs one.
See also Durability, Integrity, Concurrency
Transactional email
InfrastructureMail sent because a user just did something.
Password resets, receipts, confirmations: expected within seconds by a person who is waiting for them. Distinct from marketing mail, which goes out on your schedule and needs consent. Mixing the two costs you the reputation that gets the urgent one delivered.
See also Deliverability, Consent, Bounce
TTL
InfrastructureHow long a cached copy stays valid.
Time to live: the expiry on a cached item. Simple to reason about, at the price of accepting staleness up to that duration.
See also Cache, Invalidation
UTC
InfrastructureThe timezone servers actually run in.
Coordinated Universal Time, with no daylight saving. Servers use it so that timestamps are unambiguous. It is also why a job scheduled for "8am" may not run at 8am where your users are.
See also Cron, Scheduled job
Validation
BackendChecking that input is what you expected.
In the browser it is a courtesy that makes things pleasant. On the server it is a control, because requests do not have to come from your form. You need both, ideally from one shared schema so they cannot disagree.
See also Server function, Search params, Client
Versioning
BackendRunning old and new API shapes side by side.
Offering /v1 and /v2 so existing callers keep working while new ones use the new shape. The same expand-then-contract idea as a safe schema migration, applied to an API.
See also Breaking change, Deprecation
Worker
InfrastructureA process that pulls jobs off a queue and does them.
Separate from your web app, so you can deploy one without interrupting the other and add more workers to drain a backlog faster.
See also Queue, Background job