# authorship: generated by API Evangelist tooling. Stamped 2026-08-18 # on the file's own generator header (roadmap#64). An unmarked file is # NOT assumed to be ours -- absence of evidence was never stamped. method: generated vocabulary: name: Nhost Vocabulary description: >- Terms and concepts used across the Nhost backend-as-a-service platform, covering authentication, storage, GraphQL, and serverless functions. url: https://nhost.io/ version: "1.0.0" terms: # Core Platform - term: Project description: >- An isolated Nhost environment with its own PostgreSQL database, authentication service, storage bucket, serverless functions, and GraphQL endpoint. type: Resource - term: Subdomain description: >- The unique identifier for an Nhost project used as the hostname prefix for all service endpoints (e.g., {subdomain}.auth.{region}.nhost.run). type: Identifier - term: Region description: >- The geographic data-center region where an Nhost project is hosted (e.g., eu-central-1, us-east-1). type: Attribute # Authentication - term: Session description: >- An authenticated user session containing an access token (JWT), refresh token, access token expiry, and the associated user profile. type: Resource schema: Session - term: AccessToken description: >- A short-lived JSON Web Token (JWT) authorizing API requests. Included in the Authorization header as a Bearer token. type: Token - term: RefreshToken description: >- A long-lived opaque token used to obtain new access tokens without re-authentication. type: Token - term: User description: >- An authenticated user account with email, display name, avatar URL, roles, metadata, and locale. Managed by the Nhost Auth service. type: Resource schema: User - term: PersonalAccessToken description: >- A long-lived token generated by a user for programmatic or CI/CD access, scoped to the creating user's permissions. type: Token schema: CreatePATRequest - term: SignInEmailPassword description: >- Authentication method where a user provides email and password credentials to receive a session with access and refresh tokens. type: Operation schema: SignInEmailPasswordRequest - term: SignInPasswordlessEmail description: >- Passwordless authentication via a magic link sent to the user's email address. type: Operation schema: SignInPasswordlessEmailRequest - term: SignInIdToken description: >- Authentication using an ID token from a third-party OAuth2 provider such as Google or Apple. type: Operation schema: SignInIdTokenRequest - term: SignUpEmailPassword description: >- User registration using email and password. Returns a session if email verification is not required. type: Operation schema: SignUpEmailPasswordRequest - term: WebAuthn description: >- FIDO2/WebAuthn passwordless authentication using hardware security keys or platform authenticators (biometrics). Supported for sign-up and sign-in. type: AuthMethod - term: MFA description: >- Multi-Factor Authentication. Nhost supports TOTP-based MFA as a second factor after primary authentication. type: SecurityFeature - term: OTP description: >- One-Time Password sent via email or SMS for passwordless authentication. type: AuthMethod - term: JWK description: >- JSON Web Key used to verify JWT signatures. Available from the /.well-known/jwks.json endpoint of the Auth service. type: CryptographicKey schema: JWK - term: OAuthProvider description: >- An external identity provider (e.g., Google, GitHub, Apple, Discord) used for OAuth2-based sign-in via the Nhost Auth service. type: IntegrationProvider # Storage - term: FileMetadata description: >- Metadata record for an uploaded file including id, name, size, MIME type, bucket ID, etag, created at, and updated at timestamps. type: Resource schema: FileMetadata - term: FileSummary description: >- A summary representation of uploaded file metadata returned in list operations. type: Resource schema: FileSummary - term: Bucket description: >- A logical container for files within Nhost Storage, analogous to an S3 bucket. Each project has a default bucket. type: Resource - term: PresignedURL description: >- A time-limited, pre-authorized URL granting access to a file without requiring an Authorization header. Used for direct file downloads. type: URL schema: PresignedURLResponse - term: ImageTransformation description: >- Server-side image resizing and format conversion applied when serving images from Nhost Storage via query parameters (width, height, quality, format). type: Feature # GraphQL / Hasura - term: GraphQLEndpoint description: >- The Hasura-powered GraphQL endpoint auto-generated from the PostgreSQL schema. Supports queries, mutations, and real-time subscriptions. type: Endpoint - term: Subscription description: >- A real-time GraphQL operation that pushes data updates to connected clients over a WebSocket connection. type: GraphQLOperation - term: HasuraMetadata description: >- Configuration applied to Hasura defining table permissions, relationships, remote schemas, event triggers, and actions. type: Configuration - term: RowLevelPermission description: >- A Hasura permission rule restricting which database rows a given role can read, insert, update, or delete. type: AccessControl # Serverless Functions - term: ServerlessFunction description: >- A JavaScript or TypeScript file deployed as an HTTP endpoint under /v1/functions/. Auto-deployed from the functions/ directory via GitHub integration. type: Resource - term: EventTrigger description: >- A Hasura mechanism that fires an HTTP webhook (typically a serverless function) when database insert, update, or delete events occur. type: Trigger # AI - term: Assistant description: >- An AI assistant managed by the Nhost AI service. Configured with a model, system prompt, and vector store for RAG-based responses. type: Resource - term: AutoEmbedding description: >- Automatic generation of vector embeddings from database column content, enabling semantic search without manual embedding pipelines. type: Feature - term: Session_AI description: >- A conversation session with an Nhost AI assistant maintaining message history and context. type: Resource note: Distinct from the authentication Session resource. # Error Handling - term: ErrorResponse description: >- Standard error envelope returned by Nhost REST services containing a status code, message, and optional error details. type: Schema schema: ErrorResponse