Backend
In short
The backend is the server side of an application: the code, databases and services that store data, apply business rules and answer the frontend's requests.
What is the backend?
The backend runs on servers, out of the user's sight. It receives requests from the frontend or from other programs, checks who is asking and whether they are allowed, reads and writes data in databases, applies the application's rules, and sends back a response, usually as JSON over HTTP.
A typical backend is made of a web framework such as Express, Django, Spring Boot or ASP.NET, the application's own code, one or more databases, and supporting pieces such as caches, message queues and background jobs. It exposes what it can do through an API, so a website, a mobile app and partner systems can all use the same logic.
Because the backend holds the data and enforces the rules, it is where security matters most: passwords are hashed there, permissions are checked there, and anything the frontend sends is validated there, since a request can always be forged. Backend work also covers scaling, logging and keeping the service available as traffic grows.
Key takeaways
- The backend is the server side: data, business rules and security.
- It answers requests from the frontend and other programs through an API.
- It usually combines application code, databases, caches and queues.
- Every check that matters, such as permissions and validation, belongs in the backend.
Example
// Node.js + Express: check who is asking, read the data, answer with JSON
import express from "express";
import { db } from "./db.js";
import { authenticate } from "./auth.js";
const app = express();
app.use(authenticate); // sets req.user from the session or token
app.get("/api/orders", async (req, res) => {
if (!req.user) return res.status(401).json({ error: "Sign in first" });
const orders = await db.orders.findMany({ where: { userId: req.user.id } });
res.json(orders);
});
app.listen(3000);Readers ask
Which languages are used for backend development?
Almost any general-purpose language: JavaScript or TypeScript with Node.js, Python, Java, C#, Go, PHP and Ruby are all common. The choice usually depends on the team, the libraries available and how fast the service needs to be.
Can an application have no backend?
A purely static site, or an app that keeps everything on the device, can work without a backend of its own. Many apps instead rely on managed services, such as a backend-as-a-service or serverless functions, so someone else runs the servers.
Often compared
See also
- FrontendWeb Development, p. 17The frontend is the part of an application that runs in front of the user, usually in the browser, drawing the interface and responding to clicks and typing.
- APIBackend & APIs, p. 2An API is a set of rules that lets one piece of software request data or actions from another in a predictable, documented way.
- REST APIBackend & APIs, p. 38A REST API is a web API that exposes data as resources identified by URLs and lets clients read or change them using standard HTTP methods.
- Web ServerBackend & APIs, p. 46A web server is software, or the machine running it, that accepts HTTP requests from browsers and other clients and responds with pages, files, or data.
- DatabaseDatabases, p. 6A database is an organized collection of data stored on a computer, managed by software that lets applications save, search, and update it efficiently.
- MiddlewareBackend & APIs, p. 30Middleware is software that sits between two layers of a system, most often code that runs between an incoming request and the final response in a web server.
- Node.jsBackend & APIs, p. 32Node.js is an open-source JavaScript runtime that runs JavaScript outside the browser, most often to build web servers, APIs, and command-line tools.
- ServerlessDevOps & Cloud, p. 47Serverless is a cloud model in which the provider runs your code on demand, manages all the servers, scales automatically, and bills only for actual use.
Spotted a mistake or something missing on this page?Suggest an edit