Terminology
2205 terms, tools, patterns and metrics an architect is expected to use precisely. Each one gets a short explanation of what it is, and — where it matters — what it is commonly confused with. Search filters as you type; the column headers sort.
All areas2205
Architecture Fundamentals77
Distributed Systems107
Data Architecture110
Cloud Architecture94
Networking88
API & Integration Architecture82
Reliability & Resilience75
Observability70
Performance & Capacity Engineering72
Security Architecture86
Cost Architecture & FinOps71
Business Architecture67
Architecture Communication67
Enterprise Architecture66
Legacy Modernization71
AI-Era Architecture69
Software Architecture & Engineering71
Architecture Patterns71
Architecture Decision-Making63
The Architect's Meta-Skills61
Delivery & Release Engineering66
Platform Engineering & Developer Experience70
Testing & Quality Architecture66
Data Platform Architecture64
Streaming & Real-Time Data69
Data Governance & Semantics69
Frontend & Experience Architecture66
Edge, Mobile & IoT68
Regulatory & Data Protection Architecture65
Assurance, Audit & Model Risk64
5 terms shown.
| Term | Kind | Topic | What it is |
|---|---|---|---|
| JWKS JSON Web Key Set | protocol | Tokens & JWTs | A published endpoint listing an issuer's current public keys, allowing resource servers to validate token signatures without a shared secret and to survive key rotation. |
| Refresh Token | concept | Tokens & JWTs | A long-lived credential used solely to obtain new short-lived access tokens, so sessions can persist without long-lived access tokens circulating. |
| Revocation Window Token Lifetime as SLA, Local Validation Trade | concept | Tokens & JWTs | The period during which a revoked credential remains accepted, which for locally-validated tokens is exactly the token lifetime - the unavoidable price of removing the identity provider from the request path. |
| Token Audience Validation Audience Restriction, aud Claim | practice | Tokens & JWTs | Verifying that a signed token was issued for the service consuming it, without which a legitimately obtained low-privilege token is replayable against a high-privilege service. |
| Token Revocation Gap | concept | Tokens & JWTs | The window between deciding a token should no longer be valid and it actually ceasing to work, which for self-contained tokens is its remaining lifetime. |
Nothing on this page matches. Search the whole glossary.