Glossary
Every term. Explained.
A comprehensive reference for every platform concept, component, and pattern used across EEv3.
- Capability
- A discrete function the platform can perform. EEv3 ships with capabilities spanning AI, storage, auth, billing, and more. Each capability is invoked through the /do endpoint.
- CDN Edge Node
- A point-of-presence in the global content delivery network. Edge nodes cache static assets and run edge compute functions for sub-50ms response times worldwide.
- Conductor
- The routing engine at the heart of EEv3. The conductor receives every /do request, resolves the target capability, applies middleware (auth, rate limiting, logging), and dispatches execution.
- /do
- The single API endpoint for all capability invocations. Every action on EEv3 is a POST to /do with a capability name and payload. The conductor handles routing, auth, and execution.
- Entity
- A company or project provisioned on EEv3. Each entity receives isolated infrastructure, a unique subdomain, and its own set of scoped tokens. Entities are the top-level unit of tenancy.
- Face
- A typed SDK module mapping a business domain. Faces like ee.auth, ee.billing, and ee.ai provide domain-specific methods that compile to /do calls under the hood.
- Fan-Out
- A messaging pattern where a single event is delivered to multiple consumers simultaneously. Used in webhook delivery, queue broadcasting, and streaming event distribution.
- Hydration
- The process of populating a newly provisioned entity with default configuration, seed data, and initial resources. Hydration runs automatically after provisioning.
- Idempotency Key
- A unique identifier attached to a /do request to ensure the operation is executed exactly once, even if the request is retried. Critical for payment and webhook operations.
- Middleware
- A processing layer that runs before or after capability execution. Built-in middleware handles authentication, rate limiting, logging, and request validation.
- Multi-Tenant
- An architecture where multiple entities share the same underlying infrastructure while maintaining strict data isolation. EEv3 uses row-level security and scoped credentials for isolation.
- Provisioner
- The system that creates new entities with full infrastructure. The provisioner allocates databases, configures DNS, generates tokens, and runs hydration in under 60 seconds.
- Rate Limiter
- A middleware component that enforces request quotas per entity, per face, or per capability. Rate limits are configurable and enforced at the conductor level.
- Sandbox
- An isolated environment for development and testing. Sandboxes mirror production capabilities but use separate data stores and relaxed rate limits.
- Scoped Token
- A fine-grained API key limited to specific faces, capabilities, or resources. Scoped tokens follow the principle of least privilege and can be rotated independently.
- Streaming
- Real-time event delivery over persistent connections. ee.streaming supports Server-Sent Events and WebSockets for live dashboards, notifications, and collaborative features.
- Sub-Processor
- A third-party service that processes data on behalf of EEv3. All sub-processors are listed in the Data Processing Agreement and undergo regular security reviews.
- Tenant
- An isolated unit within the multi-tenant architecture. Each tenant has its own data partition, configuration scope, and access policies. In EEv3, tenants map to entities.
- Webhook
- An HTTP callback triggered by a platform event. EEv3 webhooks support configurable retry policies, payload signing, and delivery monitoring through ee.webhook.
- Zero-Trust
- A security model where no request is trusted by default, regardless of origin. Every /do call is authenticated, authorized, and audited before execution.