Documentation

Glossary

Short definitions of terms used throughout these docs.

A

API key
A secret string that identifies your application when it calls the API. Send it in the Authorization header. Keep it out of client-side code.
Authentication
Verifying who a user or client is. Compare with authorization, which decides what they are allowed to do.

B

Bearer token
An access token sent in the Authorization: Bearer <token>
Batch request
Several operations grouped into one HTTP request to reduce round trips.

C

Cache
A stored copy of a response or computed result, kept so later requests can be served faster.
Cursor
An opaque token returned with a page of results. Pass it back to fetch the next page.

E

Endpoint
A specific URL path and HTTP method that performs one action, such as GET /users/{id}.
Environment variable
A named value set outside your code, commonly used for secrets and per-environment settings.

I

Idempotent
An operation that produces the same result however many times it runs. GET, PUT and DELETE are idempotent; POST generally is not.
Idempotency key
A unique value you send with a request so the server can safely retry it without duplicating the effect.

J

JSON
JavaScript Object Notation. The standard text format for request and response bodies in most APIs.
JWT
JSON Web Token. A signed token that carries claims about a user or client. Signed, not encrypted, so do not put secrets in it.

R

Rate limit
The maximum number of requests you may make in a time window. Exceeding it returns 429 Too Many Requests.
Redirect
A 3xx response telling the client to request a different URL, given in the Location header.
Region
A geographic location where your data and services run. Choose one close to your users for lower latency.

W

Webhook
An HTTP callback that the service sends to a URL you provide when an event occurs, instead of you polling for changes.
Webhook signature
An HMAC computed over the payload with your shared secret. Verify it before trusting the event.

X

Xsrf / CSRF
Cross-site request forgery. An attack that tricks a logged-in browser into sending an unwanted request. Mitigated with tokens and SameSite cookies.

No terms match your filter.