The Glossary of Express.js
Core Concepts
Express — A minimalist, unopinionated web framework for Node.js that sits directly on top of the core http module, adding routing, middleware, and request/response conveniences without imposing much structure of its own.
Application Object (app) — The central object created by calling express(), used to configure routes, middleware, and settings, and ultimately to start the server.
Request Object (req) — An enhanced version of Node's native HTTP request object, representing the incoming HTTP request, carrying data like URL parameters, query strings, headers, and the request body.
Response Object (res) — An enhanced version of Node's native HTTP response object, providing convenience methods for sending back JSON, HTML, files, redirects, and status codes.
app.listen() — The method that binds the Express application to a port and starts it listening for incoming connections, the final step in getting a server running.
Unopinionated — The design philosophy that distinguishes Express from more structured frameworks: it doesn't prescribe folder structure, an ORM, a templating engine, or an architecture, leaving those decisions to the developer.
Routing
Route — A definition pairing an HTTP method and a URL path with a handler function that runs when a matching request arrives, the fundamental unit of an Express application.
HTTP Method Functions (.get(), .post(), .put(), .delete(), etc.) — Methods on the app (or a Router) object, each corresponding to an HTTP verb, used to register a handler for requests of that method and path.
Route Parameters — Named segments in a route path prefixed with a colon (like /users/:id), whose matched values are exposed on req.params.
Query String (req.query) — The key-value data parsed from a URL's query string (the part after ?), made available as a plain object on the request.
Wildcard / Pattern Matching — Express's support for special characters like * in route paths to match arbitrary sub-paths, useful for catch-all routes or matching flexible URL patterns.
express.Router() — A mini, mountable Express application used to group related routes and their middleware into a self-contained, modular unit, typically exported from its own file.
Route Chaining (app.route()) — A method that lets multiple HTTP verb handlers for the same path be chained together in a single, more concise definition rather than repeated separately.
Route Handler / Controller — The function (or array of functions) that ultimately handles a matched request, receiving req, res, and, in middleware, next as arguments.
Middleware
Middleware — A function with access to req, res, and a next function, able to run code, modify the request or response, end the request-response cycle, or pass control to the next middleware in the stack; the core architectural idea Express is built around.
next() — The function passed to every middleware, which, when called, hands control to the next matching middleware or route handler; a request hangs indefinitely if no middleware calls it or sends a response.
Application-Level Middleware — Middleware bound to the app object via app.use() or an HTTP method function, running for all or a subset of routes depending on how it's mounted.
Router-Level Middleware — Middleware bound to an express.Router() instance instead of the main app, scoped to only the routes defined on that router.
Error-Handling Middleware — A special middleware function distinguished by taking four arguments (err, req, res, next), used to catch and respond to errors thrown or passed via next(err) anywhere earlier in the chain.
Built-in Middleware — Middleware shipped with Express itself, most notably express.json() and express.urlencoded() for parsing request bodies, and express.static() for serving static files.
Third-Party Middleware — Middleware published as separate npm packages that plug into Express's middleware system, such as cors, helmet, morgan, and cookie-parser.
Middleware Stack — The ordered sequence of middleware functions registered on an application; Express executes them in the order they were added, which makes registration order functionally significant.
express.static() — The built-in middleware for serving static files (images, CSS, client-side JavaScript) directly from a specified directory, without needing a custom route for each file.
Request & Response Handling
req.params — An object holding values extracted from named route parameters in the URL path.
req.body — An object holding the parsed request body, populated by body-parsing middleware like express.json(); undefined or empty until such middleware is applied.
req.headers — An object exposing all HTTP headers sent with the incoming request.
res.send() — A general-purpose response method that sends a response body of virtually any type (string, object, buffer), automatically setting an appropriate Content-Type header.
res.json() — A response method that serializes a JavaScript object or array to JSON and sends it with the Content-Type header set accordingly.
res.status() — A response method for explicitly setting the HTTP status code of the response, commonly chained with .send() or .json().
res.redirect() — A response method that sends a redirect response, instructing the client's browser to navigate to a different URL.
res.render() — A response method that renders a configured view template (via a template engine) into HTML and sends it as the response.
Template Engines (EJS, Pug, Handlebars) — Libraries that let server-rendered HTML be generated from templates with embedded logic and variables, integrated into Express via app.set('view engine', ...).
Content Negotiation — Express's mechanism (via methods like req.accepts()) for inspecting a request's Accept header and responding with the format the client actually wants.
Error Handling & Validation
Synchronous vs. Asynchronous Error Handling — Express automatically catches errors thrown synchronously inside route handlers, but errors from asynchronous code (Promises, callbacks) must be explicitly passed to next(err) in older Express versions to reach error-handling middleware.
next(err) — The convention for signaling an error from within middleware or a route handler, skipping all remaining non-error middleware and jumping straight to the nearest error-handling middleware.
Global Error Handler — A single error-handling middleware, typically defined last in the stack, that catches errors from anywhere earlier in the application and formats a consistent error response.
Validation Middleware (express-validator, Joi, Zod) — Third-party libraries commonly used with Express to validate and sanitize incoming request data before it reaches business logic, often implemented as middleware.
404 Handler — A catch-all middleware placed after all defined routes to handle requests that didn't match any route, since Express doesn't generate a custom 404 response automatically.
Security & Production Concerns
Helmet — A widely used middleware package that sets a range of security-related HTTP headers by default, mitigating common web vulnerabilities with minimal configuration.
CORS (Cross-Origin Resource Sharing) — A browser security mechanism controlling which origins can make requests to a server; the cors middleware package configures the necessary response headers for Express APIs consumed by browser-based clients on other origins.
Rate Limiting — The practice of restricting how many requests a client can make in a given time window, commonly added to Express apps via middleware like express-rate-limit to mitigate abuse.
Environment-Based Configuration — The practice of varying an Express app's behavior (logging verbosity, error detail, database connections) based on process.env.NODE_ENV, distinguishing development from production behavior.
Session Management (express-session) — Middleware for maintaining stateful user sessions across requests using cookies and server-side (or store-backed) session data, commonly used for traditional authentication flows.
Compression — Middleware (compression) that gzips response bodies before sending them, reducing payload size and improving load times for larger responses.
Ecosystem & Related Tools
Morgan — A widely used HTTP request logging middleware for Express, printing details about each incoming request to the console or a log file.
Passport.js — An authentication middleware for Node.js commonly paired with Express, supporting a wide range of authentication strategies (local username/password, OAuth, JWT) through a pluggable "strategy" system.
MVC Pattern (in Express apps) — A common, though unenforced, convention for structuring larger Express applications into Models (data), Views (templates or API responses), and Controllers (route handler logic).
REST API — The dominant architectural style Express is used to build, structuring an API around resources, HTTP methods, and stateless requests — Express's flexibility makes it a frequent default choice for REST backends.
Fastify — A newer, performance-oriented alternative to Express, offering similar middleware-based ergonomics with a stronger emphasis on speed and built-in schema validation.
NestJS — A more structured, TypeScript-first framework that, in its default configuration, actually runs on top of Express under the hood (or optionally Fastify), adding decorators, modules, and dependency injection on top.
Taken together, this glossary traces Express's enduring appeal back to a single decision made early on: instead of prescribing an architecture, it standardized on one simple idea — a chain of functions, each with the power to inspect a request, modify it, or pass it along — and let everything else, from body parsing to authentication to templating, be built as middleware on top. That same simplicity is why Express still sits, often invisibly, underneath the Node.js core it wraps and even inside newer, more structured frameworks like NestJS that were built, in part, as a reaction to how little structure Express actually enforces.
*written with Claude Sonnet 5