Authorization header. Keep it out of client-side code.Glossary
Short definitions of terms used throughout these docs.
A
- API key
- A secret string that identifies your application when it calls the API. Send it in the
- Authentication
- Verifying who a user or client is. Compare with authorization, which decides what they are allowed to do.
B
- Bearer token
- An access token sent in the
Authorization: Bearer <token> - Batch request
- Several operations grouped into one HTTP request to reduce round trips.
C
- Cache
- A stored copy of a response or computed result, kept so later requests can be served faster.
- Cursor
- An opaque token returned with a page of results. Pass it back to fetch the next page.
E
- Endpoint
- A specific URL path and HTTP method that performs one action, such as
GET /users/{id}. - Environment variable
- A named value set outside your code, commonly used for secrets and per-environment settings.
I
- Idempotent
- An operation that produces the same result however many times it runs.
GET,PUTandDELETEare idempotent;POSTgenerally is not. - Idempotency key
- A unique value you send with a request so the server can safely retry it without duplicating the effect.
J
- JSON
- JavaScript Object Notation. The standard text format for request and response bodies in most APIs.
- JWT
- JSON Web Token. A signed token that carries claims about a user or client. Signed, not encrypted, so do not put secrets in it.
R
- Rate limit
- The maximum number of requests you may make in a time window. Exceeding it returns
429 Too Many Requests. - Redirect
- A
3xxresponse telling the client to request a different URL, given in theLocationheader. - Region
- A geographic location where your data and services run. Choose one close to your users for lower latency.
W
- Webhook
- An HTTP callback that the service sends to a URL you provide when an event occurs, instead of you polling for changes.
- Webhook signature
- An HMAC computed over the payload with your shared secret. Verify it before trusting the event.
X
- Xsrf / CSRF
- Cross-site request forgery. An attack that tricks a logged-in browser into sending an unwanted request. Mitigated with tokens and
SameSitecookies.
No terms match your filter.