Glossary

The words, without the shrug

Every term the courses use, defined in one line and then in a paragraph. Written to be read out of order.

Showing 124 of 124

Agent

AI in the stack

A model that can take actions, not just produce text.

A language model given a set of tools it may call, allowed to loop: decide, act, look at the result, decide again. The important design question is not accuracy but blast radius: what the worst wrong action can reach.

See also Tool use, Blast radius, Prompt injection

API

Backend

An agreed set of messages two systems exchange.

The contract between two pieces of software: which requests are valid, and what shape the answers take. Both sides can be rewritten freely as long as the contract holds, which is what makes independent teams possible.

See also Endpoint, Contract, REST

Architecture

Backend

Which pieces exist and how they talk.

Every diagram contains only three things: boxes that remember, boxes that do work, and arrows showing who depends on whom. The boxes that remember are the ones that constrain your options.

See also State, Stateless

Async

Infrastructure

Started now, finished later.

Work that does not block the thing that requested it. The caller gets an acknowledgement rather than a result, and finds out the outcome some other way.

See also Background job, Queue

At-least-once

Infrastructure

A delivery guarantee: your job may run more than once.

The normal promise made by queues. If a worker dies after finishing work but before recording completion, the job is handed to another worker and runs again. Jobs must therefore be safe to repeat.

See also Queue, Idempotency, Retry

Authentication

Backend

Establishing who someone is.

Proving identity: a password, a magic link, a sign-in with another provider. Distinct from authorization, which is about permission. Getting these confused is the source of a very common security hole.

See also Authorization, Session, OAuth

Authorization

Backend

Deciding whether someone may do a thing.

Checking permission for a specific action on a specific record. Must be checked on the server, per request, per record. Being logged in is not permission to view record 41 just because you asked for it.

See also Authentication, IDOR

Backfill

Data & Databases

Filling in historical data after adding a new column.

The step in a safe schema change where existing rows are given values for a newly added column. Usually done in batches so it does not lock the table or overwhelm the database.

See also Migration, Schema

Background job

Infrastructure

Work done after the response is sent.

Work moved out of the request so the user is not left waiting: sending email, processing an upload, generating a report. Requires somewhere to report progress and somewhere to report failure.

See also Queue, Worker, Cron

Blast radius

AI in the stack

How much damage a wrong action can do.

The scope of what a component can affect when it misbehaves. Read-only access has a small radius; the ability to delete records or send messages on your behalf has a large one. The primary control is not granting the capability at all.

See also Agent, Authorization

Bounce

Infrastructure

A message the receiving server refused.

A hard bounce means the address does not exist and never will; a soft bounce is temporary, such as a full mailbox. Sending again to a hard bounce is among the fastest ways to be judged a spammer, which is why providers keep a suppression list on your behalf.

See also Deliverability, Retry, Transactional email

Breaking change

Backend

A change that makes existing valid usage stop working.

Removing a field, renaming one, making an optional input required, or changing a type. The problem is that you often cannot fix it by deploying again, because the broken caller is a phone app or a script you do not control.

See also Versioning, Deprecation, Contract

Build

Infrastructure

Turning source code into something runnable.

Compiling, bundling and optimising your source into deployable output. A failed build is good news, because the pipeline caught a problem before any user did.

See also Deploy, CI/CD

Cache

Infrastructure

A kept copy of something expensive to produce.

A stored result reused instead of being recomputed or refetched. The most effective performance tool available and the source of the most confusing bugs, because a copy can be out of date. Copies live in the browser, the CDN, and your server.

See also CDN, Invalidation, TTL

CDN

Infrastructure

Copies of your files in many places worldwide.

A content delivery network keeps copies of static files at locations around the world so users are served from somewhere near them. Cheap, effective, and a place stale content loves to hide.

See also Cache, Edge, Latency

CI/CD

Infrastructure

Automation that tests and ships your changes.

Continuous integration runs checks on every change; continuous delivery deploys the ones that pass. The value is that the deploy path is exercised constantly rather than only on the day it matters.

See also Build, Deploy, Preview deployment

Client

Frontend

The side making the request, usually a browser.

Whatever asks for something: a browser, a mobile app, another server. Crucially it runs on a machine the user controls, so nothing it claims can be trusted without verification.

See also Server, Validation

Cold start

Infrastructure

The delay when no instance is running yet.

When a serverless function has no live instance, one must be created before your code runs. That startup delay is the price of paying nothing while idle, and it lands on whichever unlucky visitor arrives first.

See also Serverless, Stateless

Concurrency

Data & Databases

More than one thing happening at the same time.

Simultaneous operations touching the same data. Almost everything a database offers exists to make concurrency safe. Without it, a plain file would be fine.

See also Transaction, Integrity

Container

Infrastructure

An app packaged with everything it needs to run.

Your application plus its exact dependencies and configuration, sealed into one unit that runs identically anywhere. Largely kills "works on my machine" by removing the differences between machines.

See also Serverless, Environment

Context window

AI in the stack

How much a model can consider at once.

The total amount of text (input and output together) a model can have in front of it for a single call. A hard limit. When a conversation exceeds it, earlier messages must be dropped or summarised.

See also Token (model), Prompt caching

Contract

Backend

The agreed shape of messages between systems.

What each side promises the other about requests and responses. Exists whether or not anyone wrote it down. Shared types turn a broken contract into a build error instead of a production incident.

See also API, Breaking change

Cron

Infrastructure

Work triggered by the clock.

A scheduled job: nightly cleanup, hourly reindex, the weekly digest. Named after a Unix utility from the 1970s. Fails silently by default, because nobody is waiting for it.

See also Scheduled job, Background job, UTC

CSS

Frontend

How a page looks.

Describes presentation: colour, size, spacing, layout. Separate from structure on purpose: remove it and the page is ugly but still works and still makes sense.

See also HTML, DOM

Dead letter queue

Infrastructure

Where jobs go after failing too many times.

A holding area for work that has repeatedly failed, so it stops consuming capacity and starts being visible. A queue system without one either retries forever or loses failures quietly.

See also Queue, Retry

Deliverability

Infrastructure

Whether the mail you send reaches an inbox at all.

Sending is your side of it; delivering is the receiving provider’s decision, taken in a fraction of a second on the strength of what your domain says about you. Nothing in your code reports a failure here, which is why it is normally discovered by somebody who never got their password reset.

See also DNS, Transactional email, Bounce

Deploy

Infrastructure

Making new code live.

Build, upload, switch traffic, verify. During the switch two versions run simultaneously, which is why changes must be able to coexist with their predecessor for a few seconds.

See also Rollback, Build, CI/CD

Deprecation

Backend

Announcing that something will be removed.

Marking a field or endpoint as going away while still supporting it, so callers have time to move. Only meaningful if you can measure who is still using it.

See also Breaking change, Versioning

DNS

Frontend

The system turning names into addresses.

Translates a domain name into the numeric address of a machine. Results are cached in many places you do not control, which is why a DNS change can take hours to be seen everywhere.

See also Latency, TLS

Document store

Data & Databases

A database of flexible-shaped records.

Stores whole documents rather than rows with fixed columns. Related data is nested rather than joined. Suits genuinely independent records; fights you when your data is full of relationships.

See also NoSQL, SQL, Schema

DOM

Frontend

The browser’s live model of the page.

The structure the browser builds from your HTML and then keeps in memory. JavaScript changes the page by changing the DOM. What you see in the elements inspector is the DOM, not your original HTML.

See also HTML, Rendering

Draft persistence

Frontend

Saving what someone typed before they submit.

Keeping long-form input in browser storage as it is written, so an expired session or an accidental navigation does not destroy four paragraphs of work.

See also State, Validation

Durability

Data & Databases

A confirmed write survives a crash.

The guarantee that once the database says it saved something, that remains true even if the power goes out a millisecond later. Harder than it sounds and a large part of what you pay a database for.

See also Transaction, Concurrency

Edge

Infrastructure

Running code in many locations near users.

Executing in whichever of many worldwide locations is closest to the visitor. A large win for work needing no central data, and a trap for work that queries a database in one region.

See also CDN, Latency, Region

Embedding

AI in the stack

Text converted to numbers so similarity can be measured.

A numeric representation of meaning. Two passages about the same topic land near each other, which is how a retrieval system finds relevant documents without matching exact words.

See also RAG, Grounding

Empty state

Frontend

What a user sees when there is genuinely nothing.

The screen shown when a request succeeded and returned no items. Must look different from an error, and is the first thing every new user experiences.

See also Loading state, Skeleton

Endpoint

Backend

One address on a server that does one thing.

A path and a method together. The same path with a different verb is a different endpoint doing something different: GET /orders lists them, POST /orders creates one.

See also API, HTTP, Idempotency

Environment

Infrastructure

A complete running copy of your app.

Local, preview, and production are separate copies with their own configuration and usually their own data. The difference that causes the most surprises is data volume.

See also Environment variable, Preview deployment

Environment variable

Infrastructure

Configuration supplied from outside your code.

A value handed to your program when it starts, so the same build can point at a test database locally and the real one in production. Where secrets live, because they must never be in code.

See also Secret, Environment

Exponential backoff

Infrastructure

Waiting longer between each retry.

Retrying after one second, then two, then four, with a little randomness added. Prevents everyone retrying in unison and turning a struggling service into a dead one.

See also Retry, Idempotency

Foreign key

Data & Databases

A column pointing at another table’s row.

How a relationship is stored: an order holds the id of its customer. The database can enforce that the referenced row exists, making a whole class of corruption impossible.

See also Primary key, Join, Integrity

Full table scan

Data & Databases

Reading every row to answer one question.

What the database resorts to when no index supports your query. Instant with ten rows, catastrophic with ten million, which is why this problem never appears during development.

See also Index, Query

GraphQL

Backend

An API style where the client states what it wants.

One endpoint that accepts a description of the desired data. Fills a rich screen in one round trip with no unused fields, at the cost of much harder caching and rate limiting.

See also REST, RPC, API

Grounding

AI in the stack

Making a model answer from supplied sources.

Providing trusted passages in the prompt and instructing the model to answer only from them, then showing which were used. The main practical defence against confident fabrication.

See also RAG, Hallucination

Hallucination

AI in the stack

A confident, fluent, false answer.

Fabricated output produced by exactly the same process as correct output, which is why it looks equally convincing. Inherent to how models work rather than a bug to be patched. Fluency carries no information about accuracy.

See also RAG, Grounding

HTML

Frontend

The structure and meaning of a page.

Declares what things are: a heading, a button, a list. Content that lives in the HTML is visible to search engines, screen readers, and slow connections; content built later by JavaScript is not, until it runs.

See also CSS, DOM, Rendering

HTTP

Frontend

The request-and-response protocol of the web.

The rules by which a client asks and a server answers. A request is a method, a path, headers, and maybe a body; a response swaps the method for a status code. Stateless by default.

See also Status code, Stateless, Endpoint

HttpOnly

Backend

A cookie flag that hides it from JavaScript.

Marks a cookie unreadable by page scripts, so a single injected script cannot steal a session. Tokens stored in local storage have no equivalent protection.

See also Cookie, Session

Idempotency

Infrastructure

Doing it twice has the same effect as doing it once.

A property that makes retrying safe. Usually achieved with a key the caller sends on every attempt; the server records processed keys and returns the original result instead of repeating the work. This is what prevents double charges.

See also Retry, At-least-once, Endpoint

Identity provider

Backend

The service that vouches for who someone is.

Google, GitHub, Apple, or a dedicated auth service. You delegate the password, the resets, the breach handling and the two-factor to them, and depend on their availability in return.

See also OAuth, Authentication

IDOR

Backend

Reading someone else’s data by changing an id.

Insecure direct object reference: checking that a user is logged in but not that the requested record belongs to them. Trivially exploitable by editing a URL, and extremely common in generated code.

See also Authorization, Authentication

Incident

Infrastructure

Something is broken for real users right now.

Stop the impact first, understand it second. "What changed recently" answers most incidents, and rolling back is the cheapest action available.

See also Rollback, Postmortem

Index

Data & Databases

A lookup structure that makes one kind of query fast.

Like the index at the back of a book. Makes lookups on the indexed column fast, does nothing for other columns, costs storage, and slows down writes. Chosen per query pattern, not sprinkled everywhere.

See also Query, N+1, Full table scan

Integrity

Data & Databases

Rules the data cannot violate.

Constraints enforced by the database itself, such as an order having to belong to a customer that exists. Enforced there, they survive every future bug in every future code path.

See also Foreign key, Transaction

Invalidation

Infrastructure

Telling a cache its copy is now wrong.

Actively clearing cached copies when the underlying data changes. Always fresh, but you own the job of finding every place a copy might live. Content-based filenames avoid needing it at all.

See also Cache, TTL, CDN

Join

Data & Databases

Answering a question that spans two tables.

Matching rows across tables using a key: orders with their customer names attached. Ordinary and fast when the columns involved are indexed, and very slow when they are not.

See also Foreign key, Index, Normalisation

JSON

Backend

A text format of keys and values.

How systems usually exchange structured data. Readable by every language and by you. It carries a shape both sides agreed on, but nothing enforces that agreement at runtime, which is why validation exists.

See also API, Contract, Validation

JWT

Backend

A signed token that carries its own data.

A token containing information, cryptographically signed so it cannot be altered. Needs no server lookup, which scales well, but cannot be revoked before it expires, so it must be short-lived.

See also Session, Cookie, Token

Key rotation

Backend

Replacing a secret with a new one.

Issuing a new credential and revoking the old. The first thing to do when a secret leaks: bots scrape public repositories within minutes, so deleting the line changes nothing on its own.

See also Secret, Environment variable

Latency

Infrastructure

Time spent waiting rather than working.

The delay before a response begins. Largely set by physical distance and the number of round trips, not by processing speed. London to Virginia is about 80ms round trip no matter how good your code is.

See also Round trip, Edge, CDN

Loading state

Frontend

What is shown while a request is in flight.

One of four states every piece of loaded data has. Best delayed slightly so fast responses do not flicker, then held briefly once shown so it does not flash.

See also Empty state, Skeleton

localhost

Infrastructure

This machine, talking to itself.

The address a computer uses for itself. Reachable only from that machine, which is why your dev server is not visible to anyone else on the internet.

See also Port, Server

Logs

Infrastructure

A record of individual events.

Detailed entries about specific things that happened. Excellent for investigating one failure, poor for spotting trends, and expensive at volume. Log identifiers, never raw request bodies.

See also Metrics, Tracing, Observability

Metrics

Infrastructure

Numbers tracked over time.

Counts and durations: requests per minute, error rate, response time. Cheap to keep for a long time and the right tool for "is this worse than yesterday". Cannot tell you about one specific user.

See also Logs, Tracing

Migration

Data & Databases

A recorded, ordered change to your data’s shape.

A versioned schema change applied identically in every environment. Needed because code can be rolled back in seconds and data cannot. Safe changes expand first, then contract days later.

See also Schema, Backfill, Rollback

N+1

Data & Databases

One query for the list, then one per item.

Fetching 50 posts and then fetching each post’s author separately: 51 round trips. Invisible with test data, ruinous with real data. A database call inside a loop is the tell.

See also Query, Index

Non-deterministic

AI in the stack

The same input can produce different output.

True of language models and untrue of most other APIs. Means tests cannot assert on exact strings, and that a bug may not reproduce on demand.

See also Hallucination, Streaming

Normalisation

Data & Databases

Storing each fact in exactly one place.

Structuring tables so a customer email lives once and everything else points at it. Changing it is then one edit rather than a thousand. Deliberately duplicating for read speed is denormalisation, and you own keeping the copies in step.

See also Foreign key, Join

NoSQL

Data & Databases

Databases that are not table-and-row relational.

A loose family including document, key-value and graph stores. Flexible shape and easier extreme scale, at the cost that nothing prevents two records disagreeing about structure. The schema does not disappear; it moves into your code.

See also SQL, Document store, Schema

OAuth

Backend

Signing in via another provider.

The user authenticates with Google or GitHub, who then tell your app who they are. You never see the password, so you cannot leak it. Has enough subtle failure modes that you should always use a library.

See also Authentication, Identity provider, Token

Observability

Infrastructure

Being able to tell what your system is doing.

The combination of logs, metrics and traces that lets you answer questions about a running system, including questions you did not anticipate when you built it.

See also Logs, Metrics, Tracing

Optimistic update

Frontend

Showing the result before it is confirmed.

Updating the screen immediately on the assumption the request will succeed, reverting if it does not. Right for likes and checkboxes, wrong for payments and deletions. The revert path is the one nobody tests.

See also Pending state, Rollback

Overlap

Infrastructure

A scheduled job starting before the last one finished.

An hourly job that takes seventy minutes will have two copies running. Whether that is harmless or catastrophic depends entirely on what the job does.

See also Cron, Scheduled job

Payload

Frontend

The amount of data being sent.

The size of what travels over the network. One of four unrelated kinds of slow, and the one that gets dramatically worse on mobile connections.

See also Latency, Rendering

Pending state

Frontend

Shown, but not yet confirmed.

The honest middle ground for an optimistic update: display the change immediately, but mark it as unconfirmed. A failure then becomes a change of state rather than a contradiction.

See also Optimistic update, Loading state

Port

Infrastructure

Which program on a machine you are talking to.

A number that lets one machine run many servers at once. The address finds the machine, the port finds the program: a web app on 3000, a database on 5432.

See also Server, localhost

Postmortem

Infrastructure

A written account of an incident, without blame.

What happened, what the impact was, and what allowed it to reach users. The useful question is never who did it but which missing check would have caught it.

See also Incident, Rollback

Preview deployment

Infrastructure

A temporary live copy of a proposed change.

A working URL for a change before it is accepted, so it can be clicked rather than described. Also means the deploy path is exercised constantly rather than only when it is scary.

See also Environment, CI/CD

Primary key

Data & Databases

The column that uniquely identifies a row.

The one value that picks out exactly one row in a table. Other tables refer to a row by holding its primary key, which is how relationships are built.

See also Foreign key, Table

Process

Infrastructure

A running program.

One instance of your code, executing. A server is a process that is listening; when it exits, the server is gone even though the machine is still on.

See also Server, Port

Prompt caching

AI in the stack

Reusing an unchanged prefix across calls.

When the same large preamble is sent on every request, providers often charge a reduced rate for the repeated part. One of the cheapest available reductions in model cost.

See also Token (model), Context window

Prompt injection

AI in the stack

Hostile instructions hidden in content a model reads.

A web page, email or uploaded file containing text aimed at the model rather than the reader. There is no reliable filter, because instructions and data arrive through the same channel. Limit what the agent can do instead.

See also Agent, Blast radius, Tool use

Query

Data & Databases

A question asked of the database.

A request for data. Cheap when an index supports it, ruinous when it forces a scan of every row. Which questions you ask should be a design decision, not an accident.

See also Index, N+1, Full table scan

Queue

Infrastructure

A durable list of work waiting to be done.

Holds jobs until a worker picks them up, absorbing spikes by delaying work rather than dropping it. Survives crashes, and normally guarantees at-least-once delivery.

See also Worker, At-least-once, Dead letter queue

RAG

AI in the stack

Search first, then answer from what was found.

Retrieval-augmented generation: find relevant passages in trusted content, put them in the prompt, and have the model answer from them with citations. When results are bad the culprit is usually the search step, not the model.

See also Embedding, Grounding, Hallucination

Rate limit

Backend

A cap on how often you may call something.

A restriction on request frequency, signalled by a 429 status. Exists to keep one caller from consuming a shared service. Respect it by backing off rather than retrying immediately.

See also Status code, Retry, Exponential backoff

Region

Infrastructure

Where in the world your machines physically are.

The geographic location of a datacentre. Determines the unavoidable minimum latency for users, and where your data legally resides.

See also Latency, Edge

Rendering

Frontend

Turning content into pixels.

The browser converting HTML, CSS and JavaScript into a visible page. Server-side rendering does the first pass on the server so content exists in the HTML immediately rather than after scripts run.

See also HTML, DOM, Payload

REST

Backend

An API style organised around things.

Endpoints named after resources (/users, /orders) with HTTP verbs saying what to do to them. Highly cacheable and easy to inspect. A rich screen may need several calls.

See also GraphQL, RPC, Endpoint

Retry

Infrastructure

Trying again after a failure.

Reasonable for 5xx errors and network failures, pointless for 4xx. Must be paired with increasing delays and with idempotency, or it turns a lost response into a duplicate action.

See also Idempotency, Exponential backoff, Status code

Rollback

Infrastructure

Putting the previous version back.

The cheapest available response to a bad deploy and the correct first move in most incidents. Restores your code, not your data: deleted rows and sent emails do not come back.

See also Deploy, Migration, Incident

Round trip

Frontend

One journey there and back across the network.

The unit that actually determines perceived speed. Eight sequential round trips is slow no matter how fast the connection, which is why chattiness matters more than bandwidth.

See also Latency, DNS

RPC

Backend

Calling a named function on another machine.

An API style where you invoke an action directly rather than modelling resources. With shared types, a contract break becomes a build error, which is why it suits an app talking to its own backend.

See also Server function, REST, API

Scheduled job

Infrastructure

Work that runs because of the time, not a user.

A job triggered on a schedule. Fails in four classic ways: timezones, overlapping runs, missed runs, and growing workloads. Alert on the absence of success, not on failure.

See also Cron, Background job, UTC

Schema

Data & Databases

The declared shape of your data.

Which tables exist, which columns they have, and what is allowed in them. Changing it is a migration. In schemaless databases the schema still exists, just in your code instead of the database.

See also Migration, Table, NoSQL

Search params

Frontend

The part of a URL after the question mark.

Key-value pairs carrying page state: filters, queries, sorting. Putting state here makes it shareable, survivable across refreshes, and correct with the back button. Validating it means a hand-edited URL degrades instead of crashing.

See also State, Validation

Secret

Backend

Any value that grants access.

A database password, an API key, a signing key. Never in code, never in a client bundle. If one leaks, revoke it first. Deleting the line comes second, and git history keeps it regardless.

See also Environment variable, Key rotation

Server

Backend

A program that is open for business.

A running program listening for requests and answering them. Not a piece of hardware: one machine can run several, and it stops being a server the moment the program exits. Your laptop runs one every time you start a dev command.

See also Client, Port, Process

Server function

Backend

A function you call from the client that runs on the server.

Written like a normal function, but the build replaces the body with a network call in the client bundle and the real implementation only ever exists on the server. You get a typed contract for free and the server code never ships to the browser.

See also RPC, Validation, Secret

Server state

Frontend

Data fetched from an API, held in the UI.

Not really your application’s state, but a cache of somebody else’s, which goes stale the moment anyone else changes it. Treating it as local state is what produces "I updated it but the list still shows the old value".

See also State, Cache

Serverless

Infrastructure

You ship a function; something else runs it.

The platform decides when to run your code, how many copies to run, and when to discard them. Costs nothing while idle, scales without thought, and gives you no persistent memory between requests.

See also Cold start, Stateless, Container

Session

Backend

The server-side record that you are logged in.

A stored record the server looks up on each request using an id from a cookie. Slower than a signed token because of the lookup, but logging out is instant and reliable.

See also Cookie, JWT, Authentication

Skeleton

Frontend

A grey outline shown while content loads.

A placeholder in the shape of the coming content. Tells the user what to expect and prevents the page jumping when data arrives, which a spinner does neither of.

See also Loading state, Empty state

SQL

Data & Databases

The language for asking relational databases questions.

The query language of relational databases. Also used loosely to mean the relational family itself (Postgres, MySQL, SQLite) as opposed to NoSQL.

See also Query, NoSQL, Table

State

Frontend

Data that can change.

The real question is never what the state is but where the authoritative copy lives: the server, the URL, component memory, or browser storage. Two copies of the same fact will eventually disagree.

See also Server state, Search params

Stateless

Backend

Each request starts from nothing.

The server remembers nothing about you between requests by default. Memory has to be added deliberately, which is exactly what cookies and sessions are for.

See also HTTP, Session, Serverless

Status code

Backend

A three-digit verdict on a request.

The first digit is what matters: 2xx worked, 3xx moved, 4xx you asked wrong, 5xx they broke. The 4 versus 5 distinction decides whether retrying can possibly help.

See also HTTP, Retry, Rate limit

Streaming

AI in the stack

Sending a response in pieces as it is produced.

Delivering output progressively instead of waiting for all of it. Does not make anything faster; makes waiting tolerable, which is usually the real problem. Applies to slow page data as much as to model output.

See also Latency, Rendering

Table

Data & Databases

A spreadsheet with a strict header.

Rows are things, columns are facts about them, and every row has the same columns with declared types. That strictness is what lets the database refuse bad data.

See also Primary key, Schema, SQL

Timeout

Infrastructure

A hard limit on how long something may take.

Enforced by browsers, proxies, and serverless platforms. Work that exceeds one is killed partway through, leaving whatever it was doing half-finished.

See also Background job, Retry

TLS

Frontend

The encryption behind the S in HTTPS.

Makes the connection private and tamper-proof. Without it, anything between the user and your server can read and modify the page. Costs an extra handshake on the first connection.

See also DNS, Latency

Token

Backend

A string that proves something about you.

A credential passed with requests to identify or authorise the holder. Anyone holding it can use it, which is why tokens are short-lived and kept out of reach of page scripts.

See also JWT, Session, OAuth

Token (model)

AI in the stack

The unit models read, write, and charge by.

Roughly three quarters of a word. Everything meters in tokens: cost, the context window, and how long a response takes to produce.

See also Context window, Prompt caching

Tool use

AI in the stack

Letting a model call functions you define.

Giving a model a set of actions it may take: search, fetch, create. Turns a text generator into something that affects the world, which makes what you grant far more important than how well it reasons.

See also Agent, Blast radius

Tracing

Infrastructure

Following one request across every system it touches.

A timed record of a single request as it moves between services. When four systems are involved and something is slow, a trace identifies the culprit in seconds instead of hours.

See also Logs, Metrics, Observability

Transaction

Data & Databases

All of these changes, or none of them.

A group of changes applied as one unit. Without it, "take money from A" can succeed while "give money to B" fails. Any operation touching two things at once needs one.

See also Durability, Integrity, Concurrency

Transactional email

Infrastructure

Mail sent because a user just did something.

Password resets, receipts, confirmations: expected within seconds by a person who is waiting for them. Distinct from marketing mail, which goes out on your schedule and needs consent. Mixing the two costs you the reputation that gets the urgent one delivered.

See also Deliverability, Consent, Bounce

TTL

Infrastructure

How long a cached copy stays valid.

Time to live: the expiry on a cached item. Simple to reason about, at the price of accepting staleness up to that duration.

See also Cache, Invalidation

UTC

Infrastructure

The timezone servers actually run in.

Coordinated Universal Time, with no daylight saving. Servers use it so that timestamps are unambiguous. It is also why a job scheduled for "8am" may not run at 8am where your users are.

See also Cron, Scheduled job

Validation

Backend

Checking that input is what you expected.

In the browser it is a courtesy that makes things pleasant. On the server it is a control, because requests do not have to come from your form. You need both, ideally from one shared schema so they cannot disagree.

See also Server function, Search params, Client

Versioning

Backend

Running old and new API shapes side by side.

Offering /v1 and /v2 so existing callers keep working while new ones use the new shape. The same expand-then-contract idea as a safe schema migration, applied to an API.

See also Breaking change, Deprecation

Worker

Infrastructure

A process that pulls jobs off a queue and does them.

Separate from your web app, so you can deploy one without interrupting the other and add more workers to drain a backlog faster.

See also Queue, Background job