Technical Glossary
Technical concepts explained clearly — from APIs and architecture to AI and security.
Core Concepts
API
An Application Programming Interface is a set of rules that allows software components to communicate with each other. APIs define how different software systems interact, what data can be requested, and what responses are returned.
REST API
REST (Representational State Transfer) is an architectural style for designing APIs that uses standard HTTP methods (GET, POST, PUT, DELETE) to operate on resources identified by URLs. REST APIs are stateless, cacheable, and widely used for web services.
GraphQL
GraphQL is a query language for APIs that allows clients to request exactly the data they need, nothing more and nothing less. Unlike REST, which returns fixed data structures, GraphQL enables flexible, nested queries in a single request.
Business
SaaS
Software as a Service is a delivery model where software is hosted centrally and accessed via a web browser. SaaS applications are typically subscription-based, multi-tenant, and managed by the provider rather than installed on-premises.
MVP
A Minimum Viable Product is the simplest version of a product that can be released to validate a concept with real users. An MVP should be production-quality, not a prototype, but should include only the features necessary to test the core hypothesis.
Architecture
Microservices
An architectural style where an application is composed of small, independent services that communicate over a network. Each service is responsible for a specific business capability and can be developed, deployed, and scaled independently.
Modular Monolith
A monolithic application that is internally organized into well-defined, independent modules. This approach combines the operational simplicity of a monolith with the code-level separation of concerns found in microservices.
Event-Driven Architecture
A software architecture pattern where services communicate by producing and consuming events. When something happens, a service publishes an event, and other services react to it. This enables loose coupling and asynchronous processing.
API Gateway
A server that acts as an entry point for all API requests. An API gateway handles routing, authentication, rate limiting, request transformation, and response aggregation — simplifying client interactions with multiple backend services.
Scalability
The ability of a system to handle increasing amounts of work or to be enlarged to accommodate growth. Scalability can be vertical (more powerful hardware) or horizontal (more instances of the same component).
Operations
CI/CD
Continuous Integration and Continuous Delivery/Deployment. CI automatically integrates code changes from multiple contributors into a shared repository. CD automatically delivers or deploys those changes to production, enabling frequent and reliable releases.
DevOps
A set of practices that combines software development (Dev) and IT operations (Ops) to shorten the development lifecycle and improve delivery quality. DevOps emphasizes automation, monitoring, collaboration, and shared responsibility.
SRE
Site Reliability Engineering is a discipline that applies software engineering principles to operations problems. SRE teams build tools and systems to ensure reliability, automate incident response, and manage service-level objectives.
Observability
The ability to understand a system internal state from its external outputs. Observability includes logging, metrics, and distributed tracing — enabling teams to diagnose issues, understand performance, and make informed decisions.
High Availability
A characteristic of a system that aims to remain operational and accessible for a high percentage of time. High availability is achieved through redundancy, failover, health checks, and elimination of single points of failure.
Infrastructure
Kubernetes
An open-source container orchestration platform that automates the deployment, scaling, and management of containerized applications. Kubernetes provides service discovery, load balancing, self-healing, and rolling updates.
Docker
A platform that packages software into standardized units called containers, which include everything the software needs to run. Containers are lightweight, portable, and consistent across environments.
AI
RAG
Retrieval-Augmented Generation is a technique that enhances LLM responses by retrieving relevant information from a knowledge base before generating an answer. RAG grounds AI responses in specific, verifiable data.
LLM
A Large Language Model is an AI model trained on large amounts of text data to understand and generate human-like language. LLMs power chatbots, content generation, summarization, and other language-based applications.
Vector Database
A database optimized for storing and querying high-dimensional vectors (embeddings). Vector databases enable semantic search and are commonly used in AI applications for similarity matching and RAG systems.
Security
OAuth
An open standard for access delegation. OAuth allows users to grant third-party applications access to their data on another service without sharing their password. It is commonly used for "Sign in with Google" and similar flows.
OIDC
OpenID Connect is an identity layer built on top of OAuth 2.0. It enables clients to verify the identity of an end-user and obtain basic profile information. OIDC is widely used for single sign-on and authentication.
Authentication
The process of verifying the identity of a user, device, or system. Authentication answers the question "Who are you?" — typically through passwords, tokens, biometrics, or multi-factor methods.
Authorization
The process of determining what actions an authenticated user or system is allowed to perform. Authorization answers the question "What can you do?" — through roles, permissions, or policy-based access control.