Skip to content
>devspeak
← glossary
level 7Architecture

Middleware

also: middlewares

Code that runs in the middle of every request, before your main code handles it, to do a shared job like checking the user is logged in.

a bit more technical

A function in the request pipeline that runs between an incoming request and the route handler, and sometimes on the response. Each can inspect or change the request, stop it, or pass it on. Common uses: authentication, logging, CORS headers, rate limiting.

picture it

Airport security. Every passenger passes through it on the way to any gate. It checks everyone the same way and can stop someone before they reach their plane.

why it matters

Middleware affects every request that passes through it. A small agent change there can log everyone out, block the whole app, or quietly expose private pages. Treat middleware edits as high-impact.

what your agent might say
agent
I added auth middleware to all /api/admin routes. Requests without a valid session now get a 401 before they reach the handler.
how you might use it
you → your agent
Add logging middleware that records the method, path and response time of every API request. Don't log what's inside requests, since that can contain passwords.
common mistake

Thinking middleware is a separate program or server. It's usually just code in your backend that runs, in order, before your routes.

builds on