Terminology
2185 terms, tools, patterns and metrics an architect is expected to use precisely. Each one gets a short explanation of what it is, and — where it matters — what it is commonly confused with. Search filters as you type; the column headers sort.
All areas2185
Architecture Fundamentals77
Distributed Systems107
Data Architecture110
Cloud Architecture89
Networking88
API & Integration Architecture82
Reliability & Resilience75
Observability70
Performance & Capacity Engineering72
Security Architecture81
Cost Architecture & FinOps66
Business Architecture67
Architecture Communication67
Enterprise Architecture66
Legacy Modernization66
AI-Era Architecture69
Software Architecture & Engineering71
Architecture Patterns71
Architecture Decision-Making63
The Architect's Meta-Skills61
Delivery & Release Engineering66
Platform Engineering & Developer Experience70
Testing & Quality Architecture66
Data Platform Architecture64
Streaming & Real-Time Data69
Data Governance & Semantics69
Frontend & Experience Architecture66
Edge, Mobile & IoT68
Regulatory & Data Protection Architecture65
Assurance, Audit & Model Risk64
7 terms shown.
| Term | Kind | Topic | What it is |
|---|---|---|---|
| Authorization Code Flow with PKCE PKCE | protocol | OAuth 2.0 & OIDC | The OAuth flow recommended for all client types, in which an authorisation code is exchanged for tokens using a proof key that binds the exchange to the original requester. |
| JSON Web Token JWT | protocol | Security Architecture | A signed, self-contained token carrying claims, which a service can validate locally without calling the issuer. |
| JWKS JSON Web Key Set | protocol | Tokens & JWTs | A published endpoint listing an issuer's current public keys, allowing resource servers to validate token signatures without a shared secret and to survive key rotation. |
| OAuth 2.0 | protocol | Security Architecture | An authorisation framework that lets an application obtain scoped, delegated access to a resource without handling the user's credentials. |
| OpenID Connect OIDC | protocol | Security Architecture | An identity layer over OAuth 2.0 that adds a signed ID token asserting who the user is and how they authenticated. |
| Token Exchange RFC 8693, Delegation Token | protocol | OAuth 2.0 & OIDC | Trading one token for another with different scope, audience or subject, so a service can call downstream on a user's behalf without reusing the original token. |
| Token Introspection | protocol | OAuth 2.0 & OIDC | Asking the authorisation server whether a token is currently valid, rather than validating it locally from its signature. |
Nothing on this page matches. Search the whole glossary.