PageSourceSearch

https://byob.studio/_app/immutable/chunks/DsnoSIqP.js

js byob.studio collected 2026-09-24 13:54:36 UTC 194,092 bytes, 1 lines download raw bytes

1const h=e=>e.map(([a,t,n,i])=>({slug:a,term:t,def:n,area:"ai-search-geo",related:i})),m=[...h([["answer-engine-optimization","Answer Engine Optimization (AEO)","Answer Engine Optimization is the practice of structuring pages so answer engines and AI assistants can extract, trust, and quote them: a direct definition up top, scannable steps, quotable facts, and FAQ or Article schema behind them.",["generative-engine-optimization","citation-readiness","answer-first-writing"]],["generative-engine-optimization","Generative Engine Optimization (GEO)","Generative Engine Optimization improves how often a brand or page is cited inside AI-generated answers. It combines classic SEO (crawlability, relevance) with quotability: clear facts, named entities, sources, and machine-readable structure.",["answer-engine-optimization","share-of-voice-ai","citation-share"]],["ai-overviews","AI Overviews","Google’s AI-generated summaries at the top of some results pages. They synthesize multiple sources and link to them, which can reduce clicks to publishers even when a page ranks well organically.",["zero-click-search","google-ai-mode","citation-share"]],["zero-click-search","Zero-Click Search","A search that ends without a click to any website, because the answer appears directly on the results page or inside an AI summary. Zero-click behavior pushes measurement beyond clicks toward mentions and citations.",["ai-overviews","featured-snippet","share-of-voice-ai"]],["citation-readiness","Citation Readiness","How easily an AI answer can find, extract, and cite a page: direct definitions, self-contained paragraphs, named entities, published dates, author bylines, sources, and clean semantic HTML with matching schema.",["answer-engine-optimization","quotable-sentence","fact-density"]],["citation-share","Citation Share","The share of AI-answer citations in a topic that point to your pages versus competitors. It is the GEO analogue of share of voice: who gets quoted when the model answers money queries.",["share-of-voice-ai","generative-engine-optimization","prompt-visibility-tracking"]],["share-of-voice-ai","Share of Voice (AI)","Your brand’s visibility across AI answers for a set of tracked prompts: how often you appear or are cited relative to competitors. Tracked by sampling the same prompts repeatedly over time.",["citation-share","prompt-visibility-tracking","organic-share-of-voice"]],["llms-txt","llms.txt","An experimental convention (a Markdown file at /llms.txt) that summarizes a site for language models. Adoption and crawler support are still thin, so it sits below core crawlability and content quality in priority.",["ai-crawler","robots-txt","machine-readable-content"]],["ai-crawler","AI Crawler","A bot that fetches web content to train models or ground live answers, distinct from search-index crawlers. Examples include GPTBot, ClaudeBot, PerplexityBot, and Common Crawl’s CCBot.",["gptbot","claudebot","perplexitybot"]],["gptbot","GPTBot","OpenAI’s crawler, used for training and retrieval. It respects robots.txt and can be disallowed site-wide or per-directory without affecting other crawlers.",["ai-crawler","oai-searchbot","ai-bot-blocking"]],["claudebot","ClaudeBot","Anthropic’s crawler that fetches pages to inform Claude’s answers. Like other AI crawlers it follows robots.txt, so blocking it is a deliberate distribution decision, not a default.",["ai-crawler","gptbot","ai-bot-blocking"]],["perplexitybot","PerplexityBot","The crawler behind Perplexity’s answer engine, fetching cited sources for its responses. Being fetchable by it is a precondition for being quoted in Perplexity answers.",["ai-crawler","citation-share","grounding-source"]],["oai-searchbot","OAI-SearchBot","OpenAI’s search-oriented crawler used for live retrieval in ChatGPT answers. It is controlled separately from GPTBot in robots.txt, so training and search-fetch policies can differ.",["gptbot","ai-crawler","grounding-source"]],["ccbot","CCBot (Common Crawl)","The crawler for Common Crawl, a nonprofit web archive widely used as LLM training data. Blocking it reduces the chance your content appears in future open training corpora.",["ai-crawler","gptbot","ai-bot-blocking"]],["google-extended","Google-Extended","A standalone robots.txt token that opts content out of Google’s AI training corpora without affecting Search indexing or ranking. It does not control AI Overviews grounding.",["robots-txt","ai-bot-blocking","ai-crawler"]],["ai-bot-blocking","AI Bot Blocking","Using robots.txt (or edge rules) to stop AI crawlers from fetching a site. The tradeoff is direct: blocked content cannot be quoted or cited by the assistants doing the blocking.",["robots-txt","google-extended","citation-share"]],["retrieval-augmented-generation","Retrieval-Augmented Generation (RAG)","A pattern where a model retrieves relevant documents first, then grounds its answer in them. Most AI search answers are RAG systems, which is why retrievable, chunkable pages get cited.",["chunk-retrieval","grounding","grounding-source"]],["chunk-retrieval","Chunk Retrieval","The step in RAG where a system pulls the most relevant passages (chunks) from its index to feed the model. Pages with self-contained, fact-dense sections produce chunks that survive this selection.",["chunking","retrieval-augmented-generation","passage-ranking"]],["chunking","Chunking","Splitting content into retrievable passages for embeddings and RAG. Clear headings, one idea per section, and definitions up front make chunks that rank and quote cleanly.",["chunk-retrieval","vector-embedding","passage-embedding"]],["vector-embedding","Vector Embedding","A numeric representation of text meaning used to match queries to passages by semantic similarity rather than exact keywords. Embeddings power chunk retrieval in AI search.",["cosine-similarity","semantic-similarity","chunking"]],["cosine-similarity","Cosine Similarity","A 0-to-1 measure of how alike two embeddings are, used to rank which passages answer a query. Higher similarity means the passage reads as more about the same thing as the question.",["vector-embedding","semantic-similarity","passage-ranking"]],["grounding","Grounding","Tying a model’s answer to retrieved sources instead of pure parametric memory. Grounded answers cite pages, which turns citation readiness into visible referral and brand presence.",["grounding-source","retrieval-augmented-generation","hallucination"]],["grounding-source","Grounding Source","A page an AI answer actually retrieved and based claims on. Becoming a grounding source requires being crawlable, topically relevant, and quotable at the passage level.",["grounding","citation-share","chunk-retrieval"]],["hallucination","Hallucination","When a model states something false with confidence, usually from parametric memory without grounding. Grounded, cited answers hallucinate less, which is why engines prefer quotable sources.",["grounding","fact-checking","grounding-source"]],["query-fan-out","Query Fan-Out","When an AI system expands one question into many sub-queries behind the scenes to gather sources. Broad, well-structured topic coverage wins fan-out because more sub-queries land on your pages.",["topical-authority","query-synthesis","conversational-search"]],["conversational-search","Conversational Search","Multi-turn search where follow-up questions inherit context from earlier ones. Pages that define entities clearly and cover adjacent subtopics get pulled into longer answer threads.",["query-fan-out","people-also-ask","search-generative-experience"]],["multimodal-search","Multimodal Search","Search that mixes text, images, and voice as inputs or outputs. Alt text, descriptive captions, transcripts, and structured data decide whether non-text content is retrievable.",["image-seo","alt-text","machine-readable-content"]],["prompt-visibility-tracking","Prompt Visibility Tracking","Repeatedly asking tracked prompts and recording whether and how a brand is mentioned or cited. The GEO equivalent of rank tracking, built for answers instead of ten blue links.",["share-of-voice-ai","rank-tracking","citation-share"]]]),{slug:"answer-first-writing",term:"Answer-First Writing",def:"Answer-first writing puts the direct answer in the first 40–
160 words, then expands with evidence and steps. It serves featured snippets, AI extraction, and impatient readers with the same structure.",area:"ai-search-geo",related:["answer-engine-optimization","quotable-sentence","key-takeaways-box"],example:'Open a pricing guide with "Freelancer invoices in the EU need your VAT ID, sequential numbering, and 14-day terms." Then explain each requirement below. The opener is quotable on its own.',wrong:"Burying the answer after 300 words of throat-clearing. Extraction systems quote what they can lift cleanly, usually the top of the page."},{slug:"quotable-sentence",term:"Quotable Sentence",def:"A self-contained factual sentence an engine or writer can lift verbatim: named subject, active verb, concrete object or number. Quotable sentences are the atomic unit of citation readiness.",area:"ai-search-geo",related:["answer-first-writing","fact-density","semantic-triple"],example:'"Pages with exact-match internal anchors earned roughly five times the search traffic of pages without them (Zyppy, 2026)." Subject, verb, number, source.',wrong:'Writing vague claims like "many experts agree quality matters." Nothing checkable means nothing quotable.'},{slug:"fact-density",term:"Fact Density",def:"The concentration of checkable claims per section: numbers, names, dates, criteria, steps. Fact-dense sections survive chunk retrieval and get cited; filler does not.",area:"ai-search-geo",related:["quotable-sentence","citation-readiness","extractability"],example:'A deployment guide that states limits, timings, and error codes per step will be quoted over one that says "deploying is fast and easy" three ways.'},{slug:"cited-framework",term:"CITED Framework",def:"A checklist for citable content: Claims stated plainly, Independent corroboration, Timeliness with dates, Expertise with bylines, and Data with sources. Each element removes one reason an engine might skip you.",area:"ai-search-geo",related:["citation-readiness","fact-checking","author-bio"],faqs:[["Is CITED a Google ranking factor?","No. It is a working checklist for making pages easy to trust and quote, not a documented signal."],["What is the fastest CITED win?","Dated bylines plus one sourced stat per section. Dates and sources remove the two most common reasons for being skipped."]]},{slug:"machine-readable-content",term:"Machine-Readable Content",def:"Content structured so parsers extract it reliably: semantic HTML, one H1, real lists and tables, descriptive link text, alt text, and schema that mirrors visible content.",area:"ai-search-geo",related:["schema-markup","semantic-html","extractability"]},{slug:"extractability",term:"Extractability",def:"How cleanly a parser can lift a page’s facts: headings that label sections, tables for comparisons, lists for steps, and no critical content locked in images or client-only widgets.",area:"ai-search-geo",related:["machine-readable-content","javascript-seo","chunking"]},{slug:"semantic-triple",term:"Semantic Triple",def:'A subject–verb–object fact ("BYOB deploys sites to the edge") that engines and readers cannot misread. Triples reduce ambiguity and make claims quotable across languages and models.',area:"ai-search-geo",related:["quotable-sentence","entity-salience","entity-optimization"]},{slug:"search-generative-experience",term:"Search Generative Experience (SGE)",def:"Google’s earlier name for generative search features, superseded by AI Overviews and AI Mode. Historical SGE studies still inform how zero-click and citation behavior is measured.",area:"ai-search-geo",related:["ai-overviews","google-ai-mode","zero-click-search"]},{slug:"google-ai-mode",term:"Google AI Mode",def:"Google’s conversational answer-first search mode, where multi-turn queries are resolved with grounded AI responses. Visibility here depends on citation readiness more than classic rank position.",area:"ai-search-geo",related:["ai-overviews","conversational-search","query-fan-out"]},{slug:"llm-serp",term:"LLM SERP",def:"The answer surface of an AI assistant: the set of claims, citations, and links a model returns for a prompt. Optimizing for the LLM SERP means optimizing passages and entities, not just positions.",area:"ai-search-geo",related:["prompt-visibility-tracking","citation-share","serp"]},{slug:"ai-visibility",term:"AI Visibility",def:"Whether and how prominently a brand appears inside AI answers: mentions, citations, and links across tracked prompts and assistants. The GEO headline metric alongside citation share.",area:"ai-search-geo",related:["share-of-voice-ai","ai-brand-mention","prompt-visibility-tracking"]},{slug:"ai-brand-mention",term:"AI Brand Mention",def:"An unlinked mention of a brand inside an AI-generated answer. Mentions build familiarity and often precede citations; tracking them separately from links avoids undercounting AI presence.",area:"ai-search-geo",related:["ai-visibility","unlinked-brand-mention","share-of-voice-ai"]},{slug:"query-synthesis",term:"Query Synthesis",def:"How AI systems compose an answer from multiple retrieved passages rather than one page. Synthesis rewards sites that own several quotable passages across a topic, not a single good page.",area:"ai-search-geo",related:["query-fan-out","chunk-retrieval","topical-authority"]},{slug:"structured-answer-block",term:"Structured Answer Block",def:"A compact on-page pattern for AI extraction: direct answer, 2–3 supporting facts, and a source link in one visually grouped unit. Repeat the pattern per question the page targets.",area:"ai-search-geo",related:["answer-first-writing","key-takeaways-box","faqpage-schema"]}],f=e=>e.map(([a,t,n,i])=>({slug:a,term:t,def:n,area:"technical-seo",related:i})),b=[...f([["technical-seo","Technical SEO","The crawling, indexing, rendering, and performance work that lets search engines reach, understand, and serve your pages. It covers directives, architecture, speed, and structured data rather than words on the page.",["crawling","indexing","core-web-vitals"]],["crawling","Crawling","How search-engine bots discover pages by following links, sitemaps, and directives. If a URL is never crawled, it cannot be indexed no matter how good its content is.",["crawl-budget","log-file-analysis","xml-sitemap"]],["crawl-budget","Crawl Budget","The number of pages a search engine will crawl on a site in a given period, driven by server capacity and demand signals. Large or slow sites must spend it on indexable, valuable URLs.",["crawling","crawl-rate-limit","url-parameter"]],["indexing","Indexing","Storing and organizing crawled pages so they can be retrieved for queries. Indexing is selective: crawled does not mean indexed, and indexed does not mean ranking.",["index-selection","index-bloat","crawl-render-index-pipeline"]],["robots-txt","Robots.txt","A plain-text file at the domain root telling compliant crawlers which paths they may fetch. It controls crawling, not indexing: blocked URLs can still be indexed by URL if linked.",["xml-sitemap","ai-bot-blocking","crawl-rate-limit"]],["xml-sitemap","XML Sitemap","A machine-readable list of canonical URLs worth crawling, optionally with last-modified dates. One file holds 50,000 URLs or 50 MB uncompressed; larger sites segment by template or locale.",["robots-txt","html-sitemap","sitemap-generator"]],["301-redirect","301 Redirect","A permanent redirect passing most ranking signals to the target URL. Use it for migrations, consolidation, and retired pages with a live equivalent.",["302-redirect","redirect-chain","canonical-tag"]],["302-redirect","302 Redirect","A temporary redirect that keeps ranking signals with the source URL. Correct for short-term moves (maintenance, tests) but a common cause of signal-splitting when left permanent.",["301-redirect","redirect-chain","redirect-loop"]],["redirect-chain","Redirect Chain","Two or more redirects in sequence before the final URL. Chains waste crawl budget, slow users, and dilute signals; audits should flatten them to a single hop.",["301-redirect","redirect-loop","crawl-budget"]],["core-web-vitals","Core Web Vitals","Google’s field-measured experience metrics: Largest Contentful Paint, Interaction to Next Paint, and Cumulative Layout Shift. Roughly half of origins pass all three, so the work remains relevant.",["largest-contentful-paint","interaction-to-next-paint","cumulative-layout-shift"]],["mobile-first-indexing","Mobile-First Indexing","Google primarily uses the mobile version of a page for indexing and ranking. Parity between mobile and desktop content, links, and metadata is therefore a baseline audit check.",["crawling","indexing","page-speed"]],["https","HTTPS","Encrypted HTTP via TLS, a lightweight ranking signal and a trust requirement. Mixed HTTP resources on HTTPS pages still split signals and trigger browser warnings.",["mixed-content","http-status-code","canonical-tag"]],["javascript-seo","JavaScript SEO","Making client-rendered pages discoverable: crawlable links, server or prerendered critical content, unblocked resources, and unique URLs per state. Rendering usually happens, but slow tails hurt time-sensitive pages.",["client-side-rendering","server-side-rendering","dynamic-rendering"]],["hreflang","Hreflang","Annotations declaring language and regional variants of a page so engines serve the right one per locale. Missing return tags and wrong country codes are the classic failure modes.",["canonical-tag","duplicate-content","multi-location-seo"]],["schema-markup","Schema Markup","Structured-data vocabulary (schema.org) de
1scribing page entities so engines can disambiguate them. JSON-LD is the preferred format; markup must mirror visible content.",["json-ld","rich-result","faqpage-schema"]],["noindex-tag","Noindex Tag","A directive (meta robots or X-Robots-Tag) asking engines not to index a page. Correct for private, duplicate, staging, and utility pages; catastrophic when leaked onto money pages.",["robots-txt","canonical-tag","staging-site-indexation"]],["soft-404","Soft 404",'A page that looks like an error (empty listing, "no results") but returns HTTP 200. Engines treat it as low quality; audits should return real 404/410 statuses for dead ends.',["404-error","410-gone","http-status-code"]],["crawl-depth","Crawl Depth","Clicks from the homepage to reach a page. Deep pages get crawled less often and inherit less prominence; priority content belongs within a few hops with internal-link support.",["click-depth","internal-link","site-architecture"]],["site-migration","Site Migration","Any platform, domain, protocol, or architecture change affecting URLs. Safe migrations map every old URL, preserve signals with 301s, and monitor indexation and logs for weeks after.",["301-redirect","redirect-chain","log-file-analysis"]],["pagination","Pagination","Splitting long listings across numbered pages. Each page needs intentional canonical behavior and crawlable next/prev paths so deep items stay discoverable without duplicating signals.",["canonical-tag","crawl-depth","faceted-navigation"]],["faceted-navigation","Faceted Navigation","Filter URLs (color, size, price) that multiply crawlable combinations. Controls include noindexing thin facets, canonicalizing to parents, and parameter handling in Search Console.",["url-parameter","duplicate-content","crawl-budget"]],["url-structure","URL Structure","Readable, stable, segmented paths that describe the page. Short descriptive slugs beat parameter strings for users, sharing, and long-term maintainability.",["slug","url-parameter","site-architecture"]],["time-to-first-byte","Time to First Byte (TTFB)","Milliseconds until the server responds. High TTFB delays everything downstream including LCP, and usually points at hosting, edge caching, or server-render cost.",["page-speed","caching","cdn"]],["render-blocking-resource","Render-Blocking Resource","A script or stylesheet that delays first paint until it loads. Deferring non-critical JS, inlining critical CSS, and trimming third parties are the standard fixes.",["page-speed","largest-contentful-paint","lazy-loading"]]]),{slug:"canonical-tag",term:"Canonical Tag",def:'A hint (rel="canonical") naming the preferred URL when duplicates exist. Only about three in five pages web-wide carry a valid one, so validation must cover target quality and conflicting signals.',area:"technical-seo",related:["duplicate-content","301-redirect","pagination"],example:"A product reachable at /p/123, /sale/p/123, and /p/123?ref=x carries one canonical to /p/123. All three remain crawlable, but signals consolidate on the preferred URL.",wrong:"Pointing canonicals at broken or redirected URLs. The consolidation signal then aims at a page that cannot resolve, which is worse than no canonical at all."},{slug:"crawl-render-index-pipeline",term:"Crawl-Render-Index Pipeline",def:"The three stages between publishing and ranking: fetch the HTML, render resources including JavaScript, then select and store the page. Failures at different stages need different fixes, so audits must identify which stage broke.",area:"technical-seo",related:["crawling","indexing","javascript-seo"],example:"A page crawled but invisible in the index with content only in client-rendered widgets points at the render stage: check blocked scripts and render timeouts before rewriting copy.",faqs:[["Does Google render JavaScript?","Yes, fully for eligible pages, but with a delay tail. Time-sensitive content should not depend solely on client rendering."]]},{slug:"index-bloat",term:"Index Bloat",def:"Search indexes filling with low-value URLs: facets, parameters, tag archives, thin search pages. Bloat wastes crawl budget and dilutes quality signals, so audits segment the index by template and prune deliberately.",area:"technical-seo",related:["index-selection","faceted-navigation","content-pruning"]},{slug:"staging-site-indexation",term:"Staging Site Indexation",def:"Preview or staging hosts accidentally indexed and competing with production. Prevention is authentication plus noindex on non-production hosts; cleanup needs removal requests after the leak is sealed.",area:"technical-seo",related:["noindex-tag","canonical-tag","robots-txt"]},{slug:"log-file-analysis",term:"Log File Analysis",def:"Reading server logs to see which URLs bots actually fetch, how often, and with what status. Logs reveal crawl waste and orphaned discovery that crawler simulations can only guess at.",area:"technical-seo",related:["crawling","crawl-budget","crawl-stats-report"]},{slug:"http-status-code",term:"HTTP Status Code",def:"The numeric response of a URL: 200 success, 301/302 redirects, 404 missing, 410 gone, 500 server error. Audits classify failures by code because each one prescribes a different fix.",area:"technical-seo",related:["404-error","410-gone","soft-404"]},{slug:"404-error",term:"404 Error",def:'The standard "not found" response for dead URLs. Expected in small numbers after content removal; a spike means broken internal links or a bad migration map.',area:"technical-seo",related:["410-gone","soft-404","broken-link-building"]},{slug:"410-gone",term:"410 Gone",def:'An explicit "permanently removed" status, stronger than 404. Use it for deliberately retired pages with no equivalent, so engines drop them faster instead of rechecking.',area:"technical-seo",related:["404-error","soft-404","content-pruning"]},{slug:"json-ld",term:"JSON-LD",def:"The preferred structured-data format: a script block describing page entities without touching visible markup. One @graph can carry Organization, WebSite, Article, FAQ, and Breadcrumb nodes together.",area:"technical-seo",related:["sc
1hema-markup","rich-result","faqpage-schema"]},{slug:"client-side-rendering",term:"Client-Side Rendering",def:"Building page content in the browser with JavaScript after an initially thin HTML shell. Flexible for apps, but critical content and links should still be server-available for crawlers and fast paint.",area:"technical-seo",related:["server-side-rendering","javascript-seo","dynamic-rendering"]},{slug:"server-side-rendering",term:"Server-Side Rendering",def:"Rendering full HTML on the server per request so crawlers and users receive complete content immediately. The SEO-safe default for content pages in frameworks like SvelteKit and Next.js.",area:"technical-seo",related:["client-side-rendering","javascript-seo","time-to-first-byte"]},{slug:"dynamic-rendering",term:"Dynamic Rendering",def:"Serving prerendered HTML to bots and client-rendered pages to users. A workaround, not an architecture: useful for legacy apps, but parity drift between the two versions is a constant risk.",area:"technical-seo",related:["client-side-rendering","server-side-rendering","crawling"]},{slug:"caching",term:"Caching",def:"Storing responses at the browser, CDN, or edge so repeat visits skip origin work. Correct cache headers and edge caching are usually the cheapest large performance win available.",area:"technical-seo",related:["cdn","time-to-first-byte","page-speed"]},{slug:"cdn",term:"CDN",def:"A content delivery network serving static assets and cached pages from locations near the visitor. It cuts latency and TTFB globally without changing application code.",area:"technical-seo",related:["caching","page-speed","time-to-first-byte"]},{slug:"lazy-loading",term:"Lazy Loading",def:"Deferring below-the-fold images, video, and iframes until near the viewport. It trims initial page weight, the strongest lever on Core Web Vitals pass rates after server response.",area:"technical-seo",related:["largest-contentful-paint","page-speed","image-seo"]},{slug:"page-speed",term:"Page Speed",def:"How fast a page becomes usable, measured by field metrics like LCP and INP rather than single lab scores. Small gains compound commercially: a tenth of a second has moved retail conversions measurably.",area:"technical-seo",related:["core-web-vitals","largest-contentful-paint","time-to-first-byte"]},{slug:"largest-contentful-paint",term:"Largest Contentful Paint (LCP)",def:"The Core Web Vital measuring when the main content element finishes rendering, ideally under 2.5 seconds. Hero images, web fonts, and slow server responses are the usual culprits.",area:"technical-seo",related:["core-web-vitals","interaction-to-next-paint","cumulative-layout-shift"]},{slug:"interaction-to-next-paint",term:"Interaction to Next Paint (INP)",def:"The Core Web Vital measuring responsiveness: the delay between a user interaction and the next visual update. Heavy main-thread JavaScript is the standard cause of poor INP.",area:"technical-seo",related:["core-web-vitals","largest-contentful-paint","render-blocking-resource"]},{slug:"cumulative-layout-shift",term:"Cumulative Layout Shift (CLS)",def:"The Core Web Vital measuring visual stability: how much content jumps around while loading. Reserve space for images, ads, and embeds with width, height, or aspect-ratio boxes.",area:"technical-seo",related:["core-web-vitals","lazy-loading","page-speed"]},{slug:"mixed-content",term:"Mixed Content",def:"HTTP resources loaded on an HTTPS page. Browsers block or warn on them, breaking assets and trust signals, so audits must catch a single insecure canonical, script, or image.",area:"technical-seo",related:["https","http-status-code","canonical-tag"]},{slug:"url-parameter",term:"URL Parameter",def:"Query-string values (?sort=price) that create crawlable URL variants. Parameters expand URL space and slow rendering queues, so audits decide per parameter: crawl, canonicalize, or block.",area:"technical-seo",related:["faceted-navigation","crawl-budget","canonical-tag"]},{slug:"redirect-loop",term:"Redirect Loop",def:"Redirects that circle back on themselves so the destination never resolves. Loops are hard failures for users and bots; break them by mapping each URL to exactly one final target.",area:"technical-seo",related:["redirect-chain","301-redirect","http-status-code"]}
1,{slug:"crawl-rate-limit",term:"Crawl Rate Limit",def:"How fast a crawler is allowed to hit a server, set in Search Console or robots-adjacent controls. Lower it during fragile migrations; raise it when capacity allows faster discovery.",area:"technical-seo",related:["crawl-budget","robots-txt","log-file-analysis"]},{slug:"index-selection",term:"Index Selection",def:"The engine’s choice of which crawled pages to keep, favoring unique value and quality signals. Selection is why thin duplicates vanish from the index while consolidated canonicals survive.",area:"technical-seo",related:["indexing","index-bloat","content-consolidation"]},{slug:"html-sitemap",term:"HTML Sitemap",def:"A human-readable page listing important site sections for users and crawlers. Secondary to XML sitemaps and navigation, but useful on large or deep sites as a discovery safety net.",area:"technical-seo",related:["xml-sitemap","site-architecture","crawl-depth"]},{slug:"crawl-stats-report",term:"Crawl Stats Report",def:"The Search Console report showing crawl volume, response times, and status breakdowns over time. Sudden shifts after releases flag regressions before rankings move.",area:"technical-seo",related:["log-file-analysis","google-search-console","crawl-budget"]},{slug:"site-architecture",term:"Site Architecture",def:"How pages connect: hubs, categories, and link paths from the homepage down. Good architecture keeps priority pages shallow, clustered by topic, and reachable through descriptive links.",area:"technical-seo",related:["crawl-depth","internal-link","topic-cluster"]},{slug:"slug",term:"Slug",def:"The readable tail of a URL naming the page (/blog/what-is-byob). Short, descriptive, stable slugs survive redesigns and read well in results, shares, and AI citations.",area:"technical-seo",related:["url-structure","site-migration","url-parameter"]},{slug:"sitemap-generator",term:"Sitemap Generator",def:"A tool emitting the XML sitemap from a site’s real URL inventory. Generators must read canonical targets and indexation state, not just crawl output, or they advertise URLs engines should ignore.",area:"technical-seo",related:["xml-sitemap","canonical-tag","noindex-tag"]},{slug:"rich-result",term:"Rich Result",def:"An enhanced search result with extra visuals or data: stars, FAQs, images, prices. Eligibility comes from valid structured data plus page quality; markup alone never guarantees display.",area:"technical-seo",related:["schema-markup","json-ld","faqpage-schema"]},{slug:"click-depth",term:"Click Depth",def:"The number of clicks a user needs from the homepage to reach a page. Shallow click depth concentrates attention and internal-link value on priority content; deep pages wither.",area:"technical-seo",related:["crawl-depth","site-architecture","internal-link"]}],y=e=>e.map(([a,t,n,i])=>({slug:a,term:t,def:n,area:"onpage-content",related:i})),w=[...y([["on-page-seo","On-Page SEO","Optimizing individual pages: titles, headings, content depth, internal links, images, and schema. On-page work decides relevance once technical SEO has made the page reachable.",["title-tag","heading-hierarchy","internal-link"]],["title-tag","Title Tag","The clickable headline in search results and the strongest on-page relevance signal. Google rewrites most titles, so clarity and completeness beat rigid length rules.",["meta-description","duplicate-title-tag","serp"]],["meta-description","Meta Description","The optional summary that can become the result snippet. Absence is not a penalty and Google rewrites most descriptions, so prioritize valuable pages where controlled wording earns clicks.",["title-tag","click-through-rate","serp"]],["h1-tag","H1 Tag","The page’s primary heading naming its topic. Exactly one per page, matching search intent; everything else nests below it in the heading hierarchy.",["heading-hierarchy","title-tag","semantic-html"]],["heading-hierarchy","Heading Hierarchy","The nested H1→H2→H3 outline of a page. A clean hierarchy lets readers scan and lets parsers chunk sections accurately for retrieval and snippets.",["h1-tag","table-of-contents","chunking"]],["topic-cluster","Topic Cluster","A pillar page surrounded by interlinked subtopic pages. Cluster
1s make coverage legible to crawlers and readers at once, and internal links bind them into one structure.",["pillar-page","topical-authority","internal-link"]],["pillar-page","Pillar Page","The central page of a topic cluster covering the subject broadly and linking to every subtopic. Pillars anchor internal-link flow and usually target the head term.",["topic-cluster","content-hub","parent-topic"]],["content-hub","Content Hub","An organized entry point linking a topic’s guides, tools, and updates. Hubs distribute authority across the cluster and give readers one place to start.",["pillar-page","topic-cluster","site-architecture"]],["topical-map","Topical Map","The inventory of every subtopic, entity, and question a subject needs before writing begins. Maps expose coverage gaps competitors own and sequence what to publish next.",["topic-cluster","content-gap-analysis","parent-topic"]],["duplicate-content","Duplicate Content","Substantively identical content at multiple URLs, from facets, parameters, or syndication. Diagnose the pattern (template, locale, pagination) before prescribing canonicals or consolidation.",["canonical-tag","duplicate-title-tag","content-consolidation"]],["duplicate-title-tag","Duplicate Title Tag","Identical titles across pages, usually a symptom of faceted URLs or weak templates rather than the root problem. Fix the URL pattern or template, not just the string.",["title-tag","duplicate-content","faceted-navigation"]],["thin-content","Thin Content","Pages with little unique value: doorway variants, auto-generated filler, or stubs. Consolidate, expand with genuine information gain, or remove and redirect.",["content-pruning","content-consolidation","doorway-page"]],["keyword-cannibalization","Keyword Cannibalization","Multiple pages competing for the same query so engines split signals between them. Fix by consolidating, differentiating intent, or clarifying internal-link hierarchy.",["cannibalization-report","content-consolidation","keyword-mapping"]],["content-audit","Content Audit","A systematic inventory joining crawl data with demand, clicks, conversions, links, and quality scores. Audits decide per page: keep, refresh, consolidate, or retire.",["content-refresh","content-pruning","content-decay"]],["content-refresh","Content Refresh","Updating a promising page with current facts, coverage, and intent fit. Controlled comparisons show refreshed pages reaching top positions at roughly double the rate of untouched ones.",["content-decay","content-audit","date-modified"]],["content-decay","Content Decay","Traffic erosion as facts age, competitors expand coverage, or intent shifts. Decay signals (falling clicks at stable impressions) schedule refreshes before positions follow.",["content-refresh","decay-signal","content-audit"]],["content-pruning","Content Pruning","Removing or consolidating low-value pages to concentrate crawl budget and signals. Prune with redirects and internal-link updates, never by deletion alone.",["content-consolidation","index-bloat","410-gone"]],["content-consolidation","Content Consolidation","Merging overlapping pages into one authoritative URL with 301s and link updates. Consolidation resolves cannibalization and gives one page the combined relevance and links.",["keyword-cannibalization","301-redirect","content-pruning"]],["evergreen-content","Evergreen Content","Guides that stay relevant for years with light maintenance. Evergreen pieces compound links and traffic, funding the riskier topical bets around them.",["content-refresh","content-velocity","linkable-asset"]],["content-velocity","Content Velocity","The publishing rate within a topic over time. Velocity matters inside a bounded cluster (completing coverage fast) more than as raw site-wide volume.",["topical-authority","topical-map","editorial-calendar"]],["featured-snippet","Featured Snippet",'The excerpted answer box above organic results ("position zero"). Definitions, steps, and tables in answer-first format are the most snippet-eligible structures.',["position-zero","people-also-ask","answer-first-writing"]],["people-also-ask","People Also Ask (PAA)","Expandable related-question boxes revealing how Google decomposes a topic. PAA questions are a free brief: answer each one in a dedicated section or FAQ.",["featured-snippet","content-gap-analysis","faqpage-schema"]],["key-takeaways-box","Key Takeaways Box","A short bullet summary near the top stating the page’s conclusions. It serves skimmers, snippet extraction, and AI quoting with one scannable unit.",["answer-first-writing","structured-answer-block","featured-snippet"]],["table-of-contents","Table of Contents","Anchor-linked section lists that improve navigation, earn sitelinks, and expose heading structure to parsers. Auto-generate from H2/H3 IDs rather than hand-maintaining.",["heading-hierarchy","passage-ranking","internal-link"]],["faqpage-schema","FAQPage Schema","Structured data marking visible on-page Q&A pairs. Only mark questions with visible answers; hidden-answer FAQ markup is a spam risk, not a shortcut.",["schema-markup","people-also-ask","rich-result"]],["image-seo","Image SEO","Making images retrievable and fast: descriptive filenames, alt text, captions, responsive sizes, lazy loading, and accurate dimensions to protect CLS.",["alt-text","lazy-loading","cumulative-layout-shift"]],["alt-text","Alt Text","The text alternative describing an image for screen readers and parsers. One of the most common detectable accessibility failures, and part of every audit baseline.",["image-seo","accessibility-checker","multimodal-search"]]]),{slug:"topical-authority",term:"Topical Authority",def:"The depth and breadth of expertise a site demonstrates on a subject, earned by comprehensively covering a topic and interlinking it rather than publishing scattered pages. Engines reward the site that most completely owns a subject with rankings across many related queries.",area:"onpage-content",related:["topic-cluster","pillar-page","internal-link"],example:"HubSpot reorganized 12,000+ posts into pillar-cluster structures with roughly one internal link per 150 words, and saw broad month-over-month growth in first-page keywords across whole subjects, not single queries.",wrong:"Chasing volume: 200 thin posts loosely orbiting a keyword does not build authority. Completeness of a bounded topic plus interlinking beats archive size, and no backlink campaign substitutes for a coverage gap."},{slug:"entity-optimization",term:"Entity Optimization",def:"Writing so engines resolve which real-world things (people, products, places) a page is about: consistent names, disambiguating context, sameAs links, and schema. Entities are how modern retrieval thinks.",area:"onpage-content",related:["entity-salience","semantic-triple","knowledge-graph"],example:'A review naming "BYOB (byob.studio), the SvelteKit AI builder" with Organization schema leaves no doubt which BYOB is meant, unlike three bare mentions of "BYOB".'},{slug:"entity-salience",term:"Entity Salience",def:"How central an entity is to a passage, inferred from prominence, frequency, and position. The salient entity of each section should match the query the section targets.",area:"onpage-content",related:["entity-optimization","semantic-triple","passage-ranking"]},{slug:"semantic-similarity",term:"Semantic Similarity",def:"How alike two texts are in meaning rather than shared keywords. Engines use it for deduplication, clustering, and retrieval; near-duplicate pages with different words still read as duplicates.",area:"onpage-content",related:["cosine-similarity","duplicate-content","keyword-cluster"]},{slug:"passage-ranking",term:"Passage Ranking",def:'Ranking a page based on one strong section even when the whole page covers more. Self-contained sections with clear headings can win queries the page was never explicitly "about".',area:"onpage-content",related:["passage-embedding","chunk-retrieval","heading-hierarchy"]},{slug:"passage-embedding",term:"Passage Embedding",def:"The vector representation of a single section used in passage-level retrieval. One idea per section with the answer up front produces embeddings that match focused queries.",area:"onpage-content",related:["passage-ranking","vector-embedding","chunking"]},{slug:"parent-topic",term:"Parent Topic",def:"The broad subject a cluster of keywords or pages rolls up into. Mapping every keyword to a parent topic exposes whether coverage is complete or scattered across competing pages.",area:"onpage-content",related:["topical-map","keyword-cluster","pillar-page"]},{slug:"fact-checking",term:"Fact-Checking",def:"Verifying statistics, URLs, dates, and attributions against original publications before shipping. Citation hubs live or die on this step: one wrong number poisons every page that quotes you.",area:"onpage-content",related:["cited-framework","quotable-sentence","hallucination"]},{slug:"author-bio",term:"Author Bio",def:'Visible credentials answering "why trust this writer": role, expertise, and links to other work. Bylines with bios feed E-E-A-T assessment and make pages citable by humans and models.',area:"onpage-content",related:["byline","e-e-a-t","editorial-calendar"]},{slug:"byline",term:"Byline",def:"The named author (and date) attached to a page. C
1onsistent bylines tied to author pages turn scattered posts into attributable expertise an engine can accumulate per writer.",area:"onpage-content",related:["author-bio","date-modified","editorial-calendar"]},{slug:"date-modified",term:"dateModified",def:'Structured and visible "last updated" metadata telling engines and readers a page is maintained. Show published and updated dates together; freshness claims without dates are unverifiable.',area:"onpage-content",related:["content-refresh","byline","article-schema"]},{slug:"article-schema",term:"Article Schema",def:"Structured data for articles carrying headline, dates, author, and publisher. Pair it with visible bylines and dates so markup and page agree.",area:"onpage-content",related:["schema-markup","json-ld","author-bio"]},{slug:"e-e-a-t",term:"E-E-A-T",def:"Experience, Expertise, Authoritativeness, and Trust: Google’s quality-rater lens for content credibility. Demonstrate it with first-hand detail, named authors, sources, and accurate maintenance.",area:"onpage-content",related:["author-bio","cited-framework","search-quality-rater-guidelines"]},{slug:"editorial-calendar",term:"Editorial Calendar",def:"The publishing schedule sequencing topics, refreshes, and seasonal pieces. Calendars turn topical maps into shipped coverage instead of backlog wishes.",area:"onpage-content",related:["topical-map","content-velocity","query-deserves-freshness"]},{slug:"knowledge-graph",term:"Knowledge Graph",def:"The entity database behind knowledge panels: people, organizations, and places with verified attributes. Consistent names, sameAs links, and schema help engines connect your pages to the right entities.",area:"onpage-content",related:["entity-optimization","knowledge-panel","schema-markup"]},{slug:"knowledge-panel",term:"Knowledge Panel",def:"The entity summary box in results showing facts about a brand, person, or place. Earned through entity consistency across the site, profiles, and authoritative sources — not applied for directly.",area:"onpage-content",related:["knowledge-graph","entity-optimization","google-business-profile"]},{slug:"search-quality-rater-guidelines",term:"Search Quality Rater Guidelines",def:'The public manual for Google’s human quality raters, defining E-E-A-T assessment. Raters do not rank pages directly, but the guidelines reveal what "quality" means operationally.',area:"onpage-content",related:["e-e-a-t","helpful-content-system","author-bio"]},{slug:"helpful-content-system",term:"Helpful Content System",def:"Google’s page-level assessment rewarding original, satisfying, people-first content. Its self-assessment asks whether pages are comprehensive, expert, and clearly purposed — the signals topical authority describes.",area:"onpage-content",related:["e-e-a-t","topical-authority","content-audit"]},{slug:"glossary-page",term:"Glossary Page",def:"A definition entry owning one entity per URL with the answer in the first 50 words, related terms linked in the body, and DefinedTerm schema. Glossaries compound: each term page strengthens the cluster.",area:"onpage-content",related:["definedterm-schema","topical-authority","internal-link"]},{slug:"definedterm-schema",term:"DefinedTerm Schema",def:"Structured data marking a term and its definition for dictionary-style pages. Pair it with visible definitions and an A–Z hub so markup, navigation, and content agree.",area:"onpage-content",related:["glossary-page","schema-markup","json-ld"]},{slug:"decay-signal",term:"Decay Signal",def:"An early indicator content is aging: falling clicks at stable impressions, outdated facts, or fresher competitors. Decay signals schedule refreshes before positions follow.",area:"onpage-content",related:["content-decay","content-refresh","query-deserves-freshness"]}],v=e=>e.map(([a,t,n,i])=>({slug:a,term:t,def:n,area:"keyword-intent",related:i})),k=[...v([["keyword-research","Keyword Research","Finding the queries your audience actually types and mapping them to pages worth building. Teams that always do it report strong content results far more often than teams that skip it.",["search-intent","keyword-mapping","seed-keyword"]],["informational-intent","Informational Intent","Quer
1ies seeking to learn: guides, definitions, how-tos. Serve with complete explanations, examples, and next-step links rather than sales copy.",["search-intent","transactional-intent","pillar-page"]],["transactional-intent","Transactional Intent","Queries ready to act: buy, sign up, download. Serve with product fit, proof, pricing clarity, and one primary call to action.",["search-intent","commercial-investigation","conversion-rate"]],["commercial-investigation","Commercial Investigation",'Pre-purchase comparison queries ("X vs Y", "best X for Z"). Win with criteria tables, sourced claims, and honest fit statements instead of adjectives.',["transactional-intent","alternatives-page","fact-density"]],["navigational-intent","Navigational Intent",'Queries looking for a specific site or page ("byob pricing"). The brand’s own page should own these outright; anything else is a findability bug.',["search-intent","branded-keyword","site-architecture"]],["search-volume","Search Volume","Estimated monthly searches for a keyword. Useful for sizing demand, misleading as a value metric: intent and difficulty decide whether volume is worth chasing.",["traffic-potential","keyword-difficulty","zero-volume-keyword"]],["keyword-difficulty","Keyword Difficulty (KD)","A score estimating how hard a keyword is to win, usually from competitor link profiles. Treat it as a sorting aid, then verify with manual SERP analysis.",["search-volume","serp-analysis","traffic-potential"]],["head-term","Head Term",'A short, high-volume query ("website builder") with broad intent and fierce competition. Head terms convert through child pages and clusters, rarely through one page alone.',["mid-tail-keyword","long-tail-keyword","parent-topic"]],["mid-tail-keyword","Mid-Tail Keyword",'A 2–3 word query with clearer intent than head terms ("ai website builder pricing"). The efficient frontier for new clusters: real demand, winnable SERPs.',["head-term","long-tail-keyword","keyword-cluster"]],["long-tail-keyword","Long-Tail Keyword",'A specific multi-word query with low individual volume but strong intent ("sveltekit ai builder with custom domain"). Aggregated long tails often beat head terms on total conversions.',["zero-volume-keyword","mid-tail-keyword","striking-distance-keyword"]],["zero-volume-keyword","Zero-Volume Keyword","A query tools report as having no searches, often a data gap rather than no demand. New, specific, or conversational queries start here before tools catch up.",["long-tail-keyword","search-volume","query-fan-out"]],["striking-distance-keyword","Striking Distance Keyword","A query ranking just below its potential (positions ~11–20) where small upgrades flip meaningful traffic. Refreshes, internal links, and intent fixes are the standard plays.",["content-refresh","serp-analysis","internal-link"]],["keyword-cluster","Keyword Cluster","A group of queries one page can satisfy because they share intent and SERP overlap. Cluster before writing: it prevents cannibalization and sizes the brief correctly.",["keyword-mapping","parent-topic","semantic-similarity"]],["keyword-mapping","Keyword Mapping","Assigning each keyword cluster to exactly one canonical page. The map is the contract that stops two pages from chasing the same query.",["keyword-cannibalization","keyword-cluster","cannibalization-report"]],["seed-keyword","Seed Keyword",'The starting term expanded into a full keyword set ("website builder" → hundreds of variants). Good seeds are broad enough to branch, narrow enough to stay topical.',["keyword-research","keyword-gap","parent-topic"]],["keyword-gap","Keyword Gap","Queries competitors rank for that you do not. Gaps sized by intent and difficulty become the most defensible briefs in the backlog.",["content-gap-analysis","keyword-research","traffic-potential"]],["serp-analysis","SERP Analysis","Reading the actual results page before targeting a keyword: formats winning, intent served, freshness, and who owns it. Ten minutes here saves ten wasted briefs.",["serp","serp-feature","search-intent"]],["serp","SERP","The search engine results page: rankings, features, ads, and AI answers competing for the click. Every keyword strategy starts by looking at the SERP it wants to join.",["serp-feature","serp-analysis","serp-volatility"]],["query-deserves-freshness","Query Deserves Freshness (QDF)","Queries where recency matters (news, scores, prices, versions). QDF topics need update cadence and visible dates, not one-and-done publishing.",["content-refresh","date-modified","editorial-calendar"]]]),{slug:"search-intent",term:"Search Intent",def:"The job behind a query: learn (informational), compare (commercial), buy (transactional), or navigate (navigational). Pages that mismatch intent rarely convert no matter how well they rank.",area:"keyword-intent",related:["informational-intent","transactional-intent","keyword-mapping"],example:'"Best AI website builder" is commercial investigation: the winner is a criteria table with trials and limits, not a 3,000-word history of website builders.',wrong:"Targeting transactional queries with purely informational pages. Ranking without converting is an intent mismatch, not a CRO problem."},{slug:"cannibalization-report",term:"Cannibalization Report",def:"An analysis listing URLs competing for the same queries, with positions and internal-link counts per contender. It turns vague cannibalization suspicion into a merge-or-differentiate decision per cluster.",area:"keyword-intent",related:["keyword-cannibalization","keyword-mapping","content-consolidation"]},{slug:"content-gap-analysis",term:"Content Gap Analysis",def:"Comparing your topic coverage against competitors and unanswered audience questions to find missing subtopics. Gaps become briefs;
1 briefs become clusters.",area:"keyword-intent",related:["topical-map","keyword-gap","people-also-ask"]},{slug:"serp-feature",term:"SERP Feature",def:"Non-classic result elements: snippets, PAA boxes, image packs, local packs, AI answers. Features change click math per keyword, so targets must account for what else occupies the page.",area:"keyword-intent",related:["featured-snippet","people-also-ask","zero-click-search"]},{slug:"position-zero",term:"Position Zero",def:"Shorthand for owning the featured snippet or answer box above position one. Valuable for visibility and voice answers, but zero-click behavior means it does not always convert to visits.",area:"keyword-intent",related:["featured-snippet","zero-click-search","ai-overviews"]},{slug:"branded-keyword",term:"Branded Keyword",def:'A query containing a brand name ("byob pricing"). Brands should own these with official pages; gaps here leak navigational traffic to affiliates or competitors.',area:"keyword-intent",related:["non-branded-keyword","navigational-intent","ai-brand-mention"]},{slug:"non-branded-keyword",term:"Non-Branded Keyword",def:"Queries without a brand name, where category pages compete on merit. Growth beyond existing demand lives here, and so does most competition.",area:"keyword-intent",related:["branded-keyword","search-volume","keyword-difficulty"]},{slug:"keyword-stuffing",term:"Keyword Stuffing",def:"Repeating keywords unnaturally to manipulate relevance. Modern retrieval penalizes or ignores it; natural entity coverage and complete answers outperform repetition.",area:"keyword-intent",related:["keyword-density","scaled-content-abuse","entity-optimization"]},{slug:"keyword-density",term:"Keyword Density",def:"The percentage of a page’s words that are a target keyword. Not a ranking lever; useful only as a staleness check that a page actually discusses its topic in natural terms.",area:"keyword-intent",related:["keyword-stuffing","entity-density","tf-idf"]},{slug:"traffic-potential",term:"Traffic Potential",def:"Estimated visits if a page ranked first for its cluster, summing long-tail spillover beyond head-term volume. Better than raw volume for prioritizing briefs.",area:"keyword-intent",related:["search-volume","keyword-difficulty","traffic-value"]},{slug:"tf-idf",term:"TF-IDF",def:"Term frequency–inverse document frequency: how distinctive a word is to a document versus the corpus. A diagnostic for under-covered subtopics, not a formula for stuffing winning terms.",area:"keyword-intent",related:["entity-density","keyword-density","content-gap-analysis"]},{slug:"entity-density",term:"Entity Density",def:"How thoroughly a page names the entities its topic requires. Missing entities competitors cover is a concrete, fixable gap; padding with repetitions is not coverage.",area:"keyword-intent",related:["tf-idf","entity-optimization","content-gap-analysis"]},{slug:"alternatives-page",term:"Alternatives Page",def:'A comparison page for buyers evaluating options ("X alternatives"). Win with criteria tables, sourced limits, honest fit statements, and one CTA — adjectives and cherry-picked rows lose trust.',area:"keyword-intent",related:["commercial-investigation","fact-density","transactional-intent"]}],x=e=>e.map(([a,t,n,i])=>({slug:a,term:t,def:n,area:"links-offpage",related:i})),S=[...x([["off-page-seo","Off-Page SEO","Everything that builds a site’s reputation elsewhere: backlinks, mentions, reviews, and digital PR. Off-page signals validate what on-page content claims about expertise.",["backlink","referring-domain","digital-pr"]],["referring-domain","Referring Domain","A unique site linking to you. Domain diversity matters more than raw link counts: 100 links from one site look like one relationship, not 100 votes.",["backlink","domain-rating","link-velocity"]],["link-equity","Link Equity","The ranking value passed through a link, shaped by the source’s authority, relevance, and number of outbound links. Internal links distribute equity; external links earn it.",["backlink","internal-link","pagerank"]],["pagerank","PageRank","Google’s original link-graph algorithm scoring pages by the quantity and quality of inbound links. Still conceptually alive inside modern systems, even though the public score is long dead.",["link-equity","backlink","domain-authority"]],["dofollow-link","Dofollow Link","A normal link passing ranking signals (the default when no rel attribute says otherwise). Editorial dofollow links from relevant pages are the unit of link building.",["nofollow-link","sponsored-link-attribute","ugc-link-attribute"]],["nofollow-link","Nofollow Link",'A link carrying rel="nofollow", historically passing no signals. Treated as a hint since 2019, and still the correct tag for untrusted or paid links you cannot vouch for.',["dofollow-link","sponsored-link-attribute","follow-vs-nofollow"]],["anchor-text","Anchor Text","The clickable words of a link, telling engines what the target is about. Descriptive anchors help; exact-match anchors at scale invite manipulation scrutiny.",["exact-match-anchor","anchor-text-distribution","internal-link"]],["exact-match-anchor","Exact Match Anchor","Anchor text identical to the target keyword. Internally it correlates with stronger traffic, but template-wide repetition across the web reads as over-optimization.",["anchor-text","anchor-text-distribution","internal-link"]],["domain-authority","Domain Authority (DA)","Moz’s 1–100 prediction of a domain’s ranking strength, driven largely by links. A third-party proxy, not a Google metric: use it for triage, never as a goal.",["domain-rating","topical-authority","url-rating"]],["domain-rating","Domain Rating (DR)","Ahrefs’ 0–100 measure of a site’s backlink strength. Like all third-party scores it approximates authority; it does not confer topical relevance.",["domain-authority","referring-domain","url-rating"]],["link-velocity","Link Velocity","The rate at which a site gains (or loses) links over time. Unnatural spikes invite scrutiny; steady earned growth alongside real coverage is the healthy pattern.",["referring-domain","toxic-backlink","digital-pr"]],["toxic-backlink","Toxic Backlink","A link from spammy, hacked, or manipulative neighborhoods that risks association harm. Audit the pattern (site-wide footers, PBNs, injections) before reaching for the disavow file.",["disavow-file","link-spam","manual-action"]],["link-reclamation","Link Reclamation","Recovering links you already earned: fixing 404 targets, claiming unlinked mentions, correcting misspellings. The highest-ROI link 
1work because the editorial decision already happened.",["unlinked-brand-mention","404-error","broken-link-building"]],["digital-pr","Digital PR","Earning editorial coverage and links with newsworthy data, tools, or stories. Citation hubs and original research are the repeatable assets behind most successful campaigns.",["linkable-asset","link-bait","off-page-seo"]],["guest-posting","Guest Posting","Writing for other publications to reach audiences and earn links. Legitimate as expertise sharing; scaled keyword-rich guest posts read as link schemes.",["editorial-link","link-insertion","digital-pr"]],["skyscraper-technique","Skyscraper Technique",'Find heavily-linked content, publish something definitively better, then ask linkers to reconsider. Works when "better" means genuinely more complete or current, not longer.',["linkable-asset","broken-link-building","outreach"]],["broken-link-building","Broken Link Building","Finding dead outbound links on relevant pages and offering your live resource as a replacement. High success rate because you solve the webmaster’s problem first.",["link-reclamation","skyscraper-technique","outreach"]],["link-bait","Link Bait","Content designed to attract links on merit: data studies, free tools, definitive guides. The asset does the outreach work passively for years after launch.",["linkable-asset","digital-pr","citation-hub"]]]),{slug:"backlink",term:"Backlink",def:"A link from another site to yours, still the strongest authority signal at page level. One relevant editorial link beats dozens of low-quality ones, and aged links decay as sources disappear.",area:"links-offpage",related:["referring-domain","dofollow-link","link-equity"],example:"A Forbes article linking your statistics hub as its data source passes relevance and trust no directory listing can match — and it arrived with zero outreach because the asset was the easiest page to cite.",wrong:"Buying link packages by volume. Two-thirds of links decay over time, and purchased patterns collapse together when sources are cleaned up."},{slug:"internal-link",term:"Internal Link",def:"A link between pages on the same site, guiding discovery and distributing relevance. Controlled tests show deliberate internal-link changes lifting organic traffic 5–25%, and underlinked priority pages are a standard audit finding.",area:"links-offpage",related:["topic-cluster","anchor-text","crawl-depth"],example:"Linking six related regional pages together produced a measured 7% traffic uplift in one controlled test: starved architecture fed with genuinely useful connections.",wrong:"Stuffing footers with keyword-rich links and calling it architecture. Prominence redistribution has losers as well as winners across the destination set."},{slug:"unlinked-brand-mention",term:"Unlinked Brand Mention",def:"A mention of your brand without a hyperlink. In classic SEO it is a reclamation opportunity; in AI search it is also visibility, since assistants cite and repeat familiar names.",area:"links-offpage",related:["link-reclamation","ai-brand-mention","digital-pr"]},{slug:"doorway-page",term:"Doorway Page",def:"Thin pages built to rank for specific queries and funnel visitors elsewhere. A long-standing spam category: serve the query on the page itself or consolidate into one genuine destination.",area:"links-offpage",related:["thin-content","scaled-content-abuse","manual-action"]},{slug:"disavow-file",term:"Disavow File",def:"A Search Console upload asking Google to ignore listed backlinks. A last resort for manual-action recovery or clear manipulation you cannot remove, not routine hygiene.",area:"links-offpage",related:["toxic-backlink","manual-action","reconsideration-request"]},{slug:"anchor-text-distribution",term:"Anchor Text Distribution",def:"The mix of branded, exact-match, partial, and generic anchors pointing at a page. Natural profiles skew branded and varied; heavy exact-match skew flags manipulation.",area:"links-offpage",related:["anchor-text","exact-match-anchor","co-occurrence"]},{slug:"co-occurrence",term:"Co-occurrence",def:"Brand or keyword mentions appearing near links or topics without direct anchors. Engines read co-occurrence as topical association, which is why unlinked mentions still move understanding.",area:"links-offpage",related:["co-citation","unlinked-brand-mention","entity-optimization"]},{slug:"co-citation",term:"Co-citation",def:"Two pages frequently cited together, implying topical relationship. Being co-cited with established authorities borrows relevance no single link states explicitly.",area:"links-offpage",related:["co-occurrence","digital-pr","citation-share"]},{slug:"link-spam",term:"Link Spam",def:"Manipulative linking at scale: paid posts without disclosure, PBNs, injections, automated comments. Detection (SpamBrain and manual review) targets patterns, so one tactic’s death never saves the strategy.",area:"links-offpage",related:["toxic-backlink","private-blog-network","manual-action"]},{slug:"private-blog-network",term:"Private Blog Network (PBN)",def:"Sites controlled by one party purely to sell or pass links. Footprint detection (hosting, themes, ownership, link overlap) makes PBNs a recurring manual-action source.",area:"links-offpage",related:["link-spam","toxic-backlink","manual-action"]},{slug:"linkable-asset",term:"Linkable Asset",def:"A page worth referencing: original data, free tool, definitive guide, or reference hub. Assets earn while you sleep; outreach without an asset is just asking for favors.",area:"links-offpage",related:["citation-hub","link-bait","digital-pr"]},{slug:"citation-hub",term:"Citation Hub",def:"A statistics page with 100+ verified, dated, sourced figures that writers and AI agents cite when they need a number. It earns backlinks passively because citing a verified source makes the citer credible.",area:"links-offpage",related:["linkable-asset","fact-checking","digital-pr"],example:"A freshly published audit-statistics hub picked up dofollow links from multiple referring domains within weeks, including a DR-94 publisher, with zero outreach.",wrong:'Publishing unsourced "statistics" roundups. One unverifiable number destroys the trust the whole asset monetizes.'},{slug:"outreach",term:"Outreach",def:"Asking publishers, linkers, or journalists to cover or link y
1our asset. Converts at low rates unless the asset genuinely improves their page, which is why asset quality precedes outreach volume.",area:"links-offpage",related:["digital-pr","broken-link-building","link-insertion"]},{slug:"follow-vs-nofollow",term:"Follow vs Nofollow",def:"Whether a link passes ranking signals (default follow) or withholds endorsement (nofollow, sponsored, ugc). Use follow for genuine editorial votes; tag anything paid, untrusted, or user-generated.",area:"links-offpage",related:["dofollow-link","nofollow-link","sponsored-link-attribute"]},{slug:"sponsored-link-attribute",term:"Sponsored Link Attribute",def:'rel="sponsored" marking paid or compensated links. Required disclosure for ads and sponsorships; omitting it turns marketing spend into a link-scheme liability.',area:"links-offpage",related:["nofollow-link","ugc-link-attribute","follow-vs-nofollow"]},{slug:"ugc-link-attribute",term:"UGC Link Attribute",def:'rel="ugc" marking user-generated links like comments and forum posts. Correct default for uncontrolled contributions; upgrade to follow only for vetted editorial content.',area:"links-offpage",related:["nofollow-link","sponsored-link-attribute","follow-vs-nofollow"]},{slug:"editorial-link",term:"Editorial Link",def:"A link a publisher adds voluntarily because the target improves their content. The gold standard of link building and the only kind that compounds without ongoing payment.",area:"links-offpage",related:["digital-pr","linkable-asset","guest-posting"]},{slug:"link-insertion",term:"Link Insertion",def:"Adding your link to an existing published page (niche edits). Legitimate when the page genuinely needs the resource; a paid-link risk when money changes hands quietly.",area:"links-offpage",related:["outreach","guest-posting","sponsored-link-attribute"]},{slug:"url-rating",term:"URL Rating (UR)",def:"Ahrefs’ page-level link-strength score. Useful for comparing two competing URLs’ backlink weight, not for judging topical fit or content quality.",area:"links-offpage",related:["domain-rating","domain-authority","backlink"]},{slug:"manual-action",term:"Manual Action",def:"A human reviewer penalty suppressing a site or pages until fixed and reconsidered. Check the Search Console report first whenever traffic collapses overnight without an update correlation.",area:"links-offpage",related:["reconsideration-request","link-spam","site-reputation-abuse"]},{slug:"reconsideration-request",term:"Reconsideration Request",def:"The documented cleanup plea after fixing a manual action: what was wrong, what changed, and evidence. Granted on proof of remediation, not on promises.",area:"links-offpage",related:["manual-action","disavow-file","link-spam"]},{slug:"scaled-content-abuse",term:"Scaled Content Abuse",def:"Mass-producing low-value pages (often AI-generated) to chase queries without genuine effort or oversight. A spam policy category: scale invites scrutiny, and thin pages fail selection regardless of volume.",area:"links-offpage",related:["thin-content","doorway-page","manual-action"]}],A=e=>e.map(([a,t,n,i])=>({slug:a,term:t,def:n,area:"local-seo",related:i})),T=[...A([["google-business-profile","Google Business Profile (GBP)","The free listing controlling how a business appears in Maps and local results: hours, categories, photos, reviews, posts. Complete and active profiles outrank neglected ones.",["gbp-category","review-signal","local-pack"]],["local-pack","Local Pack","The three-business map block atop local results. Pack membership runs on proximity plus profile strength, so track it separately from organic positions.",["map-pack","local-rank-tracking","google-business-profile"]],["nap-consistency","NAP Consistency","Matching Name, Address, and Phone data across listings, citations, and the site. Inconsistencies confuse entity resolution and suppress local confidence.",["local-citation","google-business-profile","entity-optimization"]],["local-citation","Local Citation","A directory or web mention of business name, address, and phone. Core citations on major platforms establish existence; niche directories add relevance per vertical.",["nap-consistency","local-link-building","duplicate-listing"]],["geo-modifier","Geo-Modifier",'A location word added to a query ("plumber austin"). Location pages and profiles must mirror the modifiers searchers actually use, not internal district names.',["local-search-intent","local-landing-page","near-me-search"]],["near-me-search","Near Me Search","Queries resolved by the searcher’s location rather than named places. Mobile proximity dominates, so service-area accuracy and reviews outweigh keyword density.",["local-search-intent","proximity-local-ranking-factor","google-business-profile"]],["review-signal","Review Signal","Rating volume, velocity, recency, and owner responses as local ranking and conversion input. A steady stream of answered reviews beats a stale perfect score.",["review-schema","google-business-profile","local-pack"]],["local-landing-page","Local Landing Page","A dedicated page per served location with unique proof: staff, photos, local reviews, area specifics. Template-swapped city pages with no local substance are doorway pages.",["geo-modifier","doorway-page","service-area-business"]],["gbp-category","GBP Category","The primary and secondary classifications of a business profile. The primary category is the strongest relevance lever in the profile;
1 choose what you are, not what you wish to rank for.",["google-business-profile","local-search-intent","multi-location-seo"]],["service-area-business","Service Area Business","A business serving customers at their locations without a storefront (plumbers, tutors). Hide the address, define service areas precisely, and lean on reviews and location pages.",["local-landing-page","google-business-profile","store-locator"]],["duplicate-listing","Duplicate Listing","Multiple profiles for one location splitting reviews and signals. Find via Maps search and category scans, merge through official channels, and prevent with one-owner governance.",["nap-consistency","google-business-profile","local-citation"]],["local-link-building","Local Link Building","Links from neighborhood sources: chambers, sponsors, local press, partners. A handful of genuinely local links outweigh national links for pack relevance.",["local-citation","digital-pr","linkable-asset"]],["local-rank-tracking","Local Rank Tracking","Measuring positions per searcher location via grid or coordinate tracking. Local results change block by block, so single-point rank checks mislead.",["local-pack","rank-tracking","map-pack"]],["multi-location-seo","Multi-Location SEO","Managing many profiles and location pages under one brand: governance, bulk verification, review workflows, and unique per-location proof at scale.",["local-landing-page","gbp-category","store-locator"]]]),{slug:"local-seo",term:"Local SEO",def:"Winning location-based results: business profiles, reviews, citations, and location pages. Proximity, relevance, and prominence decide the map pack more than classic domain metrics.",area:"local-seo",related:["google-business-profile","local-pack","nap-consistency"],example:"A dental clinic that completes its profile, adds real photos, answers every review, and publishes one unique location page per suburb typically takes the pack from competitors with stronger websites but neglected profiles.",wrong:'Keyword-stuffing the business name ("Best Cheap Plumber Austin 24/7"). Name spam risks suspension and converts worse than genuine review strength.'},{slug:"local-search-intent",term:"Local Search Intent",def:'Queries with an implicit or explicit location need: "near me", geo-modifiers, or services consumed locally. Serve with locations, hours, availability, and proof of proximity.',area:"local-seo",related:["near-me-search","geo-modifier","local-landing-page"]},{slug:"map-pack",term:"Map Pack",def:"The map-anchored business block in local results, synonymous with the local pack. Same optimization surface: profile completeness, reviews, proximity, and behavioral signals.",area:"local-seo",related:["local-pack","local-rank-tracking","review-signal"]},{slug:"proximity-local-ranking-factor",term:"Proximity (Local Ranking Factor)",def:"The searcher’s distance to the business, the heaviest local-pack input. You cannot move the searcher, so compete on the factors you control: relevance, reviews, and profile strength.",area:"local-seo",related:["near-me-search","local-pack","review-signal"]},{slug:"gbp-post",term:"GBP Post",def:"Short updates published directly on a business profile: offers, events, news. Low direct ranking effect, but active profiles earn more listing engagement and look maintained.",area:"local-seo",related:["google-business-profile","review-signal","local-pack"]},{slug:"store-locator",term:"Store Locator",def:"The find-a-location experience linking searchers to the right branch page. Each location needs its own crawlable URL with unique details, not a single map widget.",area:"local-seo",related:["local-landing-page","multi-location-seo","service-area-business"]},{slug:"review-schema",term:"Review Schema",def:"Structured data for visible on-page reviews. Google restricts review stars for self-serving pages, so mark up genuine third-party-reviewable entities and keep policies in mind.",area:"local-seo",related:["review-signal","schema-markup","site-reputation-abuse"]},{slug:"site-reputation-abuse",term:"Site Reputation Abuse",def:"Publishing third-party content (coupons, payday loans, unrelated affiliates) to exploit a reputable domain’s rankings. A policy violation regardless of disclosure quality.",area:"local-seo",related:["manual-action","review-schema","scaled-content-abuse"]}],P=e=>e.map(([a,t,n,i])=>({slug:a,term:t,def:n,area:"analytics-measure",related:i})),B=[...P([["google-search-console","Google Search Console (GSC)","The free official view of how Google sees a site: impressions, clicks, positions, indexation, and issues. Audits join its demand data to crawl findings before prioritizing anything.",["google-analytics-4","click-through-rate","index-coverage-report"]],["google-analytics-4","Google Analytics 4 (GA4)","Event-based analytics measuring what visitors do after they arrive. Pair it with Search Console to connect rankings to engagement and conversions instead of optimizing positions blindly.",["google-search-console","engagement-rate","conversion-rate"]],["impression","Impression","One appearance of a page or link in results or AI answers. Impressions without clicks diagnose snippets and intent fit; falling impressions diagnose demand or visibility loss.",["click","click-through-rate","average-position"]],["click","Click","A visit from a result or citation. Clicks are the reality check on rankings: positions that never convert are research inputs, not assets.",["impression","click-through-rate","organic-traffic"]],["click-through-rate","Click-Through Rate (CTR)","Clicks divided by impressions. Titles, descriptions, brands, and SERP features move CTR at stable positions, which is why snippet work precedes rank-chasing on convert
1ing queries.",["impression","title-tag","meta-description"]],["average-position","Average Position","The mean rank of a page or query in Search Console. Directional, not literal: features, personalization, and averaging blur it, so read it with impressions and clicks.",["rank-tracking","impression","serp-volatility"]],["organic-traffic","Organic Traffic","Visits from unpaid search results, historically about a third of site traffic across industries. It converts intent already formed, which is why release controls should reflect its contribution.",["organic-share-of-voice","conversion-rate","click"]],["organic-share-of-voice","Organic Share of Voice","Visibility across a tracked keyword set relative to competitors, usually from clicks or weighted positions. The classic counterpart to AI share of voice for ten-blue-links measurement.",["share-of-voice-ai","visibility-score","rank-tracking"]],["engagement-rate","Engagement Rate","The share of sessions with meaningful interaction (time, scroll, events, conversions). GA4’s headline quality metric replacing bounce rate for most analysis.",["bounce-rate","dwell-time","conversion-rate"]],["bounce-rate","Bounce Rate","Single-page sessions without further interaction. Weak as a quality verdict alone (answers can satisfy in one page), useful for spotting broken or mismatched landings.",["engagement-rate","pogo-sticking","dwell-time"]],["conversion-rate","Conversion Rate","Visitors completing a goal divided by total visitors. The metric that turns traffic into money; intent-matched pages convert multiples higher than mismatched ones at equal volume.",["transactional-intent","attribution","engagement-rate"]],["attribution","Attribution","Assigning conversion credit across touchpoints. SEO often assists early and gets undervalued by last-click models, so compare assisted and data-driven views before judging the channel.",["conversion-rate","traffic-value","google-analytics-4"]],["rank-tracking","Rank Tracking","Monitoring positions for a keyword set over time. Still useful for diagnostics and share of voice, but features and AI answers mean it no longer equals visibility.",["serp-volatility","average-position","prompt-visibility-tracking"]],["serp-volatility","Serp Volatility","How much rankings shuffle day to day, rising during updates and feature tests. Check volatility indices before attributing a drop to your own changes.",["google-core-update","rank-tracking","serp"]],["google-core-update","Google Core Update","Broad ranking-system revisions rolled out several times a year. Recovery comes from genuinely better satisfaction of intent, not technical tweaks.",["serp-volatility","helpful-content-system","google-dance"]],["index-coverage-report","Index Coverage Report","The Search Console view of indexed versus excluded URLs with reasons. The fastest way to confirm bloat, canonicalization, and crawl-vs-index gaps on a real site.",["index-bloat","google-search-console","index-selection"]],["baseline-period","Baseline Period","The pre-change measurement window an experiment or update is judged against. No baseline, no causal claim: seasonality and trends must be priced in first.",["statistical-significance-seo-tests","seo-split-test","causal-impact-analysis"]],["data-sampling","Data Sampling","Analytics estimating from a subset when full computation is expensive. Sampling distorts long-tail SEO analysis first, so verify unsampled or BigQuery exports for content decisions.",["google-analytics-4","regex-filtering-in-gsc","log-file-analysis"]]]),{slug:"seo-split-test",term:"SEO Split Test",def:"Running a change on a page group while holding a control group back, then comparing outcomes. The only reliable way to know whether internal links, titles, or schema actually moved the needle.",area:"analytics-measure",related:["statistical-significance-seo-tests","causal-impact-analysis","baseline-period"],example:"Testing added category-level internal links on half a grocery catalog produced a measured 25% traffic uplift on the test group — evidence, not opinion, for rollout.",wrong:'Changing everything at once and crediting the last tweak. Without a control group, seasonality and updates explain most "wins".'},{slug:"statistical-significance-seo-tests",term:"Statistical Significance (SEO Tests)",def:"Confidence that a test result is real rather than noise, given sample size and variance. Small sites often cannot reach it, so they should test bigger changes or accept directional reads.",area:"analytics-measure",related:["seo-split-test","causal-impact-analysis","baseline-period"]},{slug:"causal-impact-analysis",term:"Causal Impact Analysis",def:'Estimating what would have happened without a change by modeling against controls or history. The formal version of "was it us or the update" for migrations and rollouts.',area:"analytics-measure",related:["seo-split-test","baseline-period","site-migration"]},{slug:"visibility-score",term:"Visibility Score",def:"A weighted index of rankings across a keyword set, emphasizing top positions and high-volume terms. Better than average position for executive reporting; worse than clicks for decisions.",area:"analytics-measure",related:["organic-s
1hare-of-voice","rank-tracking","traffic-value"]},{slug:"traffic-value",term:"Traffic Value",def:"The estimated ad cost of a site’s organic clicks. A rough money translation of SEO output, useful for resourcing conversations but not for P&L accounting.",area:"analytics-measure",related:["organic-traffic","cost-per-click","attribution"]},{slug:"cost-per-click",term:"Cost Per Click (CPC)",def:"The paid-search price per keyword click. In SEO it sizes traffic value and commercial intent: sustained high CPCs mark queries worth organic investment.",area:"analytics-measure",related:["traffic-value","transactional-intent","commercial-investigation"]},{slug:"dwell-time",term:"Dwell Time",def:"How long a visitor stays before returning to results. An indirect satisfaction proxy, not a confirmed ranking factor; optimize the experience, not the stopwatch.",area:"analytics-measure",related:["engagement-rate","pogo-sticking","bounce-rate"]},{slug:"pogo-sticking",term:"Pogo-Sticking",def:"Bouncing between results and the SERP, suggesting no result satisfied the query. At scale it flags intent mismatch for the ranking pages, not a penalty on any one of them.",area:"analytics-measure",related:["bounce-rate","dwell-time","search-intent"]},{slug:"regex-filtering-in-gsc",term:"Regex Filtering in GSC",def:"Using regular expressions in Search Console to slice queries and pages by pattern. The fastest route to template-level insights: one filter exposes every faceted or localized variant at once.",area:"analytics-measure",related:["google-search-console","cannibalization-report","faceted-navigation"]},{slug:"seasonality",term:"Seasonality",def:"Predictable demand cycles by week or season. Baselines and tests must compare like-for-like periods, or every December looks like a content triumph and every January a penalty.",area:"analytics-measure",related:["baseline-period","query-deserves-freshness","editorial-calendar"]},{slug:"search-demand-curve",term:"Search Demand Curve",def:"The head-to-tail distribution of query volume in a topic: few big terms, endless specific ones. Strategy follows the curve: pillars for heads, clusters for the tail aggregate.",area:"analytics-measure",related:["head-term","long-tail-keyword","parent-topic"]},{slug:"selection-rate",term:"Selection Rate",def:"How often users pick a given source or result when shown. In AI answers it parallels CTR: being retrieved matters less than being the source users and models select.",area:"analytics-measure",related:["click-through-rate","citation-share","prompt-visibility-tracking"]},{slug:"google-dance",term:"Google Dance",def:"Historical slang for ranking fluctuations during index updates. The term survives as shorthand for any volatile reshuffle while systems settle.",area:"analytics-measure",related:["serp-volatility","google-core-update","rank-tracking"]}],C=e=>e.map(([a,t,n,i])=>({slug:a,term:t,def:n,area:"ai-builder",related:i})),q=[...C([["one-click-deployment","One-Click Deployment","Publishing a site to production hosting without manual configuration. BYOB deploys to an edge network with rollback to known commits when a release misbehaves.",["custom-domain","deployment-rollback","staging-environment"]],["custom-domain","Custom Domain","Your own address (you.com) instead of a builder subdomain, with automatic SSL. The trust baseline for anything commercial: subdomains convert worse and rank no better.",["one-click-deployment","https","dns-record"]],["visual-editing","Visual Editing","Clicking page elements in a live preview and asking the AI to refine text, spacing, or layout. It keeps non-developers in flow while the underlying code stays standard and editable.",["ai-website-builder","live-preview","version-rollback"]],["live-preview","Live Preview","A running browser view of the generated site updating as code changes. Immediate feedback is the core loop of AI building: prompt, see, refine.",["visual-editing","staging-environment","testing-agent"]],["version-rollback","Version Rollback","Restoring a saved project state with human-readable notes. Rollbacks make AI experimentation safe: try bold changes knowing any step is recoverable.",["deployment-rollback","git-history","staging-environment"]],["deployment-rollback","Deployment Rollback","Redeploying a known-good commit after a bad release. Distinct from project rollback: this restores production while the workspace keeps iterating.",["one-click-deployment","version-rollback","site-migration"]],["staging-environment","Staging Environment","A non-production copy for testing changes before release. Staging must be authenticated or noindexed so preview URLs never compete with the live site.",["staging-site-indexation","noindex-tag","testing-agent"]],["chat-mode-vs-act-mode","Chat Mode vs Act Mode","BYOB’s two gears: Chat Mode reasons, explains, and plans without touching files; Act Mode edits code, connects services, and moves the project forward. Strategy first, implementation when decided.",["preflight-plan","ai-website-builder","prompt-for-website"]],["model-context-window","Model Context Window","How much conversation, code, and history a model can consider at once. Long builds need compaction and stable model selection so decisions survive across sessions.",["session-compaction","chat-mode-vs-act-mode","preflight-plan"]],["managed-database","Managed Database","Storage provisioned inside the builder (BYOB DB, Supabase) without manual setup: credentials land in the project environment and schemas stay inspectable from the workspace.",["supabase-integration","environment-variable","backend-as-a-service"]],["supabase-integration","Supabase Integration","Connecting a Supabase project for Postgres, auth, and storage from inside the workspace: credentials, schema inspection, migrations, and generated types without leaving the builder.",["managed-database","better-auth","environment-variable"]],["environment-variable","Environment Variable","Configuration kept out of code: API keys, project refs, secrets. Builders should request missing values explicitly and store them in project environment, never in generated files.",["managed-database","supabase-integration","security-headers"]],["testing-agent","Testing Agent","Automated full-site or feature-focused visual checks run from the workspace, optionally driving a real browser. C
1atches regressions AI iteration introduces faster than manual clicking.",["staging-environment","live-preview","accessibility-checker"]],["accessibility-checker","Accessibility Checker","Automated WCAG scanning (contrast, labels, alt text, empty controls) as an audit baseline. Machine checks catch the common failures; manual review covers what tools cannot detect.",["alt-text","testing-agent","semantic-html"]],["semantic-html","Semantic HTML","Using main, nav, header, article, and proper headings so assistive tech and parsers understand page structure. The foundation of both accessibility and machine readability.",["accessibility-checker","machine-readable-content","heading-hierarchy"]]]),{slug:"ai-website-builder",term:"AI Website Builder",def:"Software that turns plain-language descriptions into working websites. The best ones generate real, editable code and deploy it; the rest lock you into a canvas you cannot export.",area:"ai-builder",related:["prompt-for-website","one-click-deployment","visual-editing"],example:'Describe "a landing page for Bean & Brew coffee shop with menu and contact map" and BYOB generates a real SvelteKit project you preview live, refine by chat, and publish to your own domain.',wrong:"Judging builders by demo speed alone. The test is week two: can you edit, export, and deploy the code, or are you locked into whatever the demo generated?",faqs:[["Do I need to code to use an AI website builder?","No. You describe outcomes in plain language and refine the preview. Code access is there when you want it, not required."],["Who owns the generated website?","With BYOB you do: real SvelteKit code you can inspect, export, and deploy, unlike canvas-locked builders."]]},{slug:"svelte-components",term:"Svelte Components",def:"Reusable UI units (.svelte files) composing a SvelteKit app. Generated projects keep components small and named by feature so humans and AI alike can modify them safely.",area:"ai-builder",related:["sveltekit","visual-editing","redesign-patterns"]},{slug:"git-history",term:"Git History",def:"The commit trail of a generated project: what changed, when, and why. AI builders that commit with readable notes make every experiment reviewable and reversible.",area:"ai-builder",related:["version-rollback","deployment-rollback","preflight-plan"]},{slug:"session-compaction",term:"Session Compaction",def:"Summarizing long build conversations so work continues within context limits without losing decisions. Compaction plus model lock keeps multi-session projects coherent.",area:"ai-builder",related:["model-context-window","chat-mode-vs-act-mode","preflight-plan"]},{slug:"backend-as-a-service",term:"Backend as a Service (BaaS)",def:"Managed database, auth, and storage consumed via APIs instead of operated servers. BaaS is why solo builders ship full-stack apps: Supabase or BYOB DB replaces the ops team.",area:"ai-builder",related:["managed-database","supabase-integration","better-auth"]},{slug:"dns-record",term:"DNS Record",def:"The domain-system entries pointing your address at hosting: A/AAAA for apex, CNAME for subdomains. Custom-domain wizards set these automatically; manual setup needs exact values from the host.",area:"ai-builder",related:["custom-domain","https","one-click-deployment"]},{slug:"security-headers",term:"Security Headers",def:"HTTP response headers (CSP, HSTS, frame options) hardening a deployed site. Edge hosts should set sensible defaults; generated apps inherit them without per-project configuration.",area:"ai-builder",related:["https","environment-variable","mixed-content"]},{slug:"content-brief",term:"Content Brief",def:"The writing spec before drafting: query, intent, headings, facts to include, links, and success metric. Briefs turn topical maps into pages that satisfy extraction and readers alike.",area:"ai-builder",related:["topical-map","preflight-plan","prompt-for-website"]},{slug:"redesign-patterns",term:"Redesign Patterns",def:"Repeatable fixes for common generated-site flaws: hierarchy, spacing rhythm, contrast, and component consistency. Auditing new builds against patterns beats redesigning from taste.",area:"ai-builder",related:["visual-editing","svelte-components","accessibility-checker"]}],R=e=>e.map(([a,t,n,i])=>({slug:a,term:t,def:n,area:"byob-platform",related:i})),d="https://byob.studio/blog",O=[...R([["guided-preflight","Guided Preflight","The multi-step setup wizard BYOB runs before generating code: refining the prompt, identifying features, proposing UX direction, and choosing data options. Planning first is 
1what separates coherent apps from random screens.",["preflight-plan","prompt-for-website","intent-classifier"]],["lucky-build","Lucky Build (Autopilot)","The one-shot fast path that skips guided setup and generates directly from the prompt. Best for experiments and landing pages; guided preflight wins for anything with data or auth.",["guided-preflight","pass-1-build","ai-website-builder"]],["pass-1-build","Pass-1 Build","The uninterruptible first generation surface: styles, layout, page, components, then validation. Letting pass one finish prevents half-built states that later edits have to repair.",["guided-preflight","lucky-build","smoke-check"]],["act-mode","Act Mode","The gear where BYOB edits files, connects services, runs checks, and moves the project forward. Chat Mode reasons and plans without touching files; Act Mode executes once decided.",["chat-mode-vs-act-mode","guided-preflight","skill-routing"]],["intent-classifier","Intent Classifier","The router that sorts requests into bugfix, UI-only, full-stack, or backend-only work before acting. Correct classification keeps small asks cheap and stops UI tweaks from triggering migrations.",["act-mode","guided-preflight","chat-mode-vs-act-mode"]],["agent-blueprint","Agent Blueprint","The create-time record of a project’s seed, axes, and build plan. Blueprints make generation reproducible: the same brief plus the same plan rebuilds the same shape.",["ssot-seed","guided-preflight","project-template"]],["ssot-seed","SSoT Seed (Design Compass)","A single source-of-truth seed that rotates design axes so builds vary coherently instead of drifting. The seed is why two projects from similar prompts can still look deliberately different.",["agent-blueprint","design-lab","design-mixer-patterns"]],["design-lab","Design Lab","A temporary exploration mode for trying visual variants without touching the real project. Variants are disposable by design; only the chosen direction gets implemented.",["design-mixer-patterns","visual-editing","frontend-review"]],["model-lock","Model Lock","Keeping model selection stable for a chat session so decisions and style stay coherent. Mid-session model drift changes code idioms silently; locking prevents it.",["session-compaction","model-context-window","chat-mode-vs-act-mode"]],["living-spec","Living Spec","The dot byob file set that carries a project forward across sessions: vision plus living spec plus bootstrap plus task plan. Chat history compacts, files persist, and every turn starts from the files instead of a bloated transcript.",["guided-preflight","agent-blueprint","session-compaction"]],["ai-credits","AI Credits","The metered unit for AI work in BYOB: planning, generation, and agent runs draw down a balance tracked per project. Credits make heavy context work visible instead of hiding it in a flat fee.",["credit-top-up","subscription-plans","billing-action"]],["credit-top-up","Credit Top-Up","A one-time credit purchase for bursts beyond plan quota. Top-ups keep long builds moving without forcing a plan change mid-project.",["ai-credits","subscription-plans","billing-action"]],["subscription-plans","Subscription Plans (Free / Pro / Max)","Quota-gated tiers bounding credits, projects, and features. Plans set the default budget; top-ups absorb spikes; pay-as-you-go covers the rest.",["ai-credits","credit-top-up","billing-action"]],["billing-action","Billing Action","The structured paywall signal (insufficient credits, quota exceeded, plan required) with a checkout URL. Generated apps use the same pattern to gate their own premium features.",["ai-credits","subscription-plans","payment-orchestration"]],["project-template","Project Template","A saved starter — public, private, or shared — that new projects clone instead of starting blank. Templates capture working stacks, auth wiring, and design systems once.",["showcase-feed","agent-blueprint","guided-preflight"]],["showcase-feed","Showcase Feed","The opt-in public gallery of BYOB projects. Publishing to the showcase earns visibility and backlinks; promotion there compounds the launch itself.",["project-template","publish-slug","referral-program"]],["publish-slug","Publish Slug","A project’s public identity (`slug.byob.page`) before or alongside a custom domain. Slugs are stable, shareable, and never hardcoded into generated code.",["custom-domain","one-click-deployment","preview-urls"]],["preview-urls","Preview, Editor & Deployment URLs","The three canonical runtime addresses: live preview, workspace editor, and deployed site. Generated code must never hardcode them; they resolve per environment.",["publish-slug","staging-environment","one-click-deployment"]],["referral-program","Referral Program","Invite-friends-earn-credits mechanics inside BYOB. Referrals turn happy builders into the acquisition channel, tracked as their own pipeline line.",["ai-credits","showcase-feed","subscription-plans"]],["skill-routing","Skill Routing","Loading mandatory domain bundles (frontend, database, payments, auth, SEO, PWA, motion) before acting in that domain. Routing is why generated code follows one convention instead of improvising per prompt.",["act-mode","air-coding-skills","frontend-review"]],["air-coding-skills","AIR Coding Skills","Reusable synced knowledge packs (SEO, auth, payments, PWA) that agents load per domain. Skills keep every project on the same implementation patterns without re-teaching the model.",["skill-routing","act-mode","byob-cli"]]]),{slug:"preflight-plan",term:"Preflight Plan",def:"The setup pass before generation: refining the prompt, identifying features, proposing UX direction, and choosing data options. Planning first is 
1what separates coherent apps from random screens.",area:"byob-platform",related:["guided-preflight","content-brief","ai-website-builder"],example:"A restaurant site brief becomes features (menu, reservations, map), a UX direction (warm, single-page with sticky booking), and a data choice (deferred backend) — approved before a line of code exists.",wrong:"Skipping planning for “speed” on anything with auth, payments, or data. Generation without a plan produces screens; generation with one produces an app.",relatedPosts:["building-first-app-with-byob","what-is-byob"],sources:[{label:"BYOB: Building your first app",url:`${d}/building-first-app-with-byob`}]},{slug:"prompt-for-website",term:"Website Prompt",def:"The plain-language brief you give an AI builder: outcome, audience, sections, style, and constraints. Specific first prompts beat vague ones every time.",area:"byob-platform",related:["guided-preflight","preflight-plan","content-brief"],example:"“Landing page for Bean & Brew coffee shop: warm palette, hero with hours, menu section, contact map” generates a coherent page; “build me a website” generates a guess.",wrong:"Prompting like a search query. Builders need outcomes and constraints, not keywords.",relatedPosts:["ai-prompt-tips-for-byob","build-landing-page-in-5-minutes"],sources:[{label:"BYOB: 10 AI prompt tips",url:`${d}/ai-prompt-tips-for-byob`}]},{slug:"byob-cli",term:"BYOB CLI",def:"The command-line companion for BYOB projects: workspace status, deploys, database, storage, auth, email, analytics, git, and DNS from the terminal. The bridge between chat-built apps and local agent workflows.",area:"byob-platform",related:["mcp-stdio-bridge","agent-vs-container-mcp","git-history"],example:"`byob deploy` ships the current workspace; `byob database` inspects the live D1 schema — same project the chat built, now scriptable.",relatedPosts:["byob-cli-mcp-connections"],sources:[{label:"BYOB: CLI & MCP connections",url:`${d}/byob-cli-mcp-connections`}]},{slug:"design-mixer-patterns",term:"Design Mixer Patterns",def:"A library of composable visual directions (around 30 named patterns) the mixer combines per project. Patterns give the model a vocabulary beyond the default neutral look it reaches for otherwise.",area:"byob-platform",related:["design-lab","ssot-seed","design-antipatterns"],relatedPosts:["byob-3d-cylinder-landing-breakdown","dark-mode-design-guide"]},{slug:"design-antipatterns",term:"Design Antipatterns",def:"Banned default aesthetics: neutral cream palettes, generic serif editorial looks, muted placeholder styling. Naming what good taste excludes keeps generated design from converging on the same safe average.",area:"byob-platform",related:["design-mixer-patterns","frontend-review","design-lab"],relatedPosts:["dark-mode-design-guide","figma-to-code-designers-guide"]},{slug:"user-facing-copy",term:"User-Facing Copy",def:"Outcome-first interface text: CTAs, errors, empty states, and paywalls written for the user’s job, not the implementation. Good microcopy converts; placeholder copy leaks trust.",area:"byob-platform",related:["readability-copy","frontend-review","conversion-rate"],example:"“Publish your site in 30 seconds” beats “Initiate deployment sequence”; “You’re out of credits — top up to keep building” beats “Error 402”."},{slug:"readability-copy",term:"Readable Copy Level",def:"Writing interface and landing copy at a 5th–7th grade reading level. Benchmark data shows simple copy converting at roughly double the rate of professional-level writing.",area:"byob-platform",related:["user-facing-copy","conversion-rate","quotable-sentence"],sources:[{label:"Unbounce Conversion Benchmark Report",url:"https://unbounce.com/conversion-benchmark-report/"}]}],L=e=>e.map(([a,t,n,i])=>({slug:a,term:t,def:n,area:"edge-data",related:i})),s="https://byob.studio/blog",I=[...L([["cloudflare-worker","Cloudflare Worker","Serverless code running on Cloudflare’s edge network, close to visitors worldwide. BYOB deploys generated apps as Workers: no servers to provision, scale, or patch.",["dispatcher-worker","pages-domain","one-click-deployment"]],["dispatcher-worker","Dis
1patcher Worker","The SaaS router that maps each request — by publish slug or custom domain — to the right per-project Worker. One edge entry point, thousands of isolated apps behind it.",["cloudflare-worker","dispatch-namespace","kv-domain-map"]],["dispatch-namespace","Dispatch Namespace","The isolate group containing a fleet of per-project Workers. Namespaces let one platform deploy, version, and route user projects independently.",["dispatcher-worker","cloudflare-worker","project-lifecycle"]],["kv-domain-map","KV Domain Map","A key-value lookup binding slugs and custom hostnames to their Workers. Custom-domain support is a map entry plus DNS — no redeploy required.",["dispatcher-worker","custom-domain-dns","publish-slug"]],["pages-domain","Pages Domain (byob.page)","The hosted-site suffix for BYOB projects. Every publish gets a stable address on it instantly; custom domains layer on top when ready.",["publish-slug","custom-domain","cloudflare-worker"]],["d1-binding","D1 Binding & Proxy Token","How apps reach their database: a Worker binding plus a server-to-server proxy token. Credentials stay in project environment, never in generated files.",["d1-database","environment-variable","project-secrets"]],["drizzle-orm","Drizzle ORM","A typed TypeScript layer over SQL for schema definition and queries. Types generated from the live schema keep app code and database in agreement.",["d1-database","database-migration","seed-data"]],["database-migration","Database Migration","Versioned SQL changes applied in order, so schema evolves without losing data. Migrations are the contract between yesterday’s database and today’s code.",["drizzle-orm","d1-database","seed-data"]],["seed-data","Seed Data & Fixtures","Realistic demo rows loaded in foreign-key order, chunked to respect limits. Good seeds make every preview feel like a real product on first load.",["drizzle-orm","database-migration","managed-database"]],["r2-bucket-binding","R2 Bucket Binding","The named attachment (conventionally STORAGE) giving a Worker scoped access to one bucket. Bindings keep storage access declarative and auditable per project.",["r2-storage","signed-url","project-secrets"]],["signed-url","Signed URL","A time-boxed link granting private-file access without exposing the bucket. Uploads stay private; sharing stays possible; nothing leaks by default.",["r2-storage","r2-bucket-binding","security-headers"]],["project-inbox-worker","Project Inbox Worker","A mail-receiving Worker that turns inbound email into database rows. Apps get email-triggered workflows without running a mail server.",["cloudflare-worker","d1-database","signed-url"]],["supabase-auth-platform","Supabase Auth (Platform)","The dashboard login layer: JWT sessions, auth-state listeners, and Google sign-in for the BYOB product itself. Distinct from the Better Auth wiring generated apps receive.",["anon-vs-service-role","row-level-security","byob-managed-google-auth"]],["anon-vs-service-role","Anon Key vs Service-Role Key","The public client key (safe in browsers, constrained by RLS) versus the privileged server key (bypasses policies, never leaves the server). Mixing them up is the classic Supabase security bug.",["row-level-security","project-secrets","supabase-auth-platform"]],["row-level-security","Row-Level Security (RLS)","Per-user table policies enforced by the database itself: users can only read or write their own rows. RLS is what makes the anon key safe to ship in client code.",["anon-vs-service-role","supabase-auth-platform","better-auth"]],["project-secrets","Project Secrets & Env Status","Safe key-presence checks and derived-variable application for projects. Agents request missing values explicitly; secrets land in project environment, never in chat logs or code.",["environment-variable","anon-vs-service-role","d1-binding"]],["payment-orchestration","Payment Orchestration","The cross-provider setup order: products, prices, client tokens, notifications, checkout, webhooks — with clear env ownership per step. Orchestration prevents half-wired billing that charges nobody or everyone.",["paddle-checkout","razorpay-stack","webhook-verification"]],["webhook-verification","Webhook Verification","Cryptographically confirming payment callbacks actually came from the provider before fulfilling orders. Unverified webhooks let anyone grant themselves premium.",["payment-orchestration","paddle-checkout","razorpay-stack"]]]),{slug:"d1-database",term:"Cloudflare D1 Database",def:"SQLite at the edge: a relational database replicated near users with SQL semantics developers already know. BYOB DB provisions one per project with schema viewing and SQL inspection.",area:"edge-data",related:["d1-binding","drizzle-orm","database-migration"],example:"A SaaS starter gets users, subscriptions, and usage tables in D1; the workspace shows schema and rows live while the app queries through Drizzle types.",wrong:"Reaching for Postgres-scale ceremony on day one. D1 covers the vast middle of apps; migrate when measurements — not anxiety — say so.",relatedPosts:["by
1ob-auth-better-auth-d1"],sources:[{label:"Cloudflare D1 documentation",url:"https://developers.cloudflare.com/d1/"},{label:"BYOB: Better Auth & D1",url:`${s}/byob-auth-better-auth-d1`}]},{slug:"r2-storage",term:"Cloudflare R2 Object Storage",def:"S3-compatible blob storage with no egress fees, bound to Workers for uploads, images, and media. Generated apps get private browser routes and smoke checks, not raw credentials.",area:"edge-data",related:["r2-bucket-binding","signed-url","cloudflare-worker"],example:"A portfolio app uploads project images to R2 through an app-signed route; visitors see them via time-boxed signed URLs while the bucket stays private.",relatedPosts:["byob-storage-r2"],sources:[{label:"Cloudflare R2 documentation",url:"https://developers.cloudflare.com/r2/"},{label:"BYOB: Mastering BYOB Storage",url:`${s}/byob-storage-r2`}]},{slug:"better-auth",term:"Better Auth",def:"Authentication with managed Google sign-in or email/password flows provisioned for generated apps. Auth pages (callbacks, sign-in) are private surfaces and stay noindexed like any other.",area:"edge-data",related:["magic-link-otp","byob-managed-google-auth","row-level-security"],example:"A client portal ships with Google sign-in managed by BYOB; the developer never touches OAuth client secrets or session tables.",relatedPosts:["byob-auth-better-auth-d1"],sources:[{label:"Better Auth documentation",url:"https://www.better-auth.com/docs"},{label:"BYOB: Better Auth & D1",url:`${s}/byob-auth-better-auth-d1`}]},{slug:"magic-link-otp",term:"Magic Link / OTP",def:"Passwordless sign-in: the user receives an email link or one-time code instead of inventing a password. Fewer credentials to phish, fewer reset flows to build, higher conversion than passwords.",area:"edge-data",related:["better-auth","byob-managed-google-auth","conversion-rate"],relatedPosts:["byob-auth-better-auth-d1"]},{slug:"byob-managed-google-auth",term:"BYOB-Managed Google Auth",def:"Google sign-in provisioned by the platform so generated apps authenticate without the developer registering OAuth clients. Project-owned OAuth remains available for teams bringing their own brand and keys.",area:"edge-data",related:["project-owned-oauth","better-auth","supabase-auth-platform"],relatedPosts:["byob-auth-better-auth-d1"]},{slug:"project-owned-oauth",term:"Project-Owned OAuth",def:"The developer’s own Google client ID and secret wired into their app. Required when the login screen must show the project’s brand and consent identity rather than the platform’s.",area:"edge-data",related:["byob-managed-google-auth","project-secrets","better-auth"]},{slug:"paddle-checkout",term:"Paddle Checkout",def:"Merchant-of-record billing: products, prices, client tokens, and notification webhooks handled by Paddle. Generated SaaS apps charge globally without assembling tax, invoicing, and dunning themselves.",area:"edge-data",related:["payment-orchestration","webhook-verification","razorpay-stack"],example:"A Pro plan becomes a Paddle product with monthly/yearly prices; checkout opens overlay-style and fulfillment fires only after webhook verification.",relatedPosts:["byob-paddle-payments"],sources:[{label:"Paddle developer docs",url:"https://developer.paddle.com/"},{label:"BYOB: Paddle payments",url:`${s}/byob-paddle-payments`}]},{slug:"razorpay-stack",term:"Razorpay Orders, Plans & Subscriptions",def:"India-first payments: orders for one-time charges, plans plus subscriptions for recurring billing, all confirmed via webhook secret. The right rail when customers pay in INR with UPI and cards.",area:"edge-data",related:["payment-orchestration","webhook-verification","paddle-checkout"],relatedPosts:["build-websites-in-india"],sources:[{label:"Razorpay docs",url:"https://razorpay.com/docs/"}]},{slug:"custom-domain-dns",term:"Custom-Domain DNS Setup",def:"Pointing your own address at a BYOB deployment: exact CNAME/TXT records, propagation waits, and status checks. The guided wizard emits the records; DNS does the rest within hours.",area:"edge-data",related:["kv-domain-map","custom-domain","dns-record"],example:"Add the provided CNAME for www and the verification TXT at the apex; the wizard polls until the edge serves your domain with automatic SSL.",wrong:"Changing nameservers blindly or stacking conflicting A/CNAME records, then debugging “site not found” for a day.",relatedPosts:["by
1ob-custom-domain-setup-guide","byob-build-to-domain-publish-flow-2026"],sources:[{label:"BYOB: Custom domain setup guide",url:`${s}/byob-custom-domain-setup-guide`}]},{slug:"git-pat-scope",term:"BYOB Git Token (PAT)",def:"A scoped personal access token granting agents and tooling repository access per project. Scoped and revocable: automation gets exactly the repos it needs, nothing ambient.",area:"edge-data",related:["git-history","project-secrets","version-rollback"],relatedPosts:["byob-version-control-git-for-non-developers"]}],j=e=>e.map(([a,t,n,i])=>({slug:a,term:t,def:n,area:"frontend-ship",related:i})),p="https://byob.studio/blog",D=[...j([["svelte-runes","Svelte Runes","The `$state`, `$derived`, `$effect`, and `$props` primitives powering Svelte 5 reactivity. Runes are mandatory in generated code: explicit, compilable, and consistent across every component.",["sveltekit","svelte-components","skill-routing"]],["file-based-routing","File-Based Routing","Pages defined by file location: `+page.svelte` renders, `+layout.svelte` wraps, `+server.js` serves data. The route tree is the app map — no separate router config to drift.",["load-function","form-actions","server-endpoint"]],["load-function","Load Function","Server-side data loading for a route before it renders. Load on the server for content crawlers and users need immediately; reach for client fetching only for interactive extras.",["file-based-routing","server-endpoint","server-side-rendering"]],["form-actions","Form Actions","Progressive-enhancement mutations: forms that work without JavaScript and upgrade with it. The default for generated app mutations — resilient and accessible by construction.",["file-based-routing","server-endpoint","hooks-server"]],["server-endpoint","Server Endpoint (+server.js)","The privileged layer for webhooks, secrets, and server-only logic. Anything touching keys, tokens, or private APIs lives here — never in components.",["hooks-server","anon-vs-service-role","webhook-verification"]],["hooks-server","Hooks (hooks.server.js)","The request gate for sessions, auth, and cookies across routes. Centralize identity checks here instead of repeating them per page.",["server-endpoint","better-auth","row-level-security"]],["ssr-csr-hydration","SSR vs CSR & Hydration","Server rendering delivers complete HTML fast; client rendering builds it in the browser; hydration animates the server HTML into an interactive app. Content pages render on the server by default.",["server-side-rendering","client-side-rendering","javascript-seo"]],["ui-kit-adapter","UI Kit Adapter","One component kit per app — shadcn-svelte, Flowbite, Skeleton, or DaisyUI — chosen at setup and used consistently. One kit means one visual language and one upgrade path.",["tailwind-tokens","svelte-components","redesign-patterns"]],["tailwind-tokens","Tailwind CSS 4 & app.css Tokens","Theme variables extended, never rewritten: generated apps customize the design system through tokens so regeneration preserves the brand instead of resetting it.",["ui-kit-adapter","protected-platform-files","design-mixer-patterns"]],["unplugin-icons","unplugin-icons / Iconify","Tree-shakable SVG icons imported as components (`~icons/lucide/*`). No raw pasted SVGs, no icon fonts — every icon ships only the paths it uses.",["svelte-components","tailwind-tokens","page-speed"]],["protected-platform-files","Protected Platform Files","The glue agents must not rewrite: layout, app.html, vite config, package manifest, llms.txt, env files. Protection keeps regeneration from destroying working infrastructure.",["tailwind-tokens","llms-txt-file","file-based-routing"]],["llms-txt-file","llms.txt","A machine-readable site map every generated app must carry. It tells AI agents what the site is and where things live — required infrastructure, not an afterthought.",["protected-platform-files","llms-txt","machine-readable-content"]],["pwa-manifest","PWA Manifest & Icons","The metadata making a site installable: name, icons, theme color, display mode. Manifest plus service worker turns a website into an app-like install.",["service-worker","install-prompt","offline-shell"]],["service-worker","Service Worker","The background script owning cache and update lifecycle. Versioned caches with explicit update prompts beat silent staleness every time.",["pwa-manifest","offline-shell","install-prompt"]],["install-prompt","Install Prompt","The add-to-home-screen moment, shown when engagement signals say yes — not on first paint. Timing the prompt is the difference between installs and dismissals.",["pwa-manifest","service-worker","safe-area-layout"]],["offline-shell","Offline Fallback & App Shell","A cached shell that renders when the network fails. Offline capability is a reliability feature users notice exactly when they need it most.",["service-worker","pwa-manifest","safe-area-layout"]],["safe-area-layout","Safe-Area Layout","Respecting notches, home indicators, and dynamic viewport units on mobile. Safe-area insets and dvh units keep CTAs tappable on every device.",["install-prompt","offline-shell","lazy-loading"]],["visual-testing-agent","Visual Testing Agent","A preview-URL auditor that checks rendered pages like a visitor would. Read-only by default; writes structured findings the builder can act on.",["testing-extension","smoke-check","frontend-review"]],["smoke-check","Smoke Check (npm run check / build)","The cheapest reliable gate: typecheck plus production build. Run it after every structural change — it catches breakage code review would take ten times longer to find.",["visual-testing-agent","pass-1-build","deployment-analytics"]],["mcp-protocol","Model Context Protocol (MCP)","The open standard connecting agents to tools: initialize, list tools, call, read resources, ping. MCP turns chat models into operators with real capabilities.",["agent-vs-container-mcp","mcp-stdio-bridge","mcp-resources"]],["agent-vs-container-mcp","Agent MCP vs Container MCP","The hosted broker versus the per-project executor. Agent MCP coordinates across projects; container MCP acts inside one workspace with its credentials and files.",["mcp-protocol","mcp-stdio-bridge","byob-cli"]],["mcp-stdio-bridge","MCP stdio Bridge","Running the BYOB CLI as a standard MCP server over stdio so Claude Code, Codex, and other clients attach directly. One 
1command turns the workspace into tools any agent can call.",["mcp-protocol","agent-vs-container-mcp","byob-cli"]],["mcp-resources","MCP Resources","Addressable context (`byob://project/<id>/context`, skill packs) agents read before acting. Resources give tools the project memory that bare function calls lack.",["mcp-protocol","air-coding-skills","session-compaction"]]]),{slug:"sveltekit",term:"SvelteKit",def:"The full-stack framework BYOB generates: Svelte 5 components with server rendering, file-based routing, and edge deployment. Standard code any developer can extend outside the builder.",area:"frontend-ship",related:["svelte-runes","file-based-routing","server-side-rendering"],example:"A generated marketing site is routes for pages, a layout for chrome, server endpoints for forms — open it in any editor and it reads like a well-built SvelteKit app, because it is one.",relatedPosts:["how-byob-uses-sveltekit","sveltekit-best-practices-2024"],sources:[{label:"SvelteKit documentation",url:"https://svelte.dev/docs/kit/introduction"},{label:"BYOB: How BYOB uses SvelteKit",url:`${p}/how-byob-uses-sveltekit`}]},{slug:"traefik-reverse-proxy",term:"Traefik Reverse Proxy",def:"The edge router in front of BYOB services: web/websecure entrypoints, Docker and file providers, automatic HTTPS redirects. One proxy terminates TLS and routes every workspace, preview, and API.",area:"frontend-ship",related:["acme-dns01","https-redirect-hsts","project-lifecycle"],sources:[{label:"Traefik documentation",url:"https://doc.traefik.io/traefik/"}]},{slug:"acme-dns01",term:"ACME DNS-01 & Wildcard Certificates",def:"Let’s Encrypt issuance via DNS challenges, producing wildcard certificates that cover every subdomain. DNS-01 is what makes `*.byob.page` and custom domains automatic instead of manual.",area:"frontend-ship",related:["traefik-reverse-proxy","custom-domain-dns","https-redirect-hsts"],sources:[{label:"Let’s Encrypt challenge docs",url:"https://letsencrypt.org/docs/challenge-types/"}]},{slug:"https-redirect-hsts",term:"HTTPS Redirect & Security Defaults",def:"Port-80-to-443 redirection with HSTS/CSP inherited from the edge. Generated apps get transport security by platform default, not per-project configuration.",area:"frontend-ship",related:["traefik-reverse-proxy","https","security-headers"],relatedPosts:["byob-build-to-domain-publish-flow-2026"]},{slug:"project-lifecycle",term:"Project Lifecycle (start / stop / restart / cleanup)",def:"Graceful workspace management: stop-before-start, local reset, stuck-project recovery. Lifecycle discipline is why iterating fast doesn’t corrupt running work.",area:"frontend-ship",related:["version-rollback","deployment-rollback","traefik-reverse-proxy"],relatedPosts:["building-first-app-with-byob"]},{slug:"deployment-analytics",term:"Deployment Analytics",def:"Per-window requests, errors, CPU time, and subrequests for every deployment, plus custom-domain status. Analytics turn “is it down?” from a feeling into a chart.",area:"frontend-ship",related:["smoke-check","one-click-deployment","log-file-analysis"],relatedPosts:["byob-deployment-pipeline-infrastructure"],sources:[{label:"BYOB: Deployment pipeline",url:`${p}/byob-deployment-pipeline-infrastructure`}]},{slug:"testing-extension",term:"BYOB Testing Extension",def:"The real-browser driver that lets the testing agent click, type, and scroll like a user. Scripted checks assert structure; the extension proves behavior.",area:"frontend-ship",related:["visual-testing-agent","cdp-playwright","smoke-check"],example:"A checkout flow test fills the form, submits, and asserts the confirmation — in a real Chromium, against the preview URL, on every release.",relatedPosts:["byob-ai-testing-extension-workflow","byob-feature-based-testing-guide"],sources:[{label:"BYOB: AI testing workflow",url:`${p}/byob-ai-testing-extension-workflow`}]},{slug:"cdp-playwright",term:"Container Browser (CDP / Playwright)",def:"The runner Chrome driven over DevTools protocol for automated checks. One shared browser, sessions with lifecycles — never install another one per test.",area:"frontend-ship",related:["testing-extension","visual-testing-agent","browser-session-lifecycle"],sources:[{label:"Playwright docs",url:"https://playwright.dev/"}]},{slug:"browser-session-lifecycle",term:"Browser Session Lifecycle",def:"Start, act, close: sessions are opened, driven through explicit actions, and torn down. Lifecycle hygiene prevents zombie browsers eating runner resources.",area:"frontend-ship",related:["cdp-playwright","testing-extension","smoke-check"]},{slug:"frontend-review",term:"Frontend Review / Critic Loop",def:"Screenshot-only scoring out of ten with a two-iteration cap. The critic sees pixels, not code — which is exactly what users see too.",area:"frontend-ship",related:["visual-testing-agent","design-antipatterns","user-facing-copy"],example:"A generated landing scores 6/10 (“hero competes with nav, CTA below fold on mobile”); two focused iterations land it at 9 without a redesign spiral."},{slug:"fruitalytics-verify",term:"Fruitalytics Verify",def:"Batch analytics assertions: click a selector, require the events. Verification turns “we shipped tracking” into “tracking fires” — per release, automatically.",area:"frontend-ship",related:["visual-testing-agent","smoke-check","engagement-rate"],relatedPosts:["by
1ob-feature-based-testing-guide"]}],z=e=>e.map(([a,t,n,i])=>({slug:a,term:t,def:n,area:"llm-engineering",related:i})),E=[...z([["temperature","Temperature","Sampling randomness for generation: low values make output focused and repeatable, high values make it varied and surprising. BYOB chat configs default near 0.5 while tool calls use 0.3 for steadier structured actions.",["top-k-top-p","model-routing","system-prompt"]],["thinking-budget","Thinking Budget","The token allowance reserved for internal model reasoning before answering. Larger budgets suit hard multi-step problems; BYOB prices thinking tokens separately so runaway reasoning shows up in metering.",["token-metering","chain-of-thought","context-threshold"]],["structured-output","Structured Output","Forcing model replies into a machine-readable shape such as JSON with fixed fields. Required wherever AI output feeds code, databases, or UI components, since free text breaks parsers the moment formatting drifts.",["json-schema-mode","function-calling","evals"]],["json-schema-mode","JSON Schema Mode","A structured-output setting where the caller supplies a JSON Schema and the model must conform to it. Types, required fields, and enums are validated automatically, which removes most post-processing repair code.",["structured-output","function-calling","evals"]],["function-calling","Function Calling","Letting a model request named tools with typed arguments instead of answering directly. The app executes the call and returns results, so the model can query data or trigger actions without inventing facts.",["structured-output","json-schema-mode","prompt-pipeline"]],["prompt-pipeline","Prompt Pipeline","A staged chain of model calls where each stage output feeds the next step: classify, then draft, then verify. Pipelines beat single giant prompts on reliability, and each stage can use the cheapest capable model.",["function-calling","model-routing","evals"]],["evals","Evals","Repeatable tests that score model behavior on fixed cases before and after prompt or model changes. Without evals every tweak is a guess; with them, regressions in tone, accuracy, or format get caught early.",["llm-judge","history-replay","structured-output"]],["history-replay","History Replay","Re-running a recorded conversation prefix to reproduce or debug model behavior deterministically. Saved histories turn flaky one-off sessions into repeatable cases for evals and judge scoring.",["evals","llm-judge","session-compaction"]],["top-k-top-p","Top-k and Top-p","Sampling filters that limit which tokens the model may pick: top-k keeps the k likeliest tokens, top-p keeps the smallest set covering probability p. They trim the weird tail without flattening style like low temperature does.",["temperature","system-prompt","model-routing"]],["system-prompt","System Prompt","The persistent instruction block prepended to every request that sets role, rules, and output format. It outranks user text in well-built stacks, which is why builders version it like code, not copy.",["few-shot-prompting","prompt-caching","prompt-injection-defense"]],["few-shot-prompting","Few-Shot Prompting","Showing the model two or more input-output examples inside the prompt so it imitates the pattern. Examples beat paragraphs of instruction for format, tone, and edge-case handling in builder and support tasks.",["system-prompt","chain-of-thought","evals"]],["chain-of-thought","Chain of Thought","Asking the model to reason step by step before giving the final answer, which raises accuracy on math, planning, and debugging. Keep the reasoning in thinking tokens and return only the conclusion to users.",["thinking-budget","few-shot-prompting","hallucination"]],["prompt-injection-defense","Prompt Injection Defense","Techniques that stop untrusted content from hijacking model instructions: delimiting retrieved text, least-privilege tools, and confirmation before side effects. Treat all pasted or fetched content as data, never orders.",["system-prompt","function-calling","grounding"]],["context-rot","Context Rot","Quality decay as prompts grow: models follow early instructions worse and miss details buried mid-context. Long builder sessions rot fastest, which is why compaction summarizes stale history instead of carrying everything.",["session-compaction","model-context-window","context-threshold"]],["rag-vs-finetune","RAG vs Fine-Tune","The build-versus-train choice for domain knowledge: retrieval grounds answers in fresh documents without retraining, while fine-tuning bakes in stable style and vocabulary. Most builders need retrieval first, training rarely.",["chunking","retrieval-augmented-generation","vector-embedding","grounding"]]]),{slug:"token",term:"Token",def:"The billing and budgeting atom of language models: text is split into subword pieces and every input, cached, thinking, and output token is metered separately. BYOB counts tokens with tiktoken and converts usage into credits per model pricing.",area:"llm-engineering",related:["token-metering","context-threshold","ai-credits","billing-action"],example:"A BYOB chat turn records input, cached, thinking, and output tokens separately, then prices each leg from the active model config — the same counters that feed the token meter and credit billing.",wrong:"Treating one token as one word or one character. Subword splitting means code and n
1on-English text cost more tokens per character than plain English prose.",faqs:[["Why do identical prompts cost different credits on different models?","Each model config carries its own input, output, cached, and thinking prices, so the same tokens convert to different credit amounts per model."],["Do cached tokens still cost anything?","Yes, at a reduced cached rate — reuse lowers the bill instead of removing it."]],relatedPosts:["byob-context-token-tracking-guide"],sources:[{label:"OpenAI documentation",url:"https://platform.openai.com/docs"},{label:"BYOB: Context token tracking guide",url:"https://byob.studio/blog/byob-context-token-tracking-guide"}]},{slug:"token-metering",term:"Token Metering",def:"Per-leg usage accounting that turns raw token counts into billable credits using each model price table plus markup. BYOB meters input, output, cached, and thinking tokens separately, with a minimum charge flooring tiny calls.",area:"llm-engineering",related:["token","context-threshold","ai-credits","billing-action"],example:"When a session uses a premium tool model, the meter shows input, output, cached, and thinking legs priced from that model config, so swapping to a cheaper chat model visibly drops the next turn credit cost.",wrong:"Reading the credit total as exact provider spend. Credits add platform markup and minimum charges, so they track relative session cost, not the provider invoice.",faqs:[["Why does one long session cost more than several short ones?","Long sessions accumulate output and thinking tokens and can cross long-context price thresholds, while short sessions reset the context each time."]],relatedPosts:["byob-context-token-tracking-guide"],sources:[{label:"BYOB: Context token tracking guide",url:"https://byob.studio/blog/byob-context-token-tracking-guide"}]},{slug:"context-threshold",term:"Context Threshold",def:"The input-size line where a provider switches a model to higher long-context pricing. BYOB model configs store the threshold with above-threshold rates, so sessions crossing it pay more per token without changing models.",area:"llm-engineering",related:["token-metering","model-context-window","session-compaction","prompt-caching"],example:"A chat config with a 272,000-token threshold bills inputs below the line at the base rate and inputs above it at the long-context rate — crossing mid-session raises costs even though the model name never changes.",wrong:"Assuming one flat per-token price. Long sessions can cross the threshold silently, so the meter, not the model name, tells you which rate is active.",relatedPosts:["byob-context-token-tracking-guide"],sources:[{label:"OpenAI documentation",url:"https://platform.openai.com/docs"},{label:"BYOB: Context token tracking guide",url:"https://byob.studio/blog/byob-context-token-tracking-guide"}]},{slug:"prompt-caching",term:"Prompt Caching",def:"Reusing priced prefixes of a prompt across requests so repeated system context bills at the reduced cached rate. Long builder sessions benefit most, since stable instructions and history prefixes repeat every turn.",area:"llm-engineering",related:["token-metering","context-threshold","model-context-window","system-prompt"],example:"BYOB model configs price cached input far below live input, with a small write cost to store the prefix — sessions that keep system prompts stable pay the cheap rate on every repeat turn.",wrong:"Expecting caching to help wildly varying prompts. Only stable shared prefixes hit the cache; rewriting instructions each turn pays full price plus write costs.",faqs:[["What breaks the cache most often?","Reordering content, appending timestamps to the prefix, or swapping models — all three turn a cache hit into a full-price call plus a fresh write."]],relatedPosts:["what-is-model-context-management"],sources:[{label:"Anthropic documentation",url:"https://platform.claude.com/docs/en/home"},{label:"BYOB: What is model context management",url:"https://byob.studio/blog/what-is-model-context-management"}]},{slug:"model-routing",term:"Model Routing",def:"Sending each request to the cheapest model that can handle it: light chat models for drafting, premium tool models for code actions. BYOB separates chat and tool configs per provider so sessions route without user intervention.",area:"llm-engineering",related:["provider-fallback","model-lock","temperature","prompt-pipeline"],example:"A BYOB session drafts copy with a light chat model and switches to the stronger tool model only for code edits and structured actions — routing keeps everyday turns cheap while reserving firepower for hard steps.",wrong:"Pinning every call to the flagship model. Maximum capability on trivial turns burns budget that routing would have saved with zero quality loss.",relatedPosts:["by
1ob-model-lock-chat-sessions"],sources:[{label:"BYOB: Model lock chat sessions",url:"https://byob.studio/blog/byob-model-lock-chat-sessions"}]},{slug:"provider-fallback",term:"Provider Fallback",def:"Retrying a failed model call on a backup provider or model instead of erroring the session. Fallbacks trade exact behavior continuity for uptime, so builders log which leg actually served each turn.",area:"llm-engineering",related:["model-routing","model-lock","token-metering"],example:"If the primary chat provider times out mid-build, the session retries on a backup provider chat config and keeps working — the meter records the fallback model rates for the affected turns.",wrong:"Assuming fallback output matches the primary exactly. Different models phrase, format, and reason differently, so verify resumed work instead of trusting continuity.",relatedPosts:["byob-model-lock-chat-sessions"],sources:[{label:"BYOB: Model lock chat sessions",url:"https://byob.studio/blog/byob-model-lock-chat-sessions"}]},{slug:"llm-judge",term:"LLM Judge",def:"Using a model to score other model outputs on rubrics like correctness, tone, or format compliance. Judges scale evals beyond hand-labeling, but need calibration against human grades or they bless fluent wrong answers.",area:"llm-engineering",related:["evals","history-replay","hallucination","grounding"],example:"BYOB backend configuration carries a dedicated judge model config alongside chat and tool configs, so scoring passes run on a calibrated grader instead of the model being tested.",wrong:"Letting the same model grade its own homework uncalibrated. Self-grading inflates scores; separate judges plus human spot-checks keep grades honest.",relatedPosts:["byob-feature-based-testing-guide"],sources:[{label:"OpenAI documentation",url:"https://platform.openai.com/docs"},{label:"BYOB: Feature based testing guide",url:"https://byob.studio/blog/byob-feature-based-testing-guide"}]}],M=e=>e.map(([a,t,n,i])=>({slug:a,term:t,def:n,area:"web-security",related:i})),H=[...M([["csrf","Cross-Site Request Forgery (CSRF)","An attack that tricks a logged-in browser into submitting unwanted state-changing requests to a trusted site. SameSite cookies, anti-CSRF tokens, and origin checks break the forgery chain.",["session-vs-token-auth","oauth2-authorization-code","rate-limiting-429"]],["sql-injection","SQL Injection","An attack that smuggles database commands through unsanitized input into application queries. Parameterized statements and least-privilege database roles keep hostile input as data, never executable code.",["owasp-top-10","dependency-scanning","row-level-security"]],["csp-directives","CSP Directives","The individual rules inside a Content Security Policy, such as script-src, object-src, and frame-ancestors. Each directive narrows one resource class, so auditing means reviewing directives one by one.",["content-security-policy","xss","mixed-content"]],["hsts","HTTP Strict Transport Security (HSTS)","A response header that obliges browsers to use HTTPS only for a domain, blocking protocol-downgrade attacks. BYOB’s Traefik edge already redirects port 80 to 443, and HSTS pins that behavior client-side.",["https","https-redirect-hsts","content-security-policy"]],["clickjacking-x-frame","Clickjacking & X-Frame-Options","A UI-redress attack that layers an invisible frame over a legitimate page to hijack clicks. The frame-ancestors CSP directive or X-Frame-Options DENY keeps sensitive pages unframeable.",["content-security-policy","csp-directives","xss"]],["pkce","PKCE (Proof Key for Code Exchange)","An OAuth extension that binds the authorization code to a secret the client created, blocking code interception on public clients. Mobile apps and browser-only clients should always send code_challenge with the request.",["oauth2-authorization-code","jwt-claims","better-auth"]],["refresh-token-rotation","Refresh Token Rotation","The practice of issuing a fresh refresh token with every access-token renewal and invalidating the old one. Stolen tokens then expire quickly, and reuse of a spent token signals compromise.",["jwt-claims","session-vs-token-auth","brute-force-protection"]],["session-vs-token-auth","Session vs Token Authentication","Server sessions store state behind an opaque cookie, while tokens carry signed claims the client presents each request. BYOB apps typically delegate both models to managed auth rather than hand-rolling stores.",["jwt-claims","refresh-token-rotation","better-auth"]],["brute-force-protection","Brute-Force Protection","Defenses that slow or block repeated credential guessing: attempt counters, progressive delays, CAPTCHAs, and account lockouts. Effe
1ctive setups throttle quietly while alerting on distributed patterns.",["rate-limiting-429","session-vs-token-auth","magic-link-otp"]],["dependency-scanning","Dependency Scanning","Automated auditing of third-party packages against vulnerability databases before and after deployment. Lockfiles, advisories, and CI gates turn newly disclosed CVEs into upgrade tasks instead of surprises.",["owasp-top-10","secrets-in-code","sql-injection"]],["webhook-timestamp-tolerance","Webhook Timestamp Tolerance","The maximum acceptable age of a signed webhook before rejection, typically measured in minutes. Tolerance windows block replay attacks while forgiving normal delivery delays and clock skew.",["webhook-verification","rate-limiting-429","open-redirect"]],["open-redirect","Open Redirect","A redirect endpoint that forwards users to any attacker-supplied URL, weaponized in phishing. Allowlists of destinations or signed redirect parameters keep navigation features from becoming launchpads.",["oauth2-authorization-code","csrf","webhook-timestamp-tolerance"]]]),{slug:"owasp-top-10",term:"OWASP Top 10",def:"The community-ranked list of the most critical web application risks, refreshed every few years from real breach data. Teams use it to prioritize injection, broken auth, and misconfiguration fixes first.",area:"web-security",related:["xss","sql-injection","secrets-in-code","security-headers"],example:"A launch review walks a BYOB storefront down the list: checkout input for injection, session cookies for broken access control, edge redirects for misconfiguration, then dependency and secrets hygiene before publish.",wrong:"Treating the ranking as a compliance checkbox instead of a prioritization aid. Your threat model decides the order; the list only tells you where whole industries keep bleeding.",faqs:[["How often does the list change?","Roughly every few years from survey and breach data. Track releases, but fix your own highest-risk findings first rather than waiting for a new edition."]],sources:[{label:"OWASP Top 10",url:"https://owasp.org/www-project-top-ten/"}]},{slug:"xss",term:"Cross-Site Scripting (XSS)",def:"An injection flaw where attacker-supplied scripts execute in a victim’s browser, stealing sessions or defacing pages. Output-encoding, framework auto-escaping, and strong CSP turn most payloads inert.",area:"web-security",related:["content-security-policy","csp-directives","clickjacking-x-frame"],example:"A project comment feed renders user text with Svelte {@html} and stored scripts run for every visitor. Switching to plain text interpolation keeps markup inert while links still render through an allowlisted markdown step.",wrong:"Filtering only known-bad strings such as script tags. Attackers encode, nest, or split payloads; escaping output and enforcing CSP defend structurally instead of chasing signatures.",faqs:[["Does a CSP make XSS impossible?","No. CSP sharply limits blast radius, but gaps such as unsafe-inline or a trusted-but-compromised script source still allow execution. Fix the injection and keep the policy tight."]],sources:[{label:"OWASP on cross-site scripting",url:"https://owasp.org/www-community/attacks/xss/"},{label:"MDN on Content Security Policy",url:"https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP"}]},{slug:"content-security-policy",term:"Content Security Policy",def:"An HTTP response header that whitelists exactly which origins may supply scripts, styles, and frames. A tight policy neuters injected payloads even after an XSS bug ships.",area:"web-security",related:["csp-directives","xss","clickjacking-x-frame","mixed-content"],example:"A BYOB marketing site allows scripts from its own origin plus one analytics domain and blocks everything else. When a third-party widget injects an inline snippet, browsers refuse it and file a violation report instead of running unknown code.",wrong:"Deploying report-only mode forever and calling the job done. Reports without enforcement train nobody; graduate tested policies to blocking once the noise settles.",sources:[{label:"MDN on Content Security Policy",url:"https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP"}]},{slug:"oauth2-authorization-code",term:"OAuth 2.0 Authorization Code Flow",def:"The standard delegation flow where users approve access on the provider and the app exchanges a short-lived code for tokens server-side. BYOB-managed Google sign-in hides this handshake from project developers entirely.",area:"web-security",related:["pkce","jwt-claims","better-auth","magic-link-otp"],example:"BYOB-managed Google sign-in runs this flow behind the scenes: the user approves on the provider, tokens land server-side, and project code receives a session without ever touching client secrets or code values.",wrong:"Running the legacy implicit flow that returns tokens in the URL fragment. Fragments leak through history and referrers; the code flow keeps tokens out of the browser address bar entirely.",faqs:[["Why prefer the code flow over implicit?","Tokens travel through a back-channel exch
1ange instead of the URL, so they avoid fragment leakage and gain PKCE and client authentication protections."]],relatedPosts:["byob-auth-better-auth-d1","what-is-better-auth"],sources:[{label:"RFC 6749: The OAuth 2.0 Authorization Framework",url:"https://datatracker.ietf.org/doc/html/rfc6749"},{label:"BYOB: Better Auth & D1",url:"https://byob.studio/blog/byob-auth-better-auth-d1"}]},{slug:"jwt-claims",term:"JWT Claims",def:"The signed JSON assertions inside a JSON Web Token, such as subject, expiry, issuer, and role. Services trust claims only after verifying signature, issuer, audience, and expiration together.",area:"web-security",related:["oauth2-authorization-code","refresh-token-rotation","session-vs-token-auth","better-auth"],example:"An API route accepts a bearer JWT, verifies signature plus expiry, issuer, and audience, then reads the role claim for authorization. Expired tokens earn a 401 even when the signature itself still checks out.",wrong:"Trusting claims from an unverified token, or skipping audience checks. A valid signature from the wrong issuer is still the wrong issuer.",relatedPosts:["byob-auth-better-auth-d1"],sources:[{label:"RFC 7519: JSON Web Token",url:"https://datatracker.ietf.org/doc/html/rfc7519"}]},{slug:"rate-limiting-429",term:"Rate Limiting & HTTP 429",def:"Server caps on request volume per client or key, answered with status 429 plus a Retry-After hint when exceeded. Limits protect login, signup, and AI endpoints from abuse and runaway costs.",area:"web-security",related:["brute-force-protection","webhook-timestamp-tolerance","server-endpoint"],example:"Login and AI-generation routes answer over-budget clients with status 429 and a Retry-After hint. Frontends back off and queue instead of retrying in a tight loop that deepens the overload.",wrong:"Returning success statuses with error bodies for throttled calls. Standard 429 responses let clients, proxies, and edge caches cooperate; bespoke signals force every integrator to guess.",sources:[{label:"MDN on HTTP 429",url:"https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/429"}]},{slug:"secrets-in-code",term:"Secrets in Code",def:"Credentials accidentally committed to repositories, chat logs, or client bundles where history preserves them forever. BYOB project secrets live in server environment, so agents request missing keys instead of pasting values.",area:"web-security",related:["project-secrets","owasp-top-10","dependency-scanning","anon-vs-service-role"],example:"A deploy fails because a payment key is missing. Instead of pasting the value into chat or code, the developer adds it through project secrets, where server environment picks it up and presence checks turn green.",wrong:"Deleting a leaked secret from the latest commit and moving on. History preserves every version, so revocation plus rotation is the only fix after exposure.",sources:[{label:"OWASP Top 10",url:"https://owasp.org/www-project-top-ten/"}]},{slug:"subdomain-takeover",term:"Subdomain Takeover",def:"Seizing a subdomain whose DNS still points at a deleted external service, then serving attacker content under a trusted name. BYOB custom-domain setup keeps DNS records verified so stale pointers get caught early.",area:"web-security",related:["hsts","https","open-redirect"],example:"A retired docs site leaves a subdomain pointed at a deleted host while DNS still answers. BYOB custom-domain verification ties records to live projects, so stale pointers surface during setup instead of after an attacker claims them.",wrong:"Removing the app but leaving its DNS records behind. Dangling records are the whole vulnerability; retire records and services together.",relatedPosts:["byob-custom-domain-setup-guide"],sources:[{label:"Cloudflare DNS documentation",url:"https://developers.cloudflare.com/dns/"}]}],Y=e=>e.map(([a,t,n,i])=>({slug:a,term:t,def:n,area:"data-deep",related:i})),r="https://byob.studio/blog",G=[...Y([["btree-index","B-Tree Index","The default balanced-tree structure making equality and range lookups fast without scanning every row. Add one where queries filter, join, or sort — then confirm with EXPLAIN before assuming victory.",["composite-index","partial-index","explain-query-plan"]],["composite-index","Composite Index","One index spanning several columns for queries that always filter them together, ordered most-selective first. A three-column composite beats three single-column indexes on the same query shape.",["btree-index","partial-index","unique-constraint-vs-index"]],["partial-index","Partial Index","An index covering only rows matching a predicate, such as live subscriptions where status is active. Smaller, faster, and cheaper to maintain than indexing rows queries never touch.",["btree-index","composite-index","soft-delete-tombstone"]],["unique-constraint-vs-index","Unique Constraint vs Index","A uniqueness guarantee enforced by the database versus a lookup accelerator with no such promise. Postgres implements unique constraints with an index, but only the constraint rejects duplicates.",["btree-index","composite-index","migration-tracking-table"]],["connection-pooling","Connection Pooling","Reusing a small set of open database connections across many requests instead of dialing fresh each time. Pools cap concurrency, cut handshake latency, and keep serverless bursts from overwhelming Postgres.",["pgbouncer-supavisor","managed-database","d1-vs-postgres-choice"]],["pgbouncer-supavisor","PgBouncer & Supavisor","Lightweight proxies that multiplex thous
1ands of app connections onto a handful of real Postgres sessions. Supavisor is Supabase’s managed pooler; PgBouncer is the self-hosted original both patterns descend from.",["connection-pooling","managed-database","supabase-auth-platform"]],["rls-performance-subquery","RLS Performance Subquery","The slow path where row policies re-evaluate per-row subqueries instead of once per statement. Wrapping the check in a single stable subquery lets Postgres cache the result and skip repeated work.",["rls-policy-recipe","row-level-security","explain-query-plan"]],["backup-pitr","Backup & Point-in-Time Recovery","Scheduled full snapshots plus a write-ahead log enabling restore to any second within retention. Point-in-time recovery turns “we dropped the wrong table” from catastrophe into a support ticket.",["retention-purge","audit-trail","managed-database"]],["retention-purge","Retention & Purge Policy","A documented policy deleting or archiving rows after their useful life, enforced by scheduled jobs. Retention bounds table growth, honors privacy promises, and keeps backups and queries fast.",["backup-pitr","soft-delete-tombstone","audit-trail"]],["audit-trail","Audit Trail","An append-only log recording who changed what and when, written by triggers or application events. Audits answer incident questions no snapshot can: intent, actor, and exact sequence of changes.",["retention-purge","soft-delete-tombstone","migration-tracking-table"]],["migration-tracking-table","Migration Tracking Table","The ledger recording which migrations already ran, so deploys apply each exactly once in order. Drizzle and Supabase both maintain one; never edit it by hand unless repairing a failed deploy.",["database-migration","seed-ordering-fk","chunked-inserts"]],["chunked-inserts","Chunked Inserts","Splitting large seed or import batches into bounded chunks that respect statement and payload limits. D1-backed seeding fails on giant multi-row inserts; a few hundred rows per batch sails through.",["seed-ordering-fk","seed-data","d1-database"]]]),{slug:"explain-query-plan",term:"EXPLAIN Query Plan",def:"The command prefix showing how the database will execute a query: scan types, index usage, join order, and row estimates. Reading plans separates “add an index” guesses from evidence about what the planner actually does.",area:"data-deep",related:["btree-index","n-plus-one","drizzle-orm"],example:"A BYOB Supabase project serves chat history through RLS policies; EXPLAIN shows a sequential scan on messages, so the team adds a conversation-scoped index and re-checks until the plan shows an index scan.",wrong:"Adding indexes blindly for every slow query. Unused indexes slow every write and bloat backups; measure with EXPLAIN first, then index deliberately.",relatedPosts:["byob-supabase-integration-deep-dive"],sources:[{label:"PostgreSQL EXPLAIN documentation",url:"https://www.postgresql.org/docs/current/sql-explain.html"},{label:"BYOB: Supabase integration deep dive",url:`${r}/byob-supabase-integration-deep-dive`}]},{slug:"n-plus-one",term:"N+1 Query Problem",def:"Fetching a list with one query then one extra query per row for its relations — 1 plus N round trips. ORMs make it easy to write; batching, joins, or dataloaders collapse it to a constant handful.",area:"data-deep",related:["explain-query-plan","drizzle-orm","connection-pooling"],example:"A project list page queries every project, then fires one follow-up query per project for owner profiles; a single join through Drizzle relations returns the same page in two round trips.",wrong:"Trusting tiny seed data to reveal query shape. Small tables hide N+1 while production-sized lists expose it, so test pagination with realistic volumes.",faqs:[["How do I spot an N+1 query?","Watch request logs for repeated identical queries differing only by id. One list fetch followed by dozens of single-row lookups is the signature pattern."],["Do joins always fix N+1?","Not always, but batching does: joins, grouped IN queries, or dataloader batching all collapse N round trips into a constant few. Measure before and after."]],relatedPosts:["by
1ob-supabase-integration-deep-dive"],sources:[{label:"Drizzle ORM documentation",url:"https://orm.drizzle.team/"},{label:"BYOB: Supabase integration deep dive",url:`${r}/byob-supabase-integration-deep-dive`}]},{slug:"rls-policy-recipe",term:"RLS Policy Recipe",def:"A tested pattern for row-level policies: scope by owner column, check membership once per statement, and deny by default. BYOB chat schemas gate every table on project or user ownership with zero public fallback.",area:"data-deep",related:["row-level-security","anon-vs-service-role","rls-performance-subquery"],example:"BYOB’s chat schema gates messages and sessions on project ownership: policies compare auth.uid() to the owner column, with service-role bypass reserved for server jobs.",wrong:"Shipping permissive “true” policies during development and forgetting them. Open RLS is silent data exposure; start deny-by-default and open narrowly with tests.",relatedPosts:["byob-supabase-integration-deep-dive"],sources:[{label:"Supabase documentation",url:"https://supabase.com/docs"},{label:"BYOB: Supabase integration deep dive",url:`${r}/byob-supabase-integration-deep-dive`}]},{slug:"soft-delete-tombstone",term:"Soft Delete & Tombstones",def:"Marking rows deleted with a timestamp flag instead of removing them, preserving history and undo. BYOB keeps a soft-delete grace window on projects before hard purge, so accidents stay recoverable.",area:"data-deep",related:["retention-purge","audit-trail","partial-index"],example:"BYOB’s project soft-delete flow stamps deleted_at instead of dropping rows; recovery jobs restore within the grace window while purge jobs later hard-delete expired tombstones.",wrong:"Soft-deleting without filtering or purging. Every query must exclude tombstones — ideally via partial indexes — or dead rows silently pollute results and growth.",faqs:[["When should rows hard-delete instead?","When retention expires, privacy law requires erasure, or storage costs bite. Soft delete is a grace window with a purge job, not permanent limbo."],["How do queries ignore tombstones?","Filter deleted_at IS NULL on every read, or hide tombstones behind views and partial indexes so application code rarely thinks about them."]]},{slug:"seed-ordering-fk",term:"FK-Ordered Seeding",def:"Inserting seed rows parent-first so every foreign key finds its target: users before projects, projects before messages. BYOB seeds run in dependency order with ids captured per step for child inserts.",area:"data-deep",related:["seed-data","chunked-inserts","migration-tracking-table"],example:"Seeding chat demo data inserts profiles, then projects referencing them, then messages referencing projects; reversing any step trips foreign-key violations on a fresh database.",wrong:"Seeding children before parents or hardcoding ids across files. Capture real ids per step and keep the dependency order explicit.",sources:[{label:"PostgreSQL constraints documentation",url:"https://www.postgresql.org/docs/current/ddl-constraints.html"}]},{slug:"d1-vs-postgres-choice",term:"D1 vs Postgres Choice",def:"Choosing edge SQLite (D1) for globally distributed reads and zero-ops scale versus Postgres for rich types, extensions, and heavy relational workloads. BYOB generates D1-first apps and reaches for Supabase Postgres when measurements demand it.",area:"data-deep",related:["d1-database","managed-database","drizzle-orm"],example:"A content-heavy marketing app ships on BYOB DB with Drizzle queries through the native binding; when full-text search and row policies dominate the roadmap, the team promotes the data layer to Supabase Postgres.",wrong:"Choosing by hype instead of workload. Model reads, writes, transactions, and extensions first; both engines win somewhere, neither wins everywhere.",faqs:[["Can a project start on D1 and move later?","Yes. Drizzle schemas port cleanly, and BYOB promotes the data layer to Supabase Postgres when workload measurements justify the move."],["What pushes a workload toward Postgres?","Full-text search depth, complex joins across large tables, extensions, and per-user row policies at scale all favor Postgres over edge SQLite."]],relatedPosts:["what-is-cloudflare-d1","what-is-supabase-postgres"],sources:[{label:"Cloudflare D1 documentation",url:"https://developers.cloudflare.com/d1/"},{label:"BYOB: What is Cloudflare D1",url:`${r}/what-is-cloudflare-d1`}]}],F=e=>e.map(([a,t,n,i])=>({slug:a,term:t,def:n,area:"api-webhooks",related:i})),o="https://byob.studio/blog",W=[...F([["rest-resource-design","REST Resource Design","Modeling an API as nouns with stable URLs — /projects/:id/messages — instead of action endpoints. Resource design makes caching, auth scoping, and client reasoning predictable across every route.",["server-endpoint","http-verbs-idempotent","openapi-contract"]],["http-verbs-idempotent","Idempotent HTTP Verbs","GET, PUT, and DELET
1E produce the same result when safely retried; POST does not promise that. BYOB server routes use idempotent verbs for mutations clients may repeat after network timeouts.",["idempotency-key","rest-resource-design","retry-backoff-jitter"]],["retry-backoff-jitter","Retry, Backoff & Jitter","Retrying failed calls after growing delays with random spread, so a fleet does not stampede a recovering service. Exponential backoff plus jitter turns synchronized thundering herds into gentle background noise.",["dead-letter-queue","webhook-delivery-attempts","rate-limit-429"]],["dead-letter-queue","Dead-Letter Queue","A holding area for messages that exhausted every retry, preserved with full context for inspection. Dead letters stop poison events from blocking healthy traffic and give operators a deliberate replay path.",["retry-backoff-jitter","webhook-delivery-attempts","webhook-replay"]],["api-versioning","API Versioning","Evolving an API without breaking existing clients: versioned paths or headers, additive changes first, removals on a schedule. Versioning is a promise that yesterday’s integration keeps working tomorrow.",["breaking-change-policy","sunset-header","openapi-contract"]],["sunset-header","Sunset Header","An HTTP response header announcing when an endpoint version retires, paired with migration guidance. Sunset headers turn surprise breakage into a planned upgrade with a date clients can schedule around.",["api-versioning","breaking-change-policy","error-envelope"]],["webhook-replay","Webhook Replay","Re-sending a past webhook event on demand to rebuild state after outages or receiver bugs. Provider dashboards and BYOB run histories both support replay; idempotent receivers make it safe to reuse.",["webhook-delivery-attempts","dead-letter-queue","idempotency-key"]],["timestamp-tolerance","Timestamp Tolerance","Rejecting signed webhooks whose timestamps fall outside a narrow window, typically minutes. Tolerance windows shrink replay-attack surface: even a valid captured payload expires before attackers can reuse it.",["hmac-signature-verify","webhook-delivery-attempts","webhook-verification"]],["openapi-contract","OpenAPI Contract","A machine-readable spec describing every route, schema, and error so clients and tests generate from truth. BYOB treats the OpenAPI file as the API contract: code, docs, and mocks all derive from it.",["rest-resource-design","error-envelope","api-versioning"]],["error-envelope","Error Envelope","A consistent failure shape — code, message, details, and request id — returned by every endpoint. Envelopes let clients handle errors programmatically instead of parsing unpredictable prose per route.",["openapi-contract","rate-limit-429","server-endpoint"]],["breaking-change-policy","Breaking-Change Policy","Written rules for what counts as breaking, how it is announced, and how long old behavior survives. Good policy pairs deprecation windows with Sunset headers so upgrades are scheduled, never sprung.",["api-versioning","sunset-header","openapi-contract"]]]),{slug:"idempotency-key",term:"Idempotency Key",def:"A client-supplied unique key letting servers recognize retried requests and return the original result. Payment endpoints require one per checkout attempt so double-clicks and timeouts never charge twice.",area:"api-webhooks",related:["http-verbs-idempotent","retry-backoff-jitter","paddle-checkout"],example:"A Paddle checkout route stores the idempotency key with the order; when the client retries after a timeout, the server returns the stored order instead of creating a second charge.",wrong:"Generating a fresh key on every retry. The key must stay constant across retries of the same intent, or the server cannot match them.",faqs:[["Where should the key live?","Clients generate one UUID per user intent and send it as a header; servers store it beside the order and match retries exactly."],["How long must keys persist?","At least as long as clients may retry — hours for checkouts, longer for background jobs. Expire them only after the retry window closes."]],relatedPosts:["byob-paddle-payments"],sources:[{label:"Str
1ipe idempotency documentation",url:"https://docs.stripe.com/api/idempotent_requests"},{label:"BYOB: Paddle payments",url:`${o}/byob-paddle-payments`}]},{slug:"hmac-signature-verify",term:"HMAC Signature Verification",def:"Recomputing a hash-based signature over the raw webhook body with a shared secret and comparing in constant time. HMAC verification is the proof a callback came from the provider, not an impersonator.",area:"api-webhooks",related:["webhook-verification","timestamp-tolerance","payment-orchestration"],example:"A Paddle notification route reads the raw body, recomputes the HMAC with the webhook secret, and fulfills the subscription only on match; mismatches log and return 400 without touching orders.",wrong:"Parsing the body to JSON first or comparing signatures with early-exit equality. Parse transforms bytes and timing leaks match length; verify raw bytes in constant time.",faqs:[["Why verify the raw body?","Serialization reformats bytes, which breaks signatures. Hash exactly the bytes received, then compare against the provider header."],["What belongs in the comparison?","Constant-time equality over hex or base64 digests. Early-exit string comparison leaks match position through timing side channels."]],relatedPosts:["byob-paddle-payments"],sources:[{label:"Paddle webhook signature verification",url:"https://developer.paddle.com/webhooks/signature-verification"},{label:"BYOB: Paddle payments",url:`${o}/byob-paddle-payments`}]},{slug:"webhook-delivery-attempts",term:"Webhook Delivery Attempts",def:"The provider retry schedule for webhooks: immediate attempts, spaced retries, then parked failures after a budget. BYOB run histories mirror this pattern, tracking each attempt so operators see exactly where delivery stands.",area:"api-webhooks",related:["webhook-replay","retry-backoff-jitter","dead-letter-queue"],example:"A subscription renewal notification fails during deploy; the provider retries on its schedule while the run history shows each attempt, and replay closes the gap once the route recovers.",wrong:"Treating one failed delivery as lost revenue. Design receivers idempotent and let the attempt schedule do its job before intervening manually.",relatedPosts:["byob-paddle-payments"],sources:[{label:"BYOB: Paddle payments",url:`${o}/byob-paddle-payments`}]},{slug:"pagination-cursor-vs-offset",term:"Cursor vs Offset Pagination",def:"Two ways to page lists: offsets skip N rows but drift as data changes; cursors anchor to a stable row id. Feeds and chat histories need cursors, where new inserts must never shift or duplicate pages.",area:"api-webhooks",related:["rest-resource-design","openapi-contract","server-endpoint"],example:"Chat message history pages by cursor on message id; loading older messages never skips or repeats rows even while new messages arrive mid-scroll.",wrong:"Using OFFSET for live feeds. Inserts shift every page boundary, so users see duplicates and gaps; reserve offsets for stable admin exports.",relatedPosts:["byob-supabase-integration-deep-dive"],sources:[{label:"BYOB: Supabase integration deep dive",url:`${o}/byob-supabase-integration-deep-dive`}]},{slug:"rate-limit-429",term:"Rate Limiting & 429s",def:"The server answering 429 Too Many Requests when clients exceed quota, with Retry-After saying when to return. Limits protect shared databases and run histories from one noisy client starving everyone else.",area:"api-webhooks",related:["retry-backoff-jitter","error-envelope","server-endpoint"],example:"A usage-metered endpoint returns 429 with Retry-After during a traffic spike; well-behaved clients back off with jitter while abusers stay capped instead of toppling the database.",wrong:"Retrying 429s immediately in a tight loop. Honor Retry-After with backoff, or the limiter keeps refusing and the spike becomes an outage."}],U=e=>e.map(([a,t,n,i])=>({slug:a,term:t,def:n,area:"email-deliverability",related:i})),N=[...U([["return-path-alignment","Return-Path Alignment","Matching the envelope sender domain used for SPF with the visible From domain that recipients see. Aligned domains let inbox providers credit authentication to the brand instead of the sending platform.",["spf-record","dmarc-policy","sender-identity"]],["sender-identity","Sender Identity","The verified domain or address a provider is permitted to send from, proven through DNS re
1cords. BYOB projects verify sending domains before campaigns so transactional mail leaves from a trusted name.",["dns-verification-txt","return-path-alignment","sender-reputation"]],["dns-verification-txt","DNS Verification (TXT)","Proving domain ownership by publishing a provider-issued token as a DNS TXT record. BYOB custom-domain and sender setup both use this challenge before activating routing or sending.",["sender-identity","spf-record","dkim-signing"]],["complaint-feedback-loop","Complaint Feedback Loop","A mailbox-provider channel reporting when recipients mark mail as spam, so senders can suppress complainers immediately. Ignoring complaints burns sender reputation far faster than any single campaign gains.",["suppression-list","sender-reputation","double-opt-in"]],["sender-reputation","Sender Reputation","The trust score mailbox providers assign to a sending domain or IP from engagement, complaints, and authentication history. High reputation lands in the inbox; low reputation diverts identical content to spam.",["email-warmup","complaint-feedback-loop","dedicated-vs-shared-ip","dmarc-policy"]],["email-warmup","Email Warmup","Gradually increasing send volume from a new domain or IP to build a positive reputation history. Patient ramp-ups with engaged recipients earn inbox placement that sudden blasts destroy.",["sender-reputation","dedicated-vs-shared-ip","transactional-vs-marketing"]],["transactional-vs-marketing","Transactional vs Marketing Email","Account messages users expect (receipts, resets, alerts) versus promotional campaigns needing consent and easy opt-out. Separating the streams protects critical delivery when marketing complaints spike.",["double-opt-in","list-unsubscribe-header","suppression-list"]],["double-opt-in","Double Opt-In","Requiring new subscribers to confirm via an emailed link before joining the list. The extra tap filters typos and bots, producing smaller lists that engage better and complain less.",["transactional-vs-marketing","complaint-feedback-loop","conversion-rate"]],["list-unsubscribe-header","List-Unsubscribe Header","A standard mail header advertising one-click unsubscribe, increasingly required by major mailbox providers for bulk senders. Honoring instant opt-outs preserves reputation better than hiding the exit.",["transactional-vs-marketing","double-opt-in","complaint-feedback-loop"]],["dedicated-vs-shared-ip","Dedicated vs Shared IP","Sending from an exclusive IP you warm and guard, versus pooling with other senders on a shared one. Dedicated suits high steady volume; modest senders usually inherit better reputation from a shared pool.",["sender-reputation","email-warmup","transactional-vs-marketing"]]]),{slug:"spf-record",term:"SPF Record",def:"A DNS TXT entry naming the mail servers allowed to send for a domain, checked against the envelope sender. Receivers distrust or reject mail from unlisted servers, so publishing SPF is step one of authentication.",area:"email-deliverability",related:["dkim-signing","dmarc-policy","return-path-alignment"],example:"A BYOB project sends receipts from its own domain through a mail provider. Publishing the provider’s sending hosts in one SPF TXT record tells receivers that matching mail is legitimate instead of spoofed.",wrong:"Stacking multiple SPF records or piling on includes until lookups fail. One record, minimal includes, then validate with a checker before campaigns start.",faqs:[["Why does SPF alone not stop all spoofing?","SPF checks the envelope sender, which recipients never see. Pair it with DKIM and a DMARC policy so the visible From domain carries the authentication result."]],relatedPosts:["byob-custom-domain-setup-guide"],sources:[{label:"Cloudflare email DNS records",url:"https://developers.cloudflare.com/dns/manage-dns-records/how-to/email-records/"},{label:"BYOB custom domain setup guide",url:"https://byob.studio/blog/byob-custom-domain-setup-guide"}]},{slug:"dkim-signing",term:"DKIM Signing",def:"Cryptographic email signing where the sender attaches a signature header verified against a DNS-published public key. Passing DKIM proves the message survived transit unmodified and truly came from the domain holder.",area:"email-deliverability",related:["spf-record","dmarc-policy","sender-identity"],example:"The project generates a DKIM key pair, publishes the public key as a DNS TXT record, and signs every receipt. Inbox providers verify the signature on arrival and treat intact mail as genuinely from the domain.",wrong:"Signing with weak keys or forgetting rotation after staff changes. Key hygiene matters as much as the signature itself.",relatedPosts:["by
1ob-custom-domain-setup-guide"],sources:[{label:"Cloudflare email DNS records",url:"https://developers.cloudflare.com/dns/manage-dns-records/how-to/email-records/"}]},{slug:"dmarc-policy",term:"DMARC Policy",def:"A DNS rule telling receivers how to treat mail that fails SPF and DKIM alignment: monitor, quarantine, or reject. Published reports then reveal exactly who sends as your domain, legitimate or not.",area:"email-deliverability",related:["spf-record","dkim-signing","return-path-alignment","sender-reputation"],example:"After SPF and DKIM pass consistently, the domain publishes a DMARC policy moving from monitoring to quarantine and finally reject. Aggregate reports then show exactly which services still send unauthenticated mail.",wrong:"Jumping straight to a reject policy on day one. Legitimate flows such as forwarding break first; ramp through monitoring so reports reveal every sender before enforcement.",faqs:[["What breaks most often under DMARC enforcement?","Forwarded mail and unauthenticated third-party senders. Inventory every service that sends as your domain during monitoring, then authenticate or remove each one."]],relatedPosts:["byob-custom-domain-setup-guide"],sources:[{label:"Cloudflare email DNS records",url:"https://developers.cloudflare.com/dns/manage-dns-records/how-to/email-records/"}]},{slug:"bounce-handling",term:"Bounce Handling",def:"Processing delivery failures by classifying hard bounces (dead addresses) separately from soft ones (full inbox, throttling). The project inbox worker records outcomes so dead addresses stop receiving retries automatically.",area:"email-deliverability",related:["suppression-list","sender-reputation","project-inbox-worker"],example:"The project inbox worker logs each send outcome; hard bounces land on the suppression list immediately while soft bounces retry a few times before the same fate. Dead addresses therefore stop consuming budget automatically.",wrong:"Retrying hard bounces indefinitely. Dead addresses never recover, and repeated attempts signal poor hygiene that drags down the whole domain."},{slug:"suppression-list",term:"Suppression List",def:"A persistent do-not-send registry of bounced addresses, spam complainants, and unsubscribes consulted before every send. BYOB’s email broker checks suppression first, so one bad address never poisons a whole campaign.",area:"email-deliverability",related:["bounce-handling","complaint-feedback-loop","transactional-vs-marketing","project-inbox-worker"],example:"Before a campaign launch, the email broker screens recipients against suppression: prior bounces, complaints, and unsubscribes drop out silently. The send reaches fewer addresses but every one of them is legally and technically mailable.",wrong:"Deleting suppressions to inflate list size before a big send. Re-mailing complainants invites blocks that punish future transactional mail too.",faqs:[["Can suppressed addresses ever return?","Yes, through a fresh, explicit opt-in that clears the old complaint or bounce state. Never restore addresses in bulk or on assumption."]]}],K=e=>e.map(([a,t,n,i])=>({slug:a,term:t,def:n,area:"product-analytics",related:i})),V=[...K([["autocapture","Autocapture","Automatic collection of clicks, pageviews, and form interactions without per-element instrumentation. Fast to start but noisy: retroactive data comes with vague names and mystery events that explicit tracking would have labeled.",["event-tracking","explicit-events","event-taxonomy"]],["explicit-events","Explicit Events","Hand-defined tracking calls placed at meaningful product moments: signup completed, checkout started, invite sent. Explicit events cost engineering time upfront and pay back in clean names and trustworthy funnels.",["event-tracking","autocapture","event-taxonomy"]],["event-taxonomy","Event Taxonomy","The naming contract for analytics: object-action conventions, required properties, and ownership per event. Taxonomies prevent the analytics swamp where three teams log the same signup three different ways.",["event-tracking","explicit-events","funnel-analysis"]],["cohort-analysis","Cohort Analysis","Grouping users by shared start time or behavior, then tracking each group retention or revenue over its own lifetime. Cohorts reveal whether product changes help new users or just reflect older, stickier ones.",["funnel-analysis","event-tracking","conversion-rate"]],["hypothesis","Hypothesis","A falsifiable prediction written before an experiment: changing X will move metric Y b
1y a stated direction. Hypotheses force teams to name the mechanism, which makes both wins and flat results interpretable.",["ab-testing","randomization","guardrail-metrics"]],["randomization","Randomization","Assigning users to test variants by chance so groups differ only randomly. Sound randomization is what lets an A/B result claim causation instead of correlation with pre-existing user differences.",["ab-testing","hypothesis","guardrail-metrics"]],["guardrail-metrics","Guardrail Metrics","Secondary metrics watched during experiments to catch harm the primary goal misses: latency, error rate, support contacts, unsubscribe rate. A test that lifts conversion while spiking unsubscribes fails its guardrails.",["ab-testing","hypothesis","engagement-rate"]],["cookieless-tracking","Cookieless Tracking","Measurement without third-party cookies: first-party identifiers, aggregated reporting, and modeled conversions. Built for browsers and regulations that block cross-site tracking, at the cost of individual-level precision.",["first-party-data","consent-mode","attribution"]],["first-party-data","First-Party Data","Behavioral and account data collected directly from your own product and site with user consent. It survives cookie deprecation and platform shifts, which is why owned telemetry beats rented audience segments.",["cookieless-tracking","consent-mode","pii-redaction"]],["consent-mode","Consent Mode","A tracking setup that adjusts data collection to each visitor consent choice: full measurement when granted, modeled or aggregate-only when declined. Preserves partial signal legally instead of choosing all-or-nothing tracking.",["cookieless-tracking","first-party-data","pii-redaction"]],["product-vs-marketing-analytics","Product vs Marketing Analytics","Two lenses on the same users: product analytics studies in-app behavior and retention, marketing analytics studies acquisition and channel return. Sharing taxonomy and user IDs keeps both lenses pointed at one truth.",["attribution","conversion-rate","engagement-rate","funnel-analysis"]]]),{slug:"event-tracking",term:"Event Tracking",def:"Recording user actions as timestamped events with properties, the raw material of product analytics. Clean event tracking answers what users do before asking why; replays and surveys explain the motivations behind the counts.",area:"product-analytics",related:["explicit-events","autocapture","event-taxonomy","funnel-analysis"],example:"A SaaS team logs signup started, signup completed, and project created with plan and source properties, then builds activation funnels directly from those three events without touching code again.",wrong:"Tracking everything just in case. Unowned volume events inflate bills and bury signal; instrument the decisions you actually make, then expand deliberately.",faqs:[["When is autocapture enough?","For early exploration and retroactive questions. Graduate to explicit events once funnels and experiments drive decisions."]]},{slug:"funnel-analysis",term:"Funnel Analysis",def:"Measuring stepwise conversion through an ordered series of events to find where users drop off. Funnels turn vague activation complaints into a specific step with a specific leak to fix first.",area:"product-analytics",related:["event-tracking","cohort-analysis","conversion-rate","ab-testing"],example:"A checkout funnel of viewed pricing to started trial to added payment to subscribed shows the steepest drop between trial and payment, so the team tests payment-step copy before touching pricing.",wrong:"Averaging conversion across all traffic. Blended funnels hide segment truths; split by source, device, and new versus returning users before redesigning anything.",faqs:[["How many steps should a funnel have?","Three to six covering one job: more steps usually means you merged two jobs and should split the funnel."]]},{slug:"ab-testing",term:"A/B Testing",def:"Comparing two or more variants on randomized audiences to measure causal impact on a chosen metric. Valid tests need a written hypothesis, sufficient sample, and guardrail metrics so wins do not hide damage elsewhere.",area:"product-analytics",related:["hypothesis","randomization","guardrail-metrics","funnel-analysis"],example:"A team tests a one-step versus three-step signup on randomly split traffic, watches completion as the goal with support-contact rate as guardrail, and ships only after the sample covers full weekly cycles.",wrong:"Peeking at results daily and stopping at the first significant-looking day. Early stopping inflates false wins; pre-commit to sample size and runtime before launching.",faqs:[["How long should an A/B test run?","Long enough to cover full weekly behavior cycles at the planned sample size — calendar time matters as much as visitor counts."]]},{slug:"pii-redaction",term:"PII Redaction",def:"Stripping emails, tokens, keys, and secrets from logged payloads before storage or display. Redaction belongs in the pipeline itself, since downstream dashboards and exports inherit whatever the collector kept.",area:"product-analytics",related:["first-party-data","consent-mode","allowed-origin-policy"],example:"BYOB redacts values whose keys contain markers like KEY, SECRET, TOKEN, JWT, or PASSWORD before logging environment writes, and payment reports store a redacted payload with secrets replaced.",wrong:"Redacting only at display time. Raw secrets in stored logs leak through exports, search indexes, and backups; scrub at collection, not at render."},{slug:"allowed-origin-policy",term:"Allowed Origin Policy",def:"An explicit allowlist of origins permitted to send analytics events for a site, rejecting data from impostor domains. Origin policies keep client-side telemetry trustworthy when the collection endpoint is public.",area:"product-analytics",related:["pii-redaction","first-party-data","fruitalytics-verify"],example:"A BYOB project adds its production domain to the Fruitalytics origin allowlist so events from the live site are accepted while copycat domains posting to the same endpoint are dropped.",wrong:"Relying on obscurity of the tracking endpoint. Public client keys are copyable by design, so the allowlist — not secrecy — is the trust boundary."}],$=e=>e.map(([a,t,n,i])=>({slug:a,term:t,def:n,area:"build-performance",related:i})),Q=[...$([["ssr-per-request","SSR Per Request","Fresh HTML rendered on the server for every request, used for personalized or frequently changing pages. Server rendering guarantees complete markup on first paint but costs compute per visit, so reserve it for dynamic routes.",["prerendering-static","csr-shell","server-side-rendering"]],["csr-shell","CSR Shell","A minimal HTML shell that renders content in the browser after JavaScript loads. Client rendering suits authenticated dashboards behind login, where SEO matters less and interactivity starts only after scripts execute.",["ssr-per-request","hydration-cost","client-side-rendering"]],["hydration-cost","Hydration Cost","The JavaScript work that turns server-rendered HTML into an interactive app. Hydration replays component logic in the browser, so oversized bundles delay input readiness even when paint looks instant.",["csr-shell","code-splitting-routes","page-speed"]],["adapter-static","SvelteKit adapter-static","A SvelteKit build target that emits a fully static site with no server runtime. Fully static output fits documentation and marketing pages, but any route needing server logic must switch back to a server adapter.",["adapter-cloudflare","prerendering-static","sveltekit"]],["immutable-hashed-assets","Immutable Hashed Assets","Static files with content hashes in their filenames, emitted under the immutable build output. When code changes the hash changes, so browsers safely cache each version forever without risking stale JavaScript or styles.",["cache-control-headers","code-splitting-routes","caching"]],["preload-prefetch","Preload & Prefetch","Resource hints that load critical files early or fetch likely-next files during idle time. Preload prioritizes fonts and hero assets for the current page, while prefetch warms the cache for routes the visitor may open next.",["lazy-loading","font-display-swap","largest-contentful-paint"]],["tree-shaking","Tree-Shaking","Build-time removal of unused exports so dead code never ships to browsers. Icon libraries and utility modules benefit most: importing one icon should add only that icon’s paths, never the whole set.",["code-splitting-routes","immutable-hashed-assets","page-speed"]],["font-display-swap","font-display: swap","A font rendering rule that shows fallback text immediately and swaps in the webfont when ready. Swap avoids invisible text during font loads, trading a brief style shift for readable content from the first paint.",["preload-prefetch","largest-contentful-paint","page-speed"]],["edge-cache-html","Edge-Cached HTML","Caching rendered HTML at CDN edge nodes close to visitors. Edge HTML caching cuts time to first byte for repeat views, but dynamic or personalized pages need careful keys or bypass rules to avoid serving one user’s markup to another.",["cache-control-headers","cdn","caching"]]]),{slug:"prerendering-static",term:"Prerendering (Static)",def:"Build-time HTML generation: pages render once during the build and ship as 
1static files. This BYOB site defaults to prerendered routes with explicit opt-outs, so content loads fast and crawlers see complete markup.",area:"build-performance",related:["ssr-per-request","adapter-cloudflare","server-side-rendering"],example:"This site sets prerender to true in the root layout so marketing, blog, glossary, and tool pages build to static HTML, keeps the dashboard on automatic prerendering, and disables it for the fetch-page API endpoint.",wrong:"Teams often assume every route should prerender, then watch authenticated pages leak shared HTML or builds fail on dynamic params. Prerender stable content; leave sessions and live endpoints dynamic.",faqs:[["When should a route opt out of prerendering?","Opt out when output depends on the request: logged-in dashboards, per-user data, or endpoints fetching live pages. This codebase marks the dashboard automatic and the fetch-page endpoint false for exactly that reason."],["What is the difference between true and automatic?","True always emits static HTML at build time, while automatic lets SvelteKit decide per route. True suits stable content pages; automatic suits mixed sections like the dashboard shell."]],relatedPosts:["how-byob-uses-sveltekit","sveltekit-best-practices-2024"],sources:[{label:"SvelteKit prerendering docs",url:"https://svelte.dev/docs/kit/page-options#prerender"},{label:"BYOB: How BYOB uses SvelteKit",url:"https://byob.studio/blog/how-byob-uses-sveltekit"}]},{slug:"adapter-cloudflare",term:"adapter-cloudflare",def:"The SvelteKit build target that deploys this site to Cloudflare Workers. The adapter maps dynamic routes to workers and static files to assets, with route include and exclude rules controlling what runs at the edge.",area:"build-performance",related:["adapter-static","cloudflare-worker","one-click-deployment"],example:"The site builds with adapter-cloudflare: dashboard and API routes run as workers while blog, glossary, tools, and marketing pages serve as static files, exactly matching the include and exclude lists in svelte.config.js.",wrong:"Reaching for adapter-static on an app with server endpoints silently drops dynamic behavior. Match the adapter to the app: static output for static sites, the Cloudflare adapter when workers serve live routes.",faqs:[["Do excluded routes still deploy?","Yes. Excluded paths still publish as 
1static assets alongside the worker; the exclude list only controls what the worker handles at request time, keeping edge compute focused on dynamic routes."]],relatedPosts:["byob-one-click-deployment-explained","byob-deployment-pipeline-infrastructure"],sources:[{label:"SvelteKit adapter-cloudflare docs",url:"https://svelte.dev/docs/kit/adapter-cloudflare"},{label:"Cloudflare Workers docs",url:"https://developers.cloudflare.com/workers/"}]},{slug:"cache-control-headers",term:"Cache-Control Headers",def:"Response headers telling browsers and CDNs how long to reuse a file. This site serves its RSS feed with a one-hour public cache, while hashed static assets can carry far longer lifetimes because filenames change on rebuild.",area:"build-performance",related:["immutable-hashed-assets","edge-cache-html","caching"],example:"The blog RSS endpoint returns public cache headers with a one-hour lifetime, so feed readers refetch hourly without hammering the origin — a small server file setting with outsized bandwidth savings.",wrong:"Caching HTML as aggressively as hashed assets is the classic mistake: visitors then see yesterday’s headlines. Cache versioned files long, revalidate markup short, and never confuse the two.",faqs:[["Why can hashed assets cache longer than HTML?","A new build writes new filenames, so old cached copies can never shadow fresh code. HTML keeps its URL across deploys, so it needs short lifetimes or revalidation to stay fresh."]],relatedPosts:["byob-deployment-pipeline-infrastructure"],sources:[{label:"Web.dev HTTP caching guide",url:"https://web.dev/articles/http-cache"},{label:"Cloudflare cache docs",url:"https://developers.cloudflare.com/cache/"}]},{slug:"code-splitting-routes",term:"Code-Splitting by Route",def:"Automatic chunking of JavaScript per route so visitors download only what the current page needs. SvelteKit splits at route boundaries by default, keeping dashboard code out of marketing pages and initial loads lean.",area:"build-performance",related:["tree-shaking","preload-prefetch","lazy-loading"],example:"Because routes split automatically, the interactive dashboard bundle never loads on a marketing page visit. Each section ships its own chunk, so first visits stay light even as the app grows.",wrong:"Importing dashboard utilities into shared layout code drags them into every chunk. Keep route-only imports inside route modules so the splitter can do its job.",relatedPosts:["sveltekit-best-practices-2024"],sources:[{label:"SvelteKit routing docs",url:"https://svelte.dev/docs/kit/routing"}]},{slug:"avif-webp-responsive",term:"AVIF, WebP & Responsive Images",def:"Modern image formats and sizes served to match each device: AVIF or WebP instead of heavier legacy formats, with responsive variants so phones never download desktop-sized heroes. Smaller files mean faster largest-paint moments.",area:"build-performance",related:["lazy-loading","largest-contentful-paint","preload-prefetch"],example:"A landing hero ships as AVIF for modern browsers with WebP fallback plus small, medium, and large widths, so a phone on mobile data downloads a fraction of what a desktop fetches.",wrong:"Uploading one giant PNG and letting CSS shrink it wastes every visitor’s bandwidth. Resize at build time, serve modern formats first, and reserve legacy formats for fallback only.",faqs:[["Should every image be AVIF?","Serve AVIF first with WebP and legacy fallbacks behind it. Encoding costs rise with newer formats, so generate variants once at build time rather than converting on every request."]],relatedPosts:["build-landing-page-in-5-minutes"],sources:[{label:"Web.dev image format guide",url:"https://web.dev/articles/choose-the-right-image-format"}]}],g=[{id:"ai-search-geo",name:"AI Search & GEO",description:"How AI answers find, quote, and cite your pages: overviews, assistants, crawlers, and retrieval."},{id:"technical-seo",name:"Technical SEO",description:"Crawling, indexing, rendering, speed, and the directives that keep URLs discoverable."},{id:"onpage-content",name:"On-Page & Content",description:"Titles, headings, topic coverage, content quality, and on-page structure."},{id:"keyword-intent",name:"Keyword Research & Intent",description:"Finding demand, mapping queries to pages, and matching intent."},{id:"links-offpage",name:"Link Building & Off-Page",description:"Backlinks, anchors, authority signals, and earning references."},{id:"local-seo",name:"Local SEO",description:"Map packs, business profiles, citations, and location pages."},{id:"analytics-measure",name:"Analytics & Measurement",description:"Search Console, rankings, experiments, and proving what worked."},{id:"ai-builder",name:"Building with AI",description:"AI website builders, prompts, and shipping real sites with BYOB."},{id:"byob-platform",name:"BYOB Platform",description:"How BYOB works: planning, credits, drafts, publishing, templates, and showcase."},{id:"edge-data",name:"Edge, Data & Auth",description:"Cloudflare Workers, D1, R2, auth, and payments behind generated apps."},{id:"frontend-ship",name:"Frontend & Shipping",description:"SvelteKit patterns, PWA, testing, agent tooling, and going live."},{id:"llm-engineering",name:"LLM Engineering",description:"Tokens, context, evals, structured output, and reliable AI pipelines."},{id:"web-security",name:"Web Security",description:"OWASP basics, XSS/CSRF/SQLi defense, CSP, OAuth2, and JWT."},{id:"data-deep",name:"Databases in Practice",description:"Indexes, RLS recipes, backups, pooling, and choosing storage."},{id:"api-webhooks",name:"APIs & Webhooks",description:"REST design, idempotency, retries, versioning, and rate limits."},{id:"email-deliverability",name:"Email Deliverability",description:"SPF/DKIM/DMARC, bounces, suppression, warmup, and providers."},{id:"product-analytics",name:"Product Analytics",description:"Events, funnels, A/B tests, cookieless tracking, and consent."},{id:"build-performance",name:"Build & Render Performance",description:"Prerendering, adapters, preload, bundles, and modern images."}],u={"ai-search-geo":m,"technical-seo":b,"onpage-content":w,"keyword-intent":k,"links-offpage":S,"local-seo":T,"analytics-measure":B,"ai-builder":q,"byob-platform":O,"edge-data":I,"frontend-ship":D,"llm-engineering":E,"web-security":H,"data-deep":G,"api-webhooks":W,"email-deliverability":N,"product-analytics":V,"build-performance":Q},l=g.flatMap(e=>
1u[e.id]),J=new Map(l.map(e=>[e.slug,e]));function X(e){return J.get(e)}function Z(){return l.map(e=>e.slug)}function _(e){return g.find(a=>a.id===e)}function ee(e){return[...u[e]].sort((a,t)=>a.term.localeCompare(t.term))}function te(){var a;const e=new Map;for(const t of l){const n=t.term.charAt(0).toUpperCase();e.has(n)||e.set(n,[]),(a=e.get(n))==null||a.push(t)}return[...e.entries()].map(([t,n])=>({letter:t,terms:n.sort((i,c)=>i.term.localeCompare(c.term))})).sort((t,n)=>t.letter.localeCompare(n.letter))}function ae(e,a=6){const t=[],n=i=>{i&&i.slug!==e.slug&&!t.some(c=>c.slug===i.slug)&&t.length<a&&t.push(i)};for(const i of e.related)n(X(i));if(t.length<a){for(const i of u[e.area])if(n(i),t.length>=a)break}if(t.length<a){for(const i of l)if(n(i),t.length>=a)break}return t}export{l as a,g as b,ee as c,X as d,Z as e,_ as g,ae as r,te as t};

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.