138 terms
Software GlossarySoftware Terms A–Z
Concepts that come up again and again in custom software, SaaS and integration projects: APIs, webhooks, databases, caching, authentication and authorization, containers and continuous delivery.
The entries are written so engineers and the people who buy software can speak the same language: what a concept is, when you need it and which trade-offs it brings.
Searches term names and alternate names; on category pages also the short definitions.
A
- Access TokenAn access token is a credential showing that a client may call a protected API with specific permissions for a limited time. In OAuth 2.0 it is issued by the authorization server and usually sent in an Authorization: Bearer header. Access tokens are kept short-lived to limit the damage if one is stolen; when one expires, a longer-lived refresh token lets the client obtain a new one without making the user sign in again.Professional · Software · Security & Infrastructure
- AI AgentAn AI agent is a software system that uses a language model as its decision-maker to pursue a goal: it plans steps, calls tools such as search, APIs, code execution or file operations, evaluates the results and chooses what to do next. Unlike a single question-and-answer exchange, it carries out a task over multiple steps while interacting with external systems. Reliable agents depend on permission limits, human approval and logging.Professional · AI Visibility · Software
- APIAn API (Application Programming Interface) is a defined set of rules that lets one piece of software use the functions or data of another. It acts as a contract: it specifies which operations can be called, what parameters they take, what responses and errors come back, and in which format. Because only the interface is shared, systems such as a web shop and a payment provider can work together without knowing each other's internals.Core · Software
- API EndpointAn API endpoint is a single access point that an API exposes for one specific operation. In web APIs an endpoint is usually the combination of a URL path and an HTTP method: GET /v1/orders/{id} reads an order, while DELETE /v1/orders/{id} removes it. Each endpoint defines the parameters and request body it accepts, how callers authenticate, and the responses and status codes it can return.Core · Software
- API KeyAn API key is a long random string that an application sends with its requests so an API can identify the calling project or account. The provider uses it to attribute usage, enforce quotas and decide which operations are allowed. A key usually represents an application rather than a person and often never expires on its own, so a leaked key is a serious risk: keep it secret, restrict it and rotate it regularly.Core · Software · Security & Infrastructure
- AuthenticationAuthentication is the process of verifying that a user, device or service really is who or what it claims to be before granting access to a system. It relies on evidence such as a password, a one-time code, a passkey or a biometric check. Authentication answers "who are you?"; deciding what that verified identity may do is the job of authorization.Core · Software · Security & Infrastructure
- AuthorizationAuthorization is the process of deciding what an authenticated user, application or service is allowed to do with a specific resource. It grants or denies access based on roles, permissions, ownership or contextual rules. Where authentication answers "who are you?", authorization answers "are you allowed to do this?" — and it always runs after identity has been established.Core · Software · Security & Infrastructure
B
- BackendThe backend is the server-side part of a website or application that users never see directly. It enforces business rules, stores and retrieves data in databases, authenticates users, talks to external services such as payment providers or email gateways, and delivers results to the frontend or to mobile apps, usually through an API.Core · Software
- BackupA backup is a copy of databases, files and configuration stored independently of the live system, so data can be restored after deletion, hardware failure, ransomware or a bad update. A backup plan is judged by how much data loss it accepts (the recovery point objective, RPO), how quickly service can be restored (the recovery time objective, RTO), and whether restores are actually tested on a regular schedule.Core · Software · Security & Infrastructure
- Blue-Green DeploymentBlue-green deployment is a release strategy that keeps two identical production environments, called blue and green, side by side. The new version is installed on the environment that is not serving traffic, verified, and then all traffic is switched to it in one step at the load balancer or routing layer. If something goes wrong, traffic is switched straight back, which keeps downtime and rollback time minimal.Advanced · Software
- Branch (Git)A branch in Git is a lightweight, movable pointer to a commit that advances as new commits are added. It opens an independent line of development: a feature or fix is built on its own branch and, once ready, merged back into the main branch. When both sides have changed the same lines differently, Git reports a merge conflict and a person decides which change wins.Core · Software
- Build ProcessA build process is the automated sequence of steps that turns source code and its dependencies into output that can run on a server or in a browser and be deployed. For web projects it typically covers installing dependencies, compiling languages such as TypeScript to JavaScript, bundling and minifying files, and pre-rendering static pages. The result is a versionable build artifact.Professional · Software
- Business Process AutomationBusiness process automation (BPA) is the use of software to carry out repetitive, rule-based business tasks with little or no human intervention. Automated workflows are started by triggers such as a new order or form submission and handle steps like data entry, approvals, notifications, document generation and moving data between systems. Connecting tools such as CRMs, ERPs and e-commerce platforms through APIs, known as system integration, is a core part of it.Core · Software
C
- CacheA cache is a storage layer that keeps temporary copies of frequently requested or expensive-to-produce data closer to where it is needed, so later requests can be served without going back to the original source, such as a database or origin server. On the web, caches exist in browsers, CDNs, servers and application code. Used well, caching cuts response times and server load; used carelessly, it serves stale data.Professional · Web Design · Software · Performance & Analytics
- Cache-ControlCache-Control is the HTTP header that tells caches such as browsers and CDNs whether a response may be stored, how long it stays fresh and what must happen once it goes stale. Its value is a comma-separated list of directives like max-age, s-maxage, no-cache, no-store, private, immutable and stale-while-revalidate. Requests can carry it too, but caching policy is defined mainly by the response header.Professional · Software · Performance & Analytics
- Canary DeploymentCanary deployment is a release strategy that exposes a new version to a small share of traffic or users first, compares metrics such as error rate and latency against the existing version, and increases the share step by step. If the metrics cross predefined thresholds, the rollout stops and the canary is withdrawn, so a faulty release is caught in a small group before it reaches everyone.Advanced · Software
- CI/CDCI/CD combines continuous integration, where every code change is automatically built and tested, with continuous delivery or continuous deployment, where changes that pass are kept ready to release or are released to production automatically. Together they form a pipeline whose goal is to ship small changes frequently, safely and repeatably, with automated tests acting as the gate between stages.Professional · Software
- Connection PoolA connection pool is a cache of open connections to a database or other service that an application reuses instead of opening a new connection for every request. Code borrows an idle connection from the pool, runs its work and returns it. Pooling removes the repeated cost of establishing connections and caps how many connections the application holds against the server at any one time.Advanced · Software · Performance & Analytics
- Context WindowA context window is the maximum number of tokens a language model can take into account in a single request. System instructions, conversation history, attached documents, retrieved sources and the model's own response all share this budget. Anything that does not fit in the window simply does not exist for the model during that request.Professional · AI Visibility · Software
- CORS (Cross-Origin Resource Sharing)CORS (Cross-Origin Resource Sharing) is the mechanism by which a server uses HTTP headers to declare which other origins may read its responses through JavaScript running in a browser. It relaxes the browser's default same-origin policy in a controlled way. CORS is enforced by browsers, not servers, so it offers no protection against requests sent to the server directly.Professional · Software · Security & Infrastructure
- CRM (Customer Relationship Management)CRM (customer relationship management) is both the practice of managing a company's interactions with prospects and customers and the software used to do it. A CRM system keeps contacts, conversations, quotes and sales opportunities in one place, so sales, marketing and support teams share the same customer history and managers can see how much business sits at each stage of the sales pipeline.Core · Software · CMS & E-commerce
- Cron JobA cron job is a command that the cron scheduler on Unix-like systems runs automatically at fixed times or intervals. Schedules are written in a crontab file using five fields: minute, hour, day of month, month and day of week, followed by the command. Nightly backups, report generation, cache warming and cleanup of old records are typical uses.Professional · Software
- CSR (Client-Side Rendering)CSR (client-side rendering) is a rendering approach in which page content is built by JavaScript in the user's browser rather than on the server. The server typically sends a near-empty HTML shell plus JavaScript bundles; the browser runs that code, fetches data from APIs and writes the interface into the DOM. It enables fluid, app-like transitions but makes first paint, and what search engines can see, depend on JavaScript.Professional · SEO · Web Design · Software
- Custom SoftwareCustom software is software designed and built for a specific organization's processes, users and integration needs, either from scratch or on top of existing components. Unlike off-the-shelf packages and subscription SaaS products sold identically to everyone, it is shaped around how the business actually works. The organization usually controls the source code and the roadmap, and in exchange carries responsibility for development, hosting and ongoing maintenance, directly or through a chosen team.Core · Software
D
- DatabaseA database is an organized collection of data stored so that it can be reliably saved, queried and updated. Applications work with it through a database management system (DBMS), which handles storage, queries, concurrent access and permissions. Databases broadly fall into relational (SQL) systems that keep data in related tables, such as PostgreSQL and MySQL, and NoSQL systems that use document, key-value, wide-column or graph models.Core · Software
- Database IndexA database index is an additional data structure, most often a B-tree, that keeps the values of one or more table columns sorted and searchable, with pointers back to the matching rows. Instead of scanning the whole table, a query can jump straight to the rows it needs. Indexes can speed up reads dramatically, but they take up storage and slow down writes, because every insert, update and delete must keep them current.Professional · Software · Performance & Analytics
- Database MigrationA database migration is a versioned script that applies one change to a database schema, such as creating a table, altering a column or adding an index, in a defined order. Migration files live in the code repository next to the application, and the database records which ones have already run. This lets development, test and production environments reach the same schema version in a repeatable, reviewable way.Professional · Software
- Database SchemaA database schema is the blueprint that defines how data in a database is structured: which tables exist, which columns and data types each table has, how tables relate through primary and foreign keys, and which constraints and indexes apply. In relational databases the schema is defined with SQL DDL statements such as CREATE TABLE and is enforced by the database on every write.Professional · Software
- Database TransactionA database transaction groups several reads and writes into a single, all-or-nothing unit of work. When the transaction is committed, all of its changes become permanent; if it is rolled back or fails, none of them are applied. Relational databases describe these guarantees with the ACID properties, while the isolation level determines how much concurrent transactions can see of each other's work.Professional · Software
- DependencyA dependency is a library, framework or tool, usually written by someone else, that a software project needs in order to build or run. Dependencies are installed through a package manager such as npm, pip or Composer; a manifest file declares the acceptable version ranges and a lockfile records the exact versions actually installed. Every dependency saves development time but also brings update, licensing and security responsibilities into the project.Professional · Software · Security & Infrastructure
- DeploymentDeployment is the process of installing a tested build of a new software version in the production environment and getting it running. It covers transferring files or container images to servers, applying database changes, starting the new version, checking its health and routing traffic to it. Deployment is the technical rollout; releasing a feature to users can be treated as a separate step.Core · Software
- Distributed TracingDistributed tracing is a technique for recording the end-to-end path of a single request as it passes through multiple services, databases and queues, together with the duration of each step. Each step is a span, and all spans of one request form a trace. A shared trace ID travels between services in standard headers such as W3C Trace Context, revealing where latency or errors originate.Advanced · Software
- Docker (Containers)Docker is a platform for packaging an application together with its dependencies into isolated, portable units called containers, and for running them. A Dockerfile describes how to build an image; a container is a running instance of that image. Because containers share the host operating system's kernel instead of booting a full guest OS, they are far lighter than virtual machines.Professional · Software
- Docker ComposeDocker Compose is a Docker tool for defining an application made of several containers in a single YAML file and starting, stopping and managing them with one command. The file describes each service, such as a web app, a database and a background worker, together with its image, environment variables, networks and persistent volumes. It is widely used for local development and single-host deployments.Professional · Software
- DOM (Document Object Model)The DOM (Document Object Model) is the tree structure a browser builds in memory after parsing an HTML document, representing elements, text and attributes as nested nodes. JavaScript reads and changes the page through this tree, and what you see on screen is drawn from the DOM's current state, not from the original HTML source. The DOM is defined as a living standard by WHATWG.Professional · Web Design · Software
E
- Edge FunctionAn edge function is a small, short-lived piece of serverless code that runs on a CDN's globally distributed servers, in the location closest to the user. It handles requests before they reach the origin server, for tasks such as redirects, header changes, access checks or light personalisation, with very low latency. The broader idea of moving computation towards users is called edge computing.Advanced · Software · Performance & Analytics
- EmbeddingAn embedding is a numerical vector that represents the meaning of a piece of text, an image or other data, produced by an embedding model. Content with similar meaning ends up with vectors that sit close together, so related items can be found even when they share no words. Embeddings power semantic search, retrieval-augmented generation (RAG) and recommendation systems.Professional · AI Visibility · Software
- End-to-End Testing (E2E)End-to-end testing (E2E) is automated testing that exercises an application the way a real user does, with every layer from the interface down to the database running together. A test runner opens a browser, navigates pages, clicks buttons, fills in forms and checks what finally appears on screen. It gives the most realistic evidence that components are wired together correctly, but E2E tests are the slowest and hardest to maintain.Professional · Software
- Environment VariableAn environment variable is a named value that the operating system passes to a running process, which the application reads instead of relying on constants written into its code. Settings that differ between deployments, such as a database URL, an API key, a mail server or the name of the current environment, are supplied this way. The same code then runs unchanged in development, staging and production, and secrets stay out of source code.Professional · Software · Security & Infrastructure
- ERP (Enterprise Resource Planning)ERP (enterprise resource planning) is a software system that runs a company's core operations, such as accounting, purchasing, inventory, manufacturing, sales orders and HR, as connected modules on a shared database. The idea is that each transaction is entered once and reflected everywhere it matters: posting a sales invoice reduces stock, updates the customer's balance and creates the accounting entries in the same step.Core · Software
- Event-Driven ArchitectureEvent-driven architecture is a software design approach in which services publish facts about state changes, such as “order created”, as events, and other services subscribe to those events and react on their own instead of being called directly. The publisher does not need to know who is listening, which loosens coupling between components but makes consistency and debugging harder.Advanced · Software
F
- Fine-TuningFine-tuning is the process of continuing to train an already pre-trained AI model on a smaller dataset prepared for a specific task, style or domain. It changes the model's weights, which separates it from prompting, where only the input changes, and from RAG, where documents are retrieved at answer time. Typical goals are a consistent output format, a narrow classification task or a house writing style.Professional · AI Visibility · Software
- Foreign KeyA foreign key is a constraint requiring that a column's value in one table actually exists as a primary key or unique value in another table. It prevents orphaned records, such as an order pointing to a customer that does not exist, a guarantee known as referential integrity. ON DELETE and ON UPDATE rules also define what happens to dependent rows when the referenced row is deleted or changed.Professional · Software
- FrontendThe frontend is the part of a website or application that users see and interact with in the browser. HTML defines its structure, CSS its appearance and JavaScript its behaviour. Frontend development covers turning designs into code, adapting layouts to different screens, accessibility, loading performance, and presenting data from the backend correctly in every state.Core · Web Design · Software
- Full StackFull stack refers to every layer of a web application taken together: the frontend users interact with, the backend that runs business logic, the database, and the infrastructure that deploys it. Full stack development means being able to build a feature end to end across all of those layers. The term describes both a technology stack and a developer role with that breadth.Core · Software
- Function CallingFunction calling, also called tool use, is a mechanism in which a language model responds not with prose but with a structured request, usually JSON, to call a function the application has defined, along with the arguments to pass. Each function is described by a name, a description and a JSON Schema for its parameters. The application, not the model, executes the call and returns the result to the model.Advanced · AI Visibility · Software
G
- GitGit is a free, open-source, distributed version control system that records changes to files as snapshots called commits. It was created in 2005 by Linus Torvalds and the Linux kernel community. Every clone carries the full project history, so a team can see who changed what, when and why, undo a bad change, and work on the same codebase in parallel without overwriting each other.Core · Software
- GraphQLGraphQL is a query language for APIs and a specification for the server-side runtime that executes those queries. A client sends a query, usually to a single endpoint, describing exactly the fields it needs, and receives a response in exactly that shape. All available data is described by a strongly typed schema. Originally developed at Facebook, GraphQL is now governed by the GraphQL Foundation, hosted by the Linux Foundation.Professional · Software
H
- Hash FunctionA hash function is a one-way function that maps data of any length to a fixed-length value called a digest. The same input always produces the same digest, while the smallest change to the input produces a completely different one. For cryptographic hash functions such as SHA-256, recovering the input from the digest or finding two inputs with the same digest is infeasible, which is why they are used for integrity checks and digital signatures.Professional · Software · Security & Infrastructure
- Headless CMSA headless CMS is a content management system that provides an editing interface and a content model but does not render the website. Instead, it delivers content as structured data through APIs such as REST or GraphQL to any front end: a website, a mobile app or another channel. The presentation layer, the “head”, is a separate project, often built with a framework like Next.js.Professional · Software · CMS & E-commerce
- Headless CommerceHeadless commerce is an ecommerce architecture in which the customer-facing storefront is decoupled from the commerce engine that manages products, pricing, inventory, carts and orders. The engine exposes its functions through APIs, so a website, a mobile app or an in-store screen can all draw on the same backend while each front end is built and released independently.Advanced · Software · CMS & E-commerce
- HMACHMAC (hash-based message authentication code) is a method for producing a short authentication tag by running a message and a secret key, known only to sender and receiver, through a hash function such as SHA-256. The receiver repeats the calculation and compares results; a match shows the message was not altered and was produced by someone holding the key. Webhook signatures, API request signing and JWT's HS256 algorithm all use HMAC.Advanced · Software · Security & Infrastructure
- HTTP CookieAn HTTP cookie is a small name-value pair that a web server asks the browser to store using the Set-Cookie response header. The browser keeps it and sends it back in the Cookie header on later requests that match its scope. Cookies keep users signed in, remember carts and language choices, and support analytics; attributes such as Domain, Path, Expires, Max-Age and Secure control where a cookie is sent and how long it lives.Core · Web Design · Software · Security & Infrastructure
- HTTP HeaderAn HTTP header is a name-value line of metadata, written as “Name: value”, that comes before the body of an HTTP request or response. Request headers tell the server which host is wanted, what formats the client accepts and who is calling; response headers describe the content type, caching rules, cookies and security policies. Header names are case-insensitive, and the standard fields are defined in RFC 9110 and related specifications.Core · SEO · Software · Security & Infrastructure
- HTTP Method (GET, POST…)An HTTP method is the verb at the start of an HTTP request that states what the client wants done to the target resource: GET retrieves it, POST submits data for processing, PUT replaces it, PATCH modifies part of it and DELETE removes it. RFC 9110 defines the core methods and whether each is safe, idempotent and cacheable, properties that browsers, proxies, caches and crawlers rely on when handling requests.Core · Software
- HTTP Request and ResponseThe HTTP request and response are the basic exchange of the web: a client such as a browser, app or crawler sends a request to a server, and the server answers with a response. A request carries a method, a target URL, headers and an optional body. A response carries a status code, headers and usually a body such as HTML, JSON or an image. The data a message actually carries is called its payload.Core · Web Design · Software
- HTTP Status CodeAn HTTP status code is the three-digit number a server returns with every response to report the outcome of a request. The first digit gives the class: 2xx success, 3xx redirection, 4xx client error and 5xx server error. Search engines use these codes to decide whether to index a page, whether to follow a redirect and how fast to crawl a site.Core · SEO · Software
- HTTP/2HTTP/2 is the second major version of the HTTP protocol, standardised in 2015. It splits requests and responses into binary frames so that many requests can travel concurrently over a single TCP connection (multiplexing), and it compresses headers with HPACK. Methods, status codes and headers keep the same meaning as in HTTP/1.1; only the way data is packaged and transported on the wire changes.Professional · Software · Performance & Analytics
- HTTP/3 and QUICHTTP/3 is the third major version of HTTP, and it runs on the QUIC transport protocol instead of TCP. QUIC is built on UDP, folds TLS 1.3 encryption into its handshake and delivers each stream reliably and independently, so a lost packet only delays the stream it belongs to. QUIC was standardised as RFC 9000 in 2021 and HTTP/3 as RFC 9114 in 2022.Advanced · Software · Performance & Analytics
- HydrationHydration is the process of making HTML that was generated on the server (SSR) or at build time (SSG) interactive in the browser with JavaScript. The framework re-runs the component code on the client, matches the result against the existing HTML and attaches event listeners, rather than redrawing the page from scratch. Frameworks such as React, Vue, Svelte and Angular use it for server-rendered pages.Advanced · Web Design · Software
I
- IdempotencyIdempotency is the property of an operation that produces the same effect on a system whether it is applied once or repeated several times. In distributed systems, where timeouts and network failures cause requests to be retried, it ensures a retry does not charge a card twice or create a duplicate record. GET, PUT and DELETE are idempotent by definition in HTTP; operations like POST are made safe to retry with techniques such as idempotency keys.Advanced · Software
- ISR (Incremental Static Regeneration)ISR (incremental static regeneration) is a Next.js technique that regenerates individual statically generated pages in the background, either after a set interval or when explicitly triggered, without rebuilding the whole site. Visitors get the cached page instantly, and the new version replaces it once it has been generated successfully. The Next.js documentation also refers to this process as revalidation.Advanced · Web Design · Software
J
- JavaScriptJavaScript is the programming language web browsers run natively, adding interactivity, dynamic content and application logic to pages. The language is standardised as ECMAScript (ECMA-262) by Ecma International's TC39 committee, which publishes a new edition every year. Runtimes such as Node.js also let developers use JavaScript for servers, command-line tools and build pipelines.Core · Web Design · Software
- JavaScript SEOJavaScript SEO is the part of technical SEO that makes sure websites whose content, links or meta data are generated by JavaScript can be crawled, rendered and indexed correctly by search engines. Its core topics are the rendering approach (server-side rendering, static generation or client-side rendering), link markup, routing and status codes, and how much critical signals depend on JavaScript.Advanced · SEO · Software
- Job QueueA job queue is a mechanism that records work the user does not need to wait for, such as sending emails, generating PDFs or resizing images, as background jobs and hands them to separate worker processes. The web request returns quickly while the job runs in the background. Failed jobs are retried according to defined rules, and each job's state can be tracked from enqueue to completion.Professional · Software
- JSONJSON (JavaScript Object Notation) is a plain-text data interchange format that represents data as key-value objects and ordered arrays, readable by people and easy for programs to parse. It grew out of JavaScript syntax but is language-independent: virtually every programming language can read and write it. JSON is the dominant format for web APIs, webhooks and configuration files, and is standardised in RFC 8259 and ECMA-404.Core · Web Design · Software
- JWT (JSON Web Token)A JWT (JSON Web Token) is a compact, URL-safe format for passing claims between two parties, defined in RFC 7519. It consists of three dot-separated parts: header, payload and signature. In its common form a JWT is signed but not encrypted: anyone holding it can read the contents, while the signature proves the claims were not altered and were issued by the holder of the key.Professional · Software · Security & Infrastructure
K
L
- LatencyLatency is the time it takes for a request or data packet to travel from source to destination, or to make the round trip and return, usually measured in milliseconds. On the web it most often means round-trip time (RTT). Bandwidth is the maximum amount of data a connection can carry and throughput is what it actually carries; latency measures not how much data moves but how long the journey takes.Core · Software · Performance & Analytics
- LLM (Large Language Model)A large language model (LLM) is an AI model trained on very large collections of text to learn patterns in language, which then generates text by predicting it one token at a time. LLMs power assistants such as ChatGPT, Claude and Gemini and are used to answer questions, summarize, translate and write code.Core · AI Visibility · Software
- Load BalancerA load balancer is a network component that spreads incoming traffic across several servers running the same service and automatically stops sending traffic to servers that fail health checks. Clients connect to a single address, and the load balancer decides which backend handles each connection or request. It can work at layer 4 (TCP/UDP connections) or layer 7 (HTTP requests, routed by their content), adding capacity and keeping one server's failure from becoming an outage.Professional · Software · Performance & Analytics · Security & Infrastructure
- LocaleA locale is an identifier that defines the language and regional conventions software uses for a user. On the web it is usually expressed as a BCP 47 language tag such as en-US or tr-TR. The locale determines the interface language as well as how dates, times, numbers and currencies are formatted, how text is sorted and how upper- and lowercase conversions work.Professional · SEO · Web Design · Software
- LoggingLogging is the practice of recording events that occur while an application or server runs, each with a timestamp, a severity level and contextual details. Logs are used for debugging, investigating security incidents and keeping an audit trail. Good logs are structured so machines can parse them, and they never contain secrets such as passwords or tokens, or more personal data than the purpose requires.Core · Software · Security & Infrastructure
- Low-Code and No-CodeLow-code and no-code are platform approaches that let people build applications with visual editors, drag-and-drop interfaces and prebuilt components instead of writing every line of code. No-code tools are fully visual and aimed at non-technical users; low-code platforms are visual first but let developers add custom code where needed. Both work well for forms, internal tools, approval workflows and simple data apps.Core · Software
M
- Machine LearningMachine learning is the branch of artificial intelligence in which computers learn patterns from example data, rather than following explicitly written rules, in order to make predictions or decisions. A model adjusts its parameters on training data and is expected to generalise to data it has never seen. Spam filters, recommendation systems, demand forecasting, fraud detection and large language models are all applications of machine learning.Core · AI Visibility · Software
- Message QueueA message queue is an intermediary that stores messages sent by one application (the producer) until another application (the consumer) is ready to process them. The two sides do not need to run at the same time or call each other directly, and traffic spikes accumulate in the queue instead of overloading the consumer. RabbitMQ, Amazon SQS and Redis-based queues are common message brokers that provide this model.Professional · Software
- MicroservicesMicroservices is an architectural style in which an application is built as a set of small services, each responsible for one business capability, owning its own data and deployable independently. Services communicate over the network through APIs or messages. The style enables independent scaling and team autonomy, at the price of distributed-systems complexity: network failures, data consistency and much heavier operations.Advanced · Software
- Model Context Protocol (MCP)The Model Context Protocol (MCP) is an open protocol that standardises how AI applications connect to external data sources, tools and workflows. Anthropic open-sourced it in November 2024. Its architecture has a host (the AI application), one client per connected server, and servers that expose tools, resources and prompts. Messages between clients and servers use the JSON-RPC 2.0 format.Advanced · AI Visibility · Software
- Monolithic ArchitectureMonolithic architecture is a software design in which all of an application's functionality lives in one codebase and is built and deployed as a single unit. Modules such as catalogue, orders and billing run in the same process, call each other directly and usually share one database. When the internal module boundaries are strictly enforced, the result is called a modular monolith.Professional · Software
- MVP (Minimum Viable Product)A minimum viable product (MVP) is the smallest working version of a product that lets a team test its riskiest assumption with real users. Its goal is not a finished product but validated learning with the least effort: do people actually have this problem, and will they spend time or money on this solution? The idea was popularised by Eric Ries's Lean Startup method.Core · Software
- MySQLMySQL is a relational database management system first released in the mid-1990s by the Swedish company MySQL AB and now owned and developed by Oracle. The Community Edition is open source under GPLv2, while enterprise editions and OEM use are available under commercial licences. Its default storage engine, InnoDB, supports transactions, row-level locking and foreign keys, and MySQL is the standard database behind WordPress and much shared hosting.Professional · Software
N
- Next.jsNext.js is an open-source React framework developed by Vercel for building full-stack web applications. It adds what React leaves open: file-system routing, Server Components, rendering at build time or request time, data caching, and image and font optimization, with bundlers and compilers configured for you. Because one app can mix prerendered static pages with pages rendered on the server for each request, it is widely used for both marketing sites and complex web apps.Professional · Web Design · Software
- NginxNginx (pronounced “engine-x”) is an open-source web server originally written by Igor Sysoev that also works as a reverse proxy, load balancer, content cache and TCP/UDP proxy. Its event-driven architecture handles large numbers of concurrent connections with little memory, which is why it is widely used to serve static files, terminate HTTPS and sit in front of application servers.Professional · Software · Security & Infrastructure
- NonceA nonce (“number used once”) is a unique, usually random value generated for a single use in a cryptographic operation or protocol message. Nonces stop recorded messages from being accepted a second time (replay protection), keep encryptions under the same key distinct from one another, and, in Content Security Policy, allow only approved inline scripts to run.Advanced · Software · Security & Infrastructure
- NoSQLNoSQL is an umbrella term for databases that store data in models other than relational tables, such as documents, key-value pairs, wide columns or graphs. They are usually designed around the queries an application will run and often spread data across many servers. In return they accept different trade-offs from relational systems, typically around joins, enforced schemas and how quickly every copy of the data becomes consistent.Professional · Software
O
- OAuthOAuth (in practice, OAuth 2.0) is an authorization framework, defined in RFC 6749, that lets an application access resources on another service on a user's behalf without ever learning the user's password. Instead, the application receives a scoped, time-limited access token. OAuth on its own is not an authentication protocol; signing users in is added on top by OpenID Connect.Professional · Software · Security & Infrastructure
- ObservabilityObservability is the ability to understand what is happening inside a system from the telemetry it emits, mainly logs, metrics and traces, including questions nobody anticipated in advance. Monitoring watches known failure modes with thresholds and alerts; observability aims to answer new questions such as “why is this request slow?” from existing data, without writing and shipping new code first.Professional · Software
- Open SourceOpen source software is software released under a licence that lets anyone inspect, use, modify and redistribute its source code. What makes it open source is not that the code is visible online, but that the licence explicitly grants those rights. Licences that meet the Open Source Initiative's Open Source Definition qualify; MIT, Apache 2.0 and the GPL are the best known. Linux, PostgreSQL and React are open source projects.Core · Software
- OpenID Connect (OIDC)OpenID Connect (OIDC) is an identity layer built on top of OAuth 2.0. Where OAuth grants an application access to resources on a user's behalf, OIDC also tells the application who the user is and how they authenticated, by issuing an ID token: a signed JWT addressed to the client. Most “Sign in with…” buttons and modern single sign-on run on OIDC, which is published by the OpenID Foundation.Advanced · Software · Security & Infrastructure
- ORM (Object-Relational Mapping)An ORM (object-relational mapping) is a software layer that maps classes and objects in application code to tables and rows in a relational database. Developers read and write data using their programming language's own constructs, and the ORM translates those operations into SQL. Hibernate, Entity Framework Core, Django ORM, SQLAlchemy and Prisma are common examples. ORMs speed up development, but unmonitored queries can cause problems such as the N+1 query pattern.Professional · Software
P
- PaaS (Platform as a Service)PaaS (Platform as a Service) is a cloud service model in which developers deploy and run their applications without managing servers, operating systems or networks. The provider runs the runtime environment, scaling, patching and often supporting services such as managed databases, while the customer controls the application and its configuration. PaaS sits between IaaS, which rents raw infrastructure such as virtual machines, and SaaS, which delivers finished software.Professional · Software
- PostgreSQLPostgreSQL is an open-source relational database management system that grew out of the POSTGRES project at UC Berkeley in the 1980s. It is known for broad SQL standard compliance, ACID transactions, MVCC-based concurrency, rich data types such as JSONB and arrays, and an extension system. No single company owns it: the PostgreSQL Global Development Group develops it and releases it under the permissive PostgreSQL License, similar to BSD or MIT.Professional · Software
- Primary KeyA primary key is the column or set of columns that uniquely identifies each row in a relational table. Its values may not be NULL, may not repeat, and a table can have at most one primary key. The database automatically creates a unique index for it, and other tables refer to a row through this value using foreign keys, which is why primary keys should be chosen to stay stable.Core · Software
- Pull RequestA pull request (PR) is a request to merge the changes on one branch into another, typically the main branch, that gives the team a place to review and discuss them first. The PR shows the line-by-line diff, the results of automated checks and reviewers' comments together, and the change is merged once the required approvals are in. GitHub and Bitbucket call it a pull request; GitLab calls it a merge request.Core · Software
Q
R
- RAG (Retrieval-Augmented Generation)Retrieval-augmented generation (RAG) is a technique in which a language model first retrieves relevant content from an external source, such as a search index, a document store or the web, and then bases its answer on that content. It keeps answers current and tied to sources, and it underpins most AI search experiences that show citations.Professional · AI Visibility · Software
- Rate LimitingRate limiting caps how many requests a client may make within a time window, for example 60 requests per minute per IP address. When the limit is exceeded, the server rejects further requests, usually with a 429 Too Many Requests status and a Retry-After header saying how long to wait. It protects services against brute-force attempts and abuse, and stops any single client from degrading the system for everyone else.Professional · Software · Security & Infrastructure
- ReactReact is an open-source JavaScript library for building user interfaces out of reusable components. Each component is a function that describes what should appear on screen for a given state and set of inputs (props); when state changes, React updates the affected parts of the page itself. Originally developed at Meta and open-sourced in 2013, React is now owned by the React Foundation, hosted by the Linux Foundation.Professional · Web Design · Software
- React Server ComponentsReact Server Components (RSC) are React components that run only on the server or at build time and whose code is never sent to the browser. They can query a database or API directly, await data asynchronously and pass their output to the client in a special serialised format. Parts that need state, event handlers or browser APIs are written as client components, marked with the 'use client' directive, and both kinds work together in one component tree.Advanced · Web Design · Software
- RedisRedis is an in-memory data store that keeps its dataset in RAM and stores not just strings but data structures such as lists, hashes, sets, sorted sets and streams as values. Because reads and writes usually complete in well under a millisecond, it is widely used as a cache, session store, rate-limiting counter and job queue. It can persist data to disk through point-in-time snapshots (RDB), an append-only command log (AOF), or both.Professional · Software · Performance & Analytics
- Relational DatabaseA relational database stores data in tables made of rows and columns and links those tables through keys. It is based on the relational model that Edgar F. Codd described in 1970: data is queried with SQL and kept consistent by constraints and transactions. PostgreSQL, MySQL, Microsoft SQL Server and SQLite are widely used examples, ranging from large client-server systems to SQLite's single-file embedded engine.Core · Software
- RepositoryA repository (repo) is the store a version control system manages for a project: the files plus the complete history of every change made to them. In Git, the repository itself is the hidden .git directory inside the project folder, which holds all commits, branches and tags. The same repository typically exists both locally on a developer's machine and remotely on a host such as GitHub or GitLab.Core · Software
- REST APIA REST API is a web API designed around the principles of REST (Representational State Transfer), an architectural style defined by Roy Fielding. Data is modeled as resources identified by URLs and manipulated with standard HTTP methods such as GET, POST, PUT, PATCH and DELETE. Each request is self-contained, the server keeps no client session state between requests, and outcomes are reported with HTTP status codes, usually with JSON payloads.Professional · Software
- Reverse ProxyA reverse proxy is a server that accepts requests from clients, forwards them to one or more application servers behind it and returns their responses to the client. Clients only ever talk to the proxy and never see the servers behind it. TLS termination, load balancing, caching, compression and security filtering usually happen at this layer; Nginx, HAProxy and Caddy are common examples.Professional · Software · Security & Infrastructure
- RollbackA rollback is the act of returning a system to its last known good version after a release causes errors, performance regressions or unexpected behaviour. Rolling back application code is usually quick if the previous build still exists, but database schema changes and data written by the new version do not revert on their own. A rollback is therefore a recovery path that must be designed before the release.Professional · Software
S
- SaaS (Software as a Service)SaaS (Software as a Service) is a delivery model in which software runs on the provider's infrastructure and customers access it over the internet, usually through a subscription. The provider is responsible for hosting, updates, backups and security, and a single application instance typically serves many customers at once. CRMs, accounting tools, email suites and project management apps are common examples.Core · Software
- ScalabilityScalability is a system's ability to handle growing numbers of users, requests or data while keeping response times acceptable and costs roughly proportional to load. Vertical scaling adds CPU and memory to an existing server; horizontal scaling adds more servers. The closely related goal of high availability is keeping the service running when an individual component fails.Professional · Software · Performance & Analytics
- SDK (Software Development Kit)An SDK (software development kit) is a bundle of tools that makes it easier to build software for a specific platform, service or device. It typically contains client libraries, API wrappers, documentation and sample code, and sometimes compilers, emulators or command-line tools. A payment provider's SDK, for example, turns raw HTTP requests into ready-made functions with authentication and error handling built in.Core · Software
- Secrets ManagementSecrets management is the practice of storing sensitive values such as passwords, API keys, database credentials, encryption keys and tokens securely, delivering them only to the systems that need them, rotating them regularly and auditing who accessed them. Its first rule is that secrets never appear in plain text in source code, Git repositories or log files.Advanced · Software · Security & Infrastructure
- Server-Sent Events (SSE)Server-Sent Events (SSE) is a web standard that lets a server push a continuous stream of events to the browser over a single, long-lived HTTP response. The response uses the text/event-stream content type and is consumed in the browser through the EventSource interface. Communication is one-way, from server to client; if the connection drops, the browser reconnects automatically and can report the last event ID it received.Advanced · Software
- ServerlessServerless is a cloud execution model in which the provider runs application code without the developer provisioning, patching or sizing any servers. Code is typically written as short-lived functions triggered by events such as HTTP requests, queue messages or schedules. The platform scales instances automatically with demand, and billing is based on requests and execution time rather than on servers kept running.Professional · Software
- Session (Web)A web session is the mechanism that ties a user's successive requests together on top of stateless HTTP. In the classic design the server generates an unguessable session ID when the user signs in, keeps the associated data on its side and hands the ID to the browser in a cookie, which the browser sends back with every later request. The alternative keeps the state in a signed token held by the client.Core · Software · Security & Infrastructure
- Software DevelopmentSoftware development is the process of turning a need into working, maintainable software. Beyond writing code, it covers requirements analysis, design, testing, release and the maintenance and improvement that continue after launch. Teams organize these activities either sequentially, as in the waterfall model, or in short iterative cycles, as in Agile methods such as Scrum and Kanban, with analysts, designers, developers, testers and operations engineers working together.Core · Software
- Software FrameworkA software framework is reusable infrastructure that provides an application's skeleton, control flow and conventions, while developers plug their own code into defined extension points. Your code calls a library; a framework calls your code. This principle is known as inversion of control. Laravel, Django, Spring and Next.js are widely used examples.Core · Web Design · Software
- SPA (Single-Page Application)A SPA (single-page application) is a web app model that loads one HTML document into the browser and handles every later page change by rewriting that document's content with JavaScript instead of requesting a new one. Data usually comes from APIs, and the address bar is updated through the History API. Its counterpart is the multi-page application (MPA), which fetches a fresh HTML document from the server on every navigation.Professional · SEO · Web Design · Software
- SQLSQL (Structured Query Language) is the standard declarative language for defining, querying and changing data in relational databases. A database query written in SQL describes which data you want, and the database decides how to retrieve it. PostgreSQL, MySQL, SQL Server and SQLite all build on the same ISO standard, but each speaks its own dialect with differences in syntax and functions.Core · Software
- SSG (Static Site Generation)SSG (static site generation) means producing a website's HTML files once, at build time, before any visitor requests them. The resulting HTML, CSS and JavaScript files are served as-is from any web server or CDN, with no database queries or rendering at request time. Tools that perform this step are called static site generators.Professional · Web Design · Software
- SSR (Server-Side Rendering)SSR (server-side rendering) means generating a web page's HTML on the server for each request and sending it to the browser with its content already in place. The browser can show text and links before any JavaScript runs, and search engines and other crawlers find the content directly in the HTML response. In modern frameworks SSR is usually paired with hydration, which makes the page interactive.Professional · SEO · Web Design · Software
- Staging EnvironmentA staging environment is the last stop before production: a setup that mirrors the live environment as closely as possible in infrastructure, configuration and data structure, where a release is tried one final time. Problems invisible on a developer's machine, such as version mismatches, missing environment variables or failing database migrations, surface here. Staging is only as useful as its resemblance to production, and any real personal data it holds needs the same protection.Professional · Software
T
- Technical DebtTechnical debt is the accumulated cost of shortcuts and expedient design choices in software: work that saved time when it was done but makes every later change slower and riskier. The term comes from Ward Cunningham's financial metaphor, in which the principal is the effort needed to fix the underlying problem and the interest is the extra effort paid on every change until it is fixed. Deliberate debt can be a useful tool; unnoticed debt eventually stalls a project.Professional · Software
- TypeScriptTypeScript is an open-source programming language developed by Microsoft that adds a static type system to JavaScript. Its syntax is a superset of JavaScript; type annotations are removed during compilation or type stripping, so what runs in the browser or on the server is plain JavaScript. The aim is to catch a class of errors before code runs and to enable reliable autocompletion and refactoring in large codebases.Professional · Web Design · Software
U
- UI ComponentA UI component is a self-contained, reusable building block of an interface, such as a button, form field, card or menu, that bundles its markup, styling, behaviour and accessibility rules into one unit. It exposes a small interface of parameters (props), hides its internals and behaves the same wherever it is used. Components exist both in design files and in code written with frameworks like React.Core · Web Design · Software
- Unit TestA unit test is an automated test that runs the smallest testable piece of software, usually a single function, method or class, in isolation and checks that a given input produces the expected result. Because unit tests avoid real databases, networks and file systems, they finish in milliseconds, so hundreds of them can run on every change and catch a regression at the moment it is introduced.Professional · Software
V
- Vector DatabaseA vector database is a data management system designed to store high-dimensional vectors, such as embeddings, together with their source text and metadata, and to run fast similarity queries over them. On top of approximate nearest neighbor indexes it provides persistence, updates, filtering, access control and scaling. It can be a standalone product or an extension of an existing database, such as pgvector for PostgreSQL.Professional · AI Visibility · Software
- Vector SearchVector search is a search method that finds, among records stored as numerical vectors, the ones closest to a query vector according to a chosen distance metric. The records are usually embeddings of text, images or products. Because comparing the query with every vector is slow at scale, large systems use approximate nearest neighbor (ANN) indexes such as HNSW or IVF, which give up a little accuracy for a large gain in speed.Professional · AI Visibility · Software
- VPS (Virtual Private Server)A VPS (Virtual Private Server) is a virtual machine created by partitioning a physical server with virtualisation software and rented to a customer with its own operating system, root access and allocated CPU, memory and disk. It offers far more control than shared hosting, but responsibility for operating-system updates, security hardening and backups moves to the customer along with that control.Core · Software · Security & Infrastructure
W
- WebhookA webhook is an HTTP request that one system sends automatically to a pre-registered URL when a specific event occurs, such as a payment succeeding, an order being placed or a form being submitted. Instead of the receiver repeatedly asking for updates (polling), the sender pushes the event data the moment it happens. Webhooks are widely used to trigger integrations and automated workflows between separate applications.Professional · Software
- WebSocketWebSocket is a protocol that provides a persistent, full-duplex channel between a client and a server over a single TCP connection. It starts as an HTTP request; once the server answers with 101 Switching Protocols, either side can send messages at any time. Standardized in RFC 6455 in 2011, it powers low-latency real-time features such as chat, live notifications, collaborative editing and multiplayer games.Professional · Software
#
- 200 OK200 OK is the HTTP status code a server returns when it has successfully handled a request. What the response body means depends on the method: for GET it is the requested resource itself, for POST the outcome of the action. To search engines a 200 means the content can move on to the next processing step, but it does not guarantee the page will be indexed.Core · SEO · Software
- 304 Not Modified304 Not Modified is the HTTP status code a server returns to a conditional GET or HEAD request when the client's stored copy is still valid. The client sends back the earlier ETag in If-None-Match or a date in If-Modified-Since; if nothing has changed, the server replies with a body-less 304 and the client reuses its cached copy.Professional · SEO · Software · Performance & Analytics
- 401 Unauthorized401 Unauthorized is the HTTP status code meaning a request was not applied because it lacks valid authentication credentials for the target resource. Despite the name, it is about authentication rather than authorization. The server must send a WWW-Authenticate header describing how to authenticate, and the client may retry with new or corrected credentials.Professional · Software · Security & Infrastructure
- 403 Forbidden403 Forbidden is the HTTP status code meaning the server understood the request but refuses to fulfil it. If credentials were sent, the server considers them insufficient, so repeating the request with the same credentials will not help. The refusal can also have nothing to do with identity, coming instead from file permissions, IP restrictions, firewall rules or bot protection.Professional · SEO · Software · Security & Infrastructure
- 404 Not Found404 Not Found is the HTTP status code meaning the server found no current content for the requested URL, or is not willing to disclose that it exists. It does not say whether the condition is temporary or permanent. Google does not index URLs that return 404 and removes previously indexed ones; 404 responses have no effect on a site's crawl rate.Core · SEO · Software
- 429 Too Many Requests429 Too Many Requests is the HTTP status code saying a client has sent too many requests in a given amount of time, in other words that it hit a rate limit. Defined in RFC 6585, the response may include a Retry-After header stating how long to wait. Google's crawlers treat a 429 as a sign that the server is overloaded, count it as a server error and slow down crawling.Professional · SEO · Software · Security & Infrastructure
- 500 Internal Server Error500 Internal Server Error is the generic HTTP error code meaning the server hit an unexpected condition that prevented it from fulfilling the request. It is used when no more specific 5xx code applies and says the problem lies on the server, not the client. When Google receives 500s it crawls the site more slowly, and URLs that keep failing are eventually dropped from the index.Core · SEO · Software
- 502 Bad Gateway502 Bad Gateway is the HTTP status code a server returns when, acting as a gateway or proxy, it receives an invalid response from the upstream server it contacted to fulfil the request. The error is usually generated by an intermediary such as Nginx, a CDN or a load balancer, while the real fault typically lies with an application server that is down, restarting or listening on the wrong address.Professional · Software · Security & Infrastructure
- 503 Service Unavailable503 Service Unavailable is the HTTP status code a server returns when it temporarily cannot handle a request because of overload or scheduled maintenance, with the condition expected to clear after some delay. The response may include a Retry-After header telling clients when to try again. For short maintenance windows it is the code that sends search engines the right message.Professional · SEO · Software
- 504 Gateway Timeout504 Gateway Timeout is the HTTP status code a server returns when, acting as a gateway or proxy, it does not receive a timely response from the upstream server it needs to complete the request. The connection may well have been established; the problem is that no answer arrived before the proxy's timeout expired. Slow database queries, long-running work and waits on external services are the usual causes.Professional · Software · Security & Infrastructure
Other categories
- SEO Glossary167 termsCanonical URL · Core Web Vitals · Crawling · Entity
- GEO Glossary63 termsAI Visibility · Entity · GEO · Structured Data
- AI Visibility Glossary45 termsAI Visibility · Entity · GEO · LLM
- Web Design Glossary97 termsCore Web Vitals · Responsive Design · Web Accessibility · Above the Fold
- Performance & Analytics Glossary71 termsCore Web Vitals · Abandoned Cart · Bounce Rate · Call to Action
- Security & Infrastructure Glossary82 termsAPI Key · Authentication · Authorization · Backup
- CMS & E-commerce Glossary27 termsAbandoned Cart · Checkout · CMS · CRM

