Canonical definitions of the 26 security, auth, payments, and data-layer terms used across the SecureStartKit blog, free tools, and docs. Each entry links to the cluster pillar that goes deep on the topic.
JWT lifecycle, OAuth/PKCE, magic links, MFA, and the Supabase Auth surface.
Server Actions, Zod validation, security headers, CORS, and rate limiting.
Row Level Security, anon vs service_role, and backend-only data access.
Stripe webhook signature verification and idempotency patterns.
OWASP-cataloged classes: CSRF, XSS, IDOR, and how they map to Next.js + Supabase.
Vibe-coding security failures and the migration path to production-ready architecture.