HttpOnly
BackendA cookie flag that hides it from JavaScript.
Marks a cookie unreadable by page scripts, so a single injected script cannot steal a session. Tokens stored in local storage have no equivalent protection.
Glossary
Every term the courses use, defined in one line and then in a paragraph. Written to be read out of order.
Showing 5 of 5 matching “Token”
A cookie flag that hides it from JavaScript.
Marks a cookie unreadable by page scripts, so a single injected script cannot steal a session. Tokens stored in local storage have no equivalent protection.
A signed token that carries its own data.
A token containing information, cryptographically signed so it cannot be altered. Needs no server lookup, which scales well, but cannot be revoked before it expires, so it must be short-lived.
The server-side record that you are logged in.
A stored record the server looks up on each request using an id from a cookie. Slower than a signed token because of the lookup, but logging out is instant and reliable.
See also Cookie, JWT, Authentication
A string that proves something about you.
A credential passed with requests to identify or authorise the holder. Anyone holding it can use it, which is why tokens are short-lived and kept out of reach of page scripts.
The unit models read, write, and charge by.
Roughly three quarters of a word. Everything meters in tokens: cost, the context window, and how long a response takes to produce.
See also Context window, Prompt caching