Glossary

The words, without the shrug

Every term the courses use, defined in one line and then in a paragraph. Written to be read out of order.

Showing 7 of 124

Agent

AI in the stack

A model that can take actions, not just produce text.

A language model given a set of tools it may call, allowed to loop: decide, act, look at the result, decide again. The important design question is not accuracy but blast radius: what the worst wrong action can reach.

See also Tool use, Blast radius, Prompt injection

API

Backend

An agreed set of messages two systems exchange.

The contract between two pieces of software: which requests are valid, and what shape the answers take. Both sides can be rewritten freely as long as the contract holds, which is what makes independent teams possible.

See also Endpoint, Contract, REST

Architecture

Backend

Which pieces exist and how they talk.

Every diagram contains only three things: boxes that remember, boxes that do work, and arrows showing who depends on whom. The boxes that remember are the ones that constrain your options.

See also State, Stateless

Async

Infrastructure

Started now, finished later.

Work that does not block the thing that requested it. The caller gets an acknowledgement rather than a result, and finds out the outcome some other way.

See also Background job, Queue

At-least-once

Infrastructure

A delivery guarantee: your job may run more than once.

The normal promise made by queues. If a worker dies after finishing work but before recording completion, the job is handed to another worker and runs again. Jobs must therefore be safe to repeat.

See also Queue, Idempotency, Retry

Authentication

Backend

Establishing who someone is.

Proving identity: a password, a magic link, a sign-in with another provider. Distinct from authorization, which is about permission. Getting these confused is the source of a very common security hole.

See also Authorization, Session, OAuth

Authorization

Backend

Deciding whether someone may do a thing.

Checking permission for a specific action on a specific record. Must be checked on the server, per request, per record. Being logged in is not permission to view record 41 just because you asked for it.

See also Authentication, IDOR