Skip to content

PWA Glossary

This glossary defines the vocabulary of Progressive Web Apps, from app shell to Workbox, in the precise sense that the specifications, browser engineers and the rest of this site use it. Many PWA terms are overloaded: "scope" means two different things for the manifest and for a service worker, "install" means one thing to a browser and another to a service worker, and "cache" can mean at least three separate layers. Each entry gives a short, exact definition, the API surface or spec it comes from where one exists, the browser support caveat that matters most, and a link to the page that covers it in depth.

Key takeaways

  • Terms are alphabetical under letter headings. Use the letter bar below, or your browser's find-in-page, to jump to a term.
  • Where a word has two meanings (for example scope, install, client, cache), the glossary lists each meaning separately and says which API it belongs to.
  • Support caveats in the definitions reflect the state of browsers in September 2026. Chromium-only means Chrome, Edge, Samsung Internet, Opera and other Blink browsers, not Safari or Firefox.
  • Every entry links to the page that explains the mechanism, code and edge cases. The glossary defines; the linked page teaches.
  • Abbreviations used across the site (PWA, CSP, VAPID, TWA, OPFS, INP and others) show their expansion on hover everywhere, and are expanded here with context.

Jump to: A · B · C · D · E · F · G · H · I · K · L · M · N · O · P · Q · R · S · T · U · V · W

A

aes128gcm
The HTTP content coding defined in RFC 8188 ("Encrypted Content-Encoding for HTTP") and required by RFC 8291 for Web Push payloads. The push message body is a single encrypted record with a header carrying the salt, record size and the sender's ephemeral public key. Every current push service expects it; the older aesgcm draft coding is obsolete. See The Web Push Protocol.
Activate event
The activate event fires on a service worker's global scope once it becomes the registration's active worker, after the previous version has released all its clients (or after skipWaiting()). It is the correct place to delete old caches and enable navigation preload. Activation cannot fail, and fetch events from controlled pages are queued until it finishes, so keep the handler short. See Lifecycle.
Active worker
The service worker version in a registration's active slot (registration.active). Only the active worker receives functional events such as fetch, push, sync and notificationclick. "Active" is a lifecycle state, not a running state: an active worker is stopped when idle and restarted on the next event. See Lifecycle.
Add to Dock
Safari's installation command on macOS Sonoma and later (Safari 17+), under File > Add to Dock. It works for any site, with or without a manifest, and creates a web app with its own window, storage and push subscription. Safari copies the site's cookies into the new app but no other storage. See Desktop Platforms.
Add to Home Screen
The manual installation path on iOS and iPadOS, reached from the Share sheet in Safari and, since iOS 16.4, in other iOS browsers. Since iOS and iPadOS 26, every site added this way opens as a web app by default (no manifest required) unless the user switches off Open as Web App. Since iOS 17.2, Safari copies the site's cookies into the new web app, but not localStorage, IndexedDB or caches; behavior when another iOS browser creates the app isn't documented. On Android, the same label names Chrome's menu entry, which installs a WebAPK when the site qualifies. See Installation by Platform.
App badge
A small count or dot drawn on an installed app's icon in the taskbar, Dock or Home Screen, set with navigator.setAppBadge(count) and cleared with navigator.clearAppBadge() (both also available in the service worker). Supported by Chromium on Windows, macOS and ChromeOS (since Chrome 152, installed apps on macOS need notification permission for the badge to appear), by Safari 17 web apps on macOS and by Home Screen web apps on iOS 16.4+. On Android the call resolves but does nothing. See Badging API.
App shell
The minimal HTML, CSS and JavaScript needed to render an application's user interface frame (header, navigation, layout) without its data. Precaching the shell lets an installed app paint instantly and offline, then fill in content from the network or IndexedDB. The model fits single-page apps best; multi-page apps usually cache full pages instead. See App Shell Model.
App shortcuts
Deep links declared in the manifest's shortcuts member that appear in the app icon's context menu (long-press on Android, right-click on Windows taskbar, Dock menu on macOS). Each entry has name, url and optional short_name, description and icons. Chromium supports them on Android and desktop; Safari 17.4+ supports them for Dock web apps on macOS. See App Shortcuts.
appinstalled
An event fired at window in Chromium browsers after a successful installation, whether the user installed from your custom button or from the browser's own UI. On Android it fires when the user accepts, before the WebAPK is minted. Safari and Firefox never fire it. See Install Prompts & Custom UI.
apple-touch-icon
A <link rel="apple-touch-icon"> element that names the icon iOS and iPadOS use for a Home Screen web app. Safari prefers it over manifest icons when both exist, and it is the only way to control the icon's exact pixels on older iOS releases. Keep it even if your manifest is complete. See Icons & Maskable Icons.
Application server key
The public half of your VAPID key pair, passed to pushManager.subscribe({ applicationServerKey }) as a 65-byte uncompressed P-256 point (usually as a URL-safe Base64 string or a Uint8Array). The subscription is bound to this key, so rotating keys requires every browser to resubscribe. See Push Notifications.

B

Back/forward cache (bfcache)
A browser optimization that keeps a whole page, including its JavaScript heap, in memory when the user navigates away, and restores it instantly on Back or Forward. A restore fires pageshow with event.persisted === true and never consults the service worker. Chromium evicts a page from bfcache when a new service worker takes control of it via clients.claim(), or when the worker postMessage()s to it. See HTTP Caching & Service Workers.
Background Fetch
A Chromium-only API (registration.backgroundFetch.fetch(id, requests, options)) that hands large downloads to the browser's download manager, shows progress UI, and reports the result to the service worker through backgroundfetchsuccess, backgroundfetchfail or backgroundfetchabort. Chromium engineers posted an intent to deprecate it in November 2025 because of very low usage; according to Chrome Platform Status that effort "did not reach consensus for removal", so the API stays shipped and is being tightened instead (Chrome Platform Status lists CORS enforcement from Chrome 154). See Background Fetch.
Background Sync
A Chromium-only API (registration.sync.register(tag)) that asks the browser to fire a sync event in the service worker when it next has connectivity, even if the page has closed. It carries only a tag; your data lives in an IndexedDB outbox. Failed attempts are retried a limited number of times, with event.lastChance set on the final one. See Background Sync.
background_color
A manifest member that sets the color of the window before the app's stylesheet loads. Chromium on Android combines it with the app name and icon to generate the launch splash screen. Safari on iOS ignores it for splash screens. See Splash Screens & Theming.
beforeinstallprompt
A Chromium-only event fired at window when a page becomes eligible for install promotion. Calling preventDefault() suppresses the browser's automatic install message; saving the event and later calling its prompt() method from a user gesture opens the install dialog. prompt() resolves with { outcome, platform }. See Install Prompts & Custom UI.
Blink
The rendering engine of the Chromium project, used by Chrome, Edge, Samsung Internet, Opera, Brave, Vivaldi and Android WebView. Most PWA capabilities beyond the core (install prompts, WebAPKs, background APIs, OS integration members) ship in Blink first and often only there. See Platform Support.
BroadcastChannel
A same-origin messaging primitive (new BroadcastChannel(name)) that delivers messages to every window, worker and service worker of the origin that opened a channel with the same name. It is the simplest way for a service worker to announce an update or a cache change to all tabs, but unlike client.postMessage() it can't target one client. See Messaging & the Clients API.
Browser (display mode)
The browser value of the manifest's display member: the app opens in an ordinary browser tab. It is the last step of the display-mode fallback chain. A manifest whose effective display mode is browser does not pass Chromium's install promotion criteria. See Display Modes.
Bubblewrap
A Node.js command-line tool and library from Google Chrome Labs that generates and builds an Android project wrapping a PWA in a Trusted Web Activity, ready for upload to Google Play. It reads your web app manifest, generates the Android manifest, icons and Digital Asset Links configuration, and signs the build. PWABuilder uses it for its Android packages. See Trusted Web Activity.

C

Cache API
The programmatic request/response store exposed as the global caches (a CacheStorage) in windows and workers. caches.open(name) returns a Cache whose put(), add(), addAll(), match(), matchAll(), delete() and keys() methods store and retrieve Response objects keyed by Request. Entries never expire on their own and Cache-Control headers are ignored. See Cache Storage API.
Cache busting
Changing a resource's URL whenever its content changes, usually by putting a content hash in the file name (app.3f9a1c.js), so caches can keep each URL forever. It is the prerequisite for safe Cache-Control: max-age=31536000, immutable headers and for precaching without revision metadata. See HTTP Caching & Service Workers.
Cache-first
A caching strategy that answers from Cache Storage when a match exists and only goes to the network (optionally caching the result) on a miss. It suits immutable, fingerprinted assets and fonts. Applied to HTML or unversioned URLs, it serves stale content indefinitely. See Caching Strategies.
Cache Storage
The per-origin (per-storage key) collection of named Cache objects managed by the Cache API. It is shared by every page and service worker of the origin, counts against the origin's quota, and is evicted together with IndexedDB and OPFS under storage pressure. See Cache Storage API.
Capabilities project
See Project Fugu.
Clear-Site-Data
A response header that tells the browser to delete the origin's data: "cache", "cookies", "storage" (which includes IndexedDB, Cache Storage, localStorage and service worker registrations), "executionContexts" (reload open documents) or "*". It is only honored on secure responses from the network, never on a response a service worker constructs. Send it on the sign-out response to remove offline copies of personal data, or on the service worker script as a last-resort reset. See Service Worker Security.
Client
In the Service Workers specification, an environment a service worker can see and control: a window (WindowClient), a dedicated worker or a shared worker. A Client exposes id, url, type, frameType and postMessage(); a WindowClient adds focused, visibilityState, focus() and navigate(). Obtain clients with clients.get() and clients.matchAll(). See Messaging & the Clients API.
clients.claim()
A method a service worker calls, usually in activate, to become the controller of every in-scope client that it doesn't already control, including the first page that registered it. It fires controllerchange in those pages. Claiming a page with a new version mid-session can cause version skew, and it evicts pages from Chromium's bfcache. See Lifecycle.
clients.openWindow()
A service worker method that opens a new top-level window at a URL and resolves with its WindowClient (or null for a cross-origin URL the worker can't see). It is only allowed while the worker handles a user interaction, in practice a notificationclick, and rejects with an InvalidAccessError DOMException otherwise. Try clients.matchAll({ type: "window" }) and client.focus() first, so a click doesn't open a duplicate window. See Messaging & the Clients API.
Content Security Policy
A response header (Content-Security-Policy) that restricts which sources a document may load scripts, styles, frames, workers and manifests from. The worker-src directive (falling back to child-src, script-src and default-src) governs service worker registration, and manifest-src governs the manifest fetch. A service worker's own script response can carry its own policy. See Content Security Policy.
Controller
The active service worker that handles fetches for a given page, exposed as navigator.serviceWorker.controller. It is null on the very first visit (until clients.claim()), after a hard reload with Shift held, and for pages outside every registered scope. A page keeps the same controller for its lifetime unless a newer worker claims it. See Registration & Scope.
controllerchange
An event fired at navigator.serviceWorker when the page's controller changes, either through clients.claim() or because a waiting worker took over after skipWaiting(). Update flows listen for it to reload the page exactly once after the user accepts a new version. See Updating Service Workers.
Core Web Vitals
Google's three user-centric performance metrics: Largest Contentful Paint (good at 2.5 s or less), Interaction to Next Paint (200 ms or less) and Cumulative Layout Shift (0.1 or less), each assessed at the 75th percentile of page loads. INP replaced First Input Delay on March 12, 2024. See Core Web Vitals.
CORS
Cross-Origin Resource Sharing, the Fetch mechanism by which a server opts in to letting another origin read its responses (Access-Control-Allow-Origin and related headers). For PWAs it matters because a CORS response is readable and cacheable at its true size, while a no-cors cross-origin fetch yields an opaque response. See Cache Storage API.
Crafted app
Chromium's internal term for an installed web app whose name, icons, scope and display mode come from a valid manifest, as opposed to a "diy" or shortcut-style app built from the page title and favicon. Only crafted apps get OS integration such as file handlers, protocol handlers and shortcuts. See Installability Criteria.
CrUX
The Chrome User Experience Report, Google's public dataset of real-user performance measurements from opted-in Chrome users on Android and desktop. It is the source of the field data in PageSpeed Insights and Search Console. It contains no Safari or iOS data and nothing from pages that aren't public and sufficiently popular. See Measuring Performance.

D

Declarative Web Push
A WebKit extension to Web Push in which the push payload is JSON (with the key "web_push": 8030) that describes the notification, so the browser can show it without running a service worker. Shipped in Safari 18.4 on iOS and iPadOS and Safari 18.5 on macOS. Payloads can fall back to an ordinary service worker push handler in other browsers. See Web Push on iOS & Safari.
Digital Asset Links
A Google protocol that proves a website and an Android app belong to the same developer, via a JSON statement file at /.well-known/assetlinks.json listing the app's package name and signing-certificate SHA-256 fingerprint. A Trusted Web Activity without a valid statement falls back to showing browser UI (a Custom Tab with a URL bar). See Trusted Web Activity.
Digital Markets Act
The EU regulation under which Apple has, since iOS 17.4 (March 2024), allowed alternative browser engines for browser apps in the EU. Early iOS 17.4 betas removed Home Screen web apps in the EU; Apple reversed that before release, and Home Screen web apps remain built on WebKit. See iOS & iPadOS.
display
The manifest member that requests how an installed app is presented: fullscreen, standalone, minimal-ui or browser. Browsers that can't honor the requested mode fall back down that chain, never up. Style against the applied mode with the display-mode media feature, not against what the manifest asked for. See Display Modes.
Display mode
The presentation actually applied to a document: one of the four standard modes, or an extension such as window-controls-overlay, tabbed or unframed, queryable with @media (display-mode: standalone) or matchMedia(). It can change at runtime, for example when a desktop user moves an app window into a browser tab. See Display Modes.
display_override
A manifest member (Chromium 89 and later) holding an ordered list of display modes to try before display. It is the only place where the extension modes window-controls-overlay, tabbed and unframed are valid. Unknown entries are dropped silently. See Display Modes.

E

Engagement
Chromium's per-origin site engagement score, derived from how often and how actively a user uses a site. It gates or scales several PWA features: the Periodic Background Sync interval and whether navigator.storage.persist() is granted silently. Current Chromium has no engagement requirement before beforeinstallprompt; the old rule (a click plus 30 seconds on the site) is historical. You can inspect it at chrome://site-engagement. See Periodic Background Sync.
Eviction
The browser deleting an origin's stored data (IndexedDB, Cache Storage, OPFS, service worker registrations) to reclaim disk space. Best-effort data is evicted one storage bucket at a time, least recently used first; persistent data only with the user's involvement. Safari additionally deletes script-writable storage after seven days of Safari use without user interaction, a rule that exempts Home Screen web apps. See Storage Quotas & Persistence.
ExtendableEvent
The base interface of service worker events (install, activate, fetch, push, sync, notificationclick and others) whose waitUntil(promise) method keeps the worker alive and, for lifecycle events, determines success or failure. FetchEvent, PushEvent, SyncEvent and ExtendableMessageEvent all inherit from it. See Lifecycle.

F

Fetch event
The FetchEvent dispatched to the controlling service worker for every request a controlled client makes, and for navigations into its scope. It exposes request, clientId, resultingClientId, replacesClientId, preloadResponse and handled, plus respondWith() and waitUntil(). If no handler calls respondWith() synchronously, the browser performs the request normally. See Handling Fetch Events.
File Handling
A Chromium desktop capability (Chrome 102+) in which the manifest's file_handlers member registers an installed app with the operating system as a handler for given MIME types and extensions. Opened files arrive through window.launchQueue.setConsumer() as FileSystemFileHandle objects. Not available on Android, Safari or Firefox. See File Handling.
File System Access API
The API behind showOpenFilePicker(), showSaveFilePicker() and showDirectoryPicker(), which returns handles that can read and write files on the user's disk with permission. The pickers are Chromium-only (desktop, and Android from Chrome 132); the handle interfaces are also the foundation of the cross-browser OPFS. See File System Access.
Fugu
See Project Fugu.
Fullscreen (display mode)
The fullscreen value of the manifest's display member, which hides all browser and system chrome. Chromium honors it on Android; desktop Chromium falls back to standalone, and iOS opens it as standalone. Games and media apps use it; most apps should use standalone and the Fullscreen API for specific views. See Display Modes.
Functional event
The Service Workers specification's term for events other than install and activate that wake a service worker to do work: fetch, push, sync, periodicsync, notificationclick, notificationclose, backgroundfetch* and pushsubscriptionchange. Only the active worker receives them, and a functional event arriving more than 24 hours after the last update check triggers a new one. See Updating Service Workers.

G

Gecko
Mozilla's browser engine, used by Firefox on desktop and Android. It implements service workers, the Cache API, IndexedDB, Push and Notifications, but not the Chromium background APIs or most manifest integration members. Firefox on iOS uses WebKit instead. See Platform Support.
getInstalledRelatedApps()
A Chromium method (navigator.getInstalledRelatedApps()) that resolves with the related native apps or PWAs, listed in the manifest's related_applications, that are installed on the device and that point back to your site. It is the main tool for detecting from a browser tab that your PWA is already installed. On Android it detects Play apps from Chrome 80 and web apps from 84; on desktop it detects Windows apps from Chrome 85 and installed web apps from Chrome 140. See Detecting Installed Apps.

H

Home Screen web app
Apple's term for a site added to the Home Screen on iOS or iPadOS and opened as a web app. It runs in its own WebKit process with storage, permissions and push subscription separate from Safari's, and it is the only context on iOS where Web Push, the Notification interface and app badging exist. See iOS & iPadOS.
HTTP cache
The browser's standard HTTP cache governed by Cache-Control, ETag and related headers. It is independent of Cache Storage: responses a service worker returns via respondWith() never enter the page's HTTP cache, but every fetch() the worker makes can be answered from it. Misconfigured max-age on unversioned URLs is a common source of stale precaches. See HTTP Caching & Service Workers.

I

Icon purpose
The manifest icon property purpose, a space-separated set of any (the default), maskable and monochrome. An icon with only unrecognized purposes is dropped. Ship separate files for any and maskable, because a single file can't be correct for both. See Icons & Maskable Icons.
id (manifest)
The manifest member that gives an installed app its permanent identity: id resolved against the origin of start_url, fragment removed. If it is absent or invalid, the identity is start_url. Browsers use it to recognize the same app across manifest changes; a different id is a different app. See App Identity & Updates.
importScripts()
The synchronous function that loads additional classic scripts into a service worker's global scope. It can only fetch new scripts during the first evaluation and install; later calls must hit scripts already stored with the worker. Imported scripts are part of the byte-for-byte update check. Module workers (type: "module") use static import instead, and dynamic import() is disallowed in service workers. See Advanced Techniques.
IndexedDB
The transactional, indexed object store available in windows and workers, and the right place for structured app data, outbox queues and anything a service worker needs to read. Its API is event-based; most apps use a small promise wrapper. It shares the origin's quota with Cache Storage and OPFS. See IndexedDB.
Install event
The first lifecycle event a new service worker version receives, once per version. Calling event.waitUntil(promise) with a precache operation keeps the worker in the installing state; if the promise rejects, the version becomes redundant and the old version keeps running. Not to be confused with installing the app. See Lifecycle.
Install prompt
The browser dialog that confirms installing a web app. In Chromium you can open it from your own UI with a saved beforeinstallprompt event's prompt(); the browser also offers it through the address bar icon, the menu and, on Android, an install message. Safari and Firefox have no programmatic prompt. See Install Prompts & Custom UI.
Installability criteria
The conditions under which a browser promotes installation (install icon, banners, beforeinstallprompt) and installs a manifest-driven app rather than a shortcut. In Chromium: a secure context, a linked manifest with name or short_name, start_url, an app-like display, a purpose: "any" icon of at least 144 px, no prefer_related_applications: true, and the app not already installed in the profile. Chrome dropped the service worker (fetch handler) requirement for installing from the browser menu in Chrome 108 on Android and 112 on desktop; the automatic prompt still required a fetch handler at that time, and current Chromium's promotion pipeline has no service worker check. window-controls-overlay is not a valid display value (the manifest is then not installable); it belongs in display_override. Safari has no criteria. See Installability Criteria.
Installing worker
The service worker version in a registration's installing slot while its install event runs. When installation succeeds it moves to waiting (or straight to active if there is no active worker or it called skipWaiting()). See Lifecycle.
Intelligent Tracking Prevention
WebKit's set of privacy protections, including third-party cookie blocking, partitioned storage and the seven-day cap on script-writable storage for sites the user hasn't interacted with. Home Screen web apps keep their own days-of-use counter and are not expected to lose data under this rule. See Privacy & Storage Partitioning.
Isolated Web App
A Chromium packaging model in which an app is distributed as a signed Web Bundle and served from an isolated-app:// origin derived from its signing key, with a fixed strict CSP, Trusted Types and cross-origin isolation. In exchange it can use high-trust APIs such as Direct Sockets and Controlled Frame. As of September 2026 IWAs aren't available to the general public: administrators install them by policy on managed ChromeOS devices (and, per Google's enterprise release notes, managed Chrome on Windows from Chrome 150), and developers test them with a developer-mode flag. See Isolated Web Apps.

K

Kill switch
A replacement service worker you deploy at the same URL to neutralize a broken one: it skips waiting, deletes caches, unregisters itself and optionally reloads its clients. Recovery works because the browser's update request for the worker script is never intercepted by a service worker. Clear-Site-Data: "storage" on the worker's update response is the server-side equivalent. See Pitfalls & Anti-Patterns.

L

launch_handler
A Chromium manifest member (Chrome 110+) whose client_mode (auto, navigate-new, navigate-existing or focus-existing) decides whether launching the app opens a new window or reuses an existing one. With focus-existing, the target URL is delivered to window.launchQueue instead of navigating. See Protocol Handlers & Launch Handling.
launchQueue
The window.launchQueue object through which an installed app receives launch data: files from File Handling, and target URLs when launch_handler doesn't navigate. You register a consumer with launchQueue.setConsumer(params => …), which receives a LaunchParams object with targetURL and files. See File Handling.
Lighthouse
Google's open-source auditing tool, built into Chrome DevTools. Lighthouse 12.0 (April 2024) removed the PWA category, so there is no longer a Lighthouse "PWA score"; installability is checked in DevTools' Application panel instead. Performance, accessibility, best practices and SEO audits remain. See Lighthouse & Auditing.
Link capturing
The behavior where a link to a URL inside an installed app's scope, clicked elsewhere in the OS or browser, opens in the app instead of a tab. On Android, WebAPKs capture links through intent filters generated from scope. Desktop Chromium on Windows, macOS and Linux captures links into installed apps by default: from Chrome 138 for apps that declare launch_handler.client_mode and from Chrome 140 for all apps (rolled out in stages from Chrome 134). It applies only to navigations that would open a new browsing context (a new tab or window, or a link from another app). On ChromeOS it is available but off by default per app. launch_handler decides whether the app opens a new window or reuses one. Safari 18 uses the manifest scope for link handling in Dock web apps on macOS. See Protocol Handlers & Launch Handling.
Localhost
http://localhost, http://127.0.0.1 and http://[::1] are treated as potentially trustworthy origins, so service workers, push and other secure-context APIs work there during development without TLS. Any other hostname, including LAN IP addresses, needs HTTPS. See Secure context.

M

Manifest
See Web App Manifest.
manifest-src
The CSP directive that controls which URLs a document may fetch its web app manifest from, falling back to default-src. A blocked manifest fetch looks to the browser exactly like a page with no manifest, so installability silently fails. See Content Security Policy.
Maskable icon
An icon declared with purpose: "maskable": full-bleed and opaque, with all important content inside a centered safe-zone circle whose radius is 40% of the icon's width. Launchers crop it to their own shape (circle, squircle, rounded square) without adding a white background. Android, ChromeOS and Chromium on macOS prefer maskable icons; Safari never uses them. See Icons & Maskable Icons.
MessageChannel
A pair of entangled MessagePorts used for request/response messaging between a page and a service worker: the page sends one port with postMessage(data, [port2]), and the worker replies on it. It gives each request a private reply path, unlike BroadcastChannel. See Messaging & the Clients API.
Minimal UI
The minimal-ui display mode: an app window with a small set of navigation controls (typically back and reload). Desktop Chromium also uses it when a manifest says browser for an installed app. Safari does not support it. See Display Modes.
Monochrome icon
An icon with purpose: "monochrome" whose alpha channel alone is used; the platform supplies the color, for example for themed icons or notification badges. Details must be cut out as transparency. See Icons & Maskable Icons.

N

Navigation fallback
The single-page-app pattern of answering navigation requests for app routes with one cached HTML document (the app shell, often /index.html), so any deep link opens offline and the client-side router renders the view. It needs an allowlist or denylist so that server-only URLs such as /api/, /auth/callback, /sitemap.xml and file downloads still go to the network. Workbox implements it with NavigationRoute or the navigateFallback build option. See SPA vs MPA PWAs.
Navigation preload
A service worker feature (registration.navigationPreload.enable()) that starts the network request for a navigation in parallel with booting the worker, and hands the response to the fetch handler as event.preloadResponse. The request carries a Service-Worker-Navigation-Preload header (default value true). Supported in Chromium, Firefox and Safari. See Navigation Preload.
Navigation request
A request with request.mode === "navigate", produced when a document is loaded in a top-level window or iframe. Service workers treat navigations specially: they are the requests that need offline fallbacks, they create new clients (resultingClientId), and they trigger update checks. A redirected response can't answer one. See Handling Fetch Events.
navigator.standalone
A non-standard, WebKit-only boolean that is true when the page is running as a Home Screen web app on iOS or iPadOS. Check it first on Apple platforms: a Home Screen web app whose manifest says "display": "standalone" matches display-mode: fullscreen (WebKit bug 264218), and one without a manifest reports browser. Since Safari 17 it also exists on macOS (false in tabs, true in Dock web apps), so its presence doesn't imply iOS; combine it with navigator.maxTouchPoints > 0. Pair it with matchMedia("(display-mode: standalone)") for other browsers. See Detecting Installed Apps.
Network-first
A caching strategy that tries the network, updates the cache with the response, and falls back to the cached copy (or an offline page) when the network fails or times out. It is the usual strategy for HTML and API data that must be fresh. Always pair it with a timeout, or a slow network becomes a slow app. See Caching Strategies.
Notification
A system-level message shown with registration.showNotification(title, options) from a service worker (or new Notification() from a page where supported). Options include body, icon, badge, tag, renotify, data, requireInteraction and, where supported, actions. Clicks arrive in the worker as notificationclick. See Notifications API.
Notification permission
The permission ("default", "granted" or "denied", from Notification.permission) that also governs Web Push in every shipping engine. Safari and Firefox only show the prompt from a user gesture; Chromium allows a prompt without one but switches to quieter UI for sites with low acceptance rates. Once denied, only the user can reset it, and requestPermission() resolves "denied" immediately. See Permissions.
notificationclick
The service worker event fired when the user clicks a notification or one of its action buttons. event.notification is the Notification (with its data), and event.action is the clicked action's ID or an empty string for the body. The handler usually calls event.notification.close() and, inside event.waitUntil(), focuses an existing window or calls clients.openWindow(), which is only permitted during this event. See Notifications API.

O

Offline fallback
A precached page (or image, or JSON document) that a service worker returns when a request fails and nothing better is cached, so the user sees a branded "you're offline" state instead of the browser's error page. It must be precached during install so it exists before it is needed. See Offline UX & Fallbacks.
Offline-first
An architecture in which the app reads and writes local data (IndexedDB, OPFS) first and synchronizes with the server in the background, treating the network as an enhancement. It needs a conflict-resolution strategy: last-write-wins, server-authoritative merges, operational transforms or CRDTs. See Offline-First Data & Sync.
Opaque response
A Response with type === "opaque", produced by a cross-origin no-cors request (for example an <img> or a fetch(url, { mode: "no-cors" }) to a server without CORS). Its status is reported as 0 and its headers and body are unreadable, so you can't tell success from a 500. It can only answer no-cors requests, and Chromium pads its size in quota accounting by a pseudo-random amount between 0 and about 14 MiB (about 7 MiB on average). See Cache Storage API.
Opaque redirect
A response of type opaqueredirect, produced by a fetch with redirect: "manual". A service worker can return it for a navigation so that the browser follows the redirect itself, which preserves the correct final URL. See Handling Fetch Events.
Origin
The triple of scheme, host and port (https://example.com:443) that is the web's security boundary. Service worker registrations, Cache Storage, IndexedDB, permissions and push subscriptions are all keyed by origin (and, for third-party contexts, the top-level site). Separate untrusted content by origin, never by path. See Service Worker Security.
Origin Private File System
A private, per-origin file system (navigator.storage.getDirectory()) that the user can't see, supported in all major engines. From a dedicated worker, createSyncAccessHandle() gives fast synchronous reads and writes, which is how SQLite and other databases run in the browser. See Origin Private File System.
Origin trial
A Chromium (and Edge) mechanism that lets a site enable an experimental feature for a limited period by sending a token in an Origin-Trial header or <meta> tag. Features in origin trials can change or disappear; treat them as experiments, not dependencies. See Resources & Specifications.
orientation
The manifest member that sets an installed app's default screen orientation (any, natural, portrait, landscape, and the -primary/-secondary variants). It applies only in app-like display modes and mostly on Android; screen.orientation.lock() changes it at runtime where fullscreen allows. See Members Reference.

P

Periodic Background Sync
A Chromium-only API (registration.periodicSync.register(tag, { minInterval })) that wakes an installed app's service worker at browser-chosen intervals, never more often than minInterval and in Chromium at most every 12 hours, scaled by site engagement. Events arrive as periodicsync. See Periodic Background Sync.
Permissions API
navigator.permissions.query({ name }), which reports a permission's state ("granted", "denied" or "prompt") and fires change events, without prompting. Names relevant to PWAs include notifications, push, persistent-storage, background-sync and periodic-background-sync, with support varying by engine. See Permissions.
Persistent storage
A storage mode requested with navigator.storage.persist() in which the browser won't evict the origin's data under storage pressure without the user's involvement. Chromium and Safari grant it silently based on heuristics (for example installation or engagement); Firefox prompts. Check with navigator.storage.persisted(). See Storage Quotas & Persistence.
Precache
The set of resources a service worker downloads and stores during install, before it takes control, so the app can run offline immediately. Each entry pairs a URL with a revision hash so that updates download only what changed. Workbox generates the precache manifest at build time. See Precaching & Runtime Caching.
Progressive enhancement
Building a baseline that works everywhere and layering capabilities on top when feature detection shows they exist. It is the "progressive" in Progressive Web App: a PWA must still work as a website in a browser without service workers, push or installation. See What Is a PWA?.
Progressive Web App
A website built with web technologies that uses a web app manifest, a service worker and HTTPS to be installable, reliable offline and integrated with the operating system, while remaining a linkable website. Alex Russell and Frances Berriman coined the term in June 2015. See What Is a PWA?.
Project Fugu
The cross-company Chromium effort, begun in 2018 with Google, Microsoft, Intel and others, to close capability gaps between web and native apps. It produced APIs such as File System Access, Web Share, Badging, WebHID, Web Serial, File Handling and Window Controls Overlay. Most Fugu APIs remain Chromium-only. See Device & OS Integration.
Protocol handler
A registration that makes a web app the handler for a URL scheme such as mailto: or a custom web+ scheme. Installed Chromium desktop apps declare them in the manifest's protocol_handlers member and are registered with the OS; navigator.registerProtocolHandler() registers them with the browser only. See Protocol Handlers & Launch Handling.
Push API
The browser API through which a service worker subscribes to and receives push messages: registration.pushManager.subscribe({ userVisibleOnly: true, applicationServerKey }) returns a PushSubscription, and incoming messages fire push events in the worker. Supported in all major engines; on iOS and iPadOS only in Home Screen web apps. See Push Notifications.
Push event
The PushEvent a service worker receives when a push message arrives. event.data is a PushMessageData (or null for an empty push) read with .json(), .text(), .arrayBuffer() or .blob(). Because of the userVisibleOnly promise, the handler must call registration.showNotification() inside event.waitUntil(); a push that ends without a notification is penalized in every engine. See Push Notifications.
Push service
The browser vendor's server that receives messages from your application server and delivers them to the browser: Firebase Cloud Messaging for Chrome, Mozilla's autopush for Firefox, Windows Push Notification Services for Edge, and Apple's push service (on push.apple.com) for Safari. You never choose it; the subscription's endpoint URL points at it. See The Web Push Protocol.
Push subscription
The PushSubscription object that identifies one browser installation to your server: an endpoint URL, an optional expirationTime, and keys (p256dh, the browser's P-256 public key, and auth, a 16-byte secret) used to encrypt payloads. Store subscription.toJSON() on your server. See Push Notifications.
pushsubscriptionchange
A service worker event fired when the browser invalidates, expires or rotates a push subscription, so the worker can resubscribe and send the new subscription to the server. Firefox (since 44, with the oldSubscription and newSubscription properties from version 137) and Safari 16 on macOS support it; it is not available on iOS and iPadOS. Chrome 138 fires it only in one case, when notification permission is granted again after being revoked, and with both properties null, so the handler must be able to create a subscription itself. See Push Notifications.
PWABuilder
A Microsoft-backed open-source tool (pwabuilder.com) that analyzes a PWA's manifest and service worker and generates store packages: MSIX for the Microsoft Store, a Trusted Web Activity app for Google Play, and an Xcode project wrapping the site for the Apple App Store. See PWABuilder.

Q

Quota
The maximum amount of storage an origin may use across IndexedDB, Cache Storage, OPFS and service worker registrations. Chromium allows up to about 60% of total disk per origin, Firefox the smaller of 10% of disk or 10 GiB per site group (more when persistent), Safari 17+ up to 60% of disk per origin for browser apps (Safari and third-party browsers that can be the default browser, such as Chrome, Edge and Firefox for iOS) and 15% for non-browser apps that embed WKWebView. navigator.storage.estimate() reports usage and quota, but Chrome reports quota as usage plus 10 GiB (the default since Chrome 148) to avoid fingerprinting, not the enforced limit. See Storage Quotas & Persistence.
QuotaExceededError
The DOMException thrown or used to reject a write (IndexedDB transaction, cache.put(), OPFS write) that would exceed the origin's quota. Handle it by evicting your own least-valuable caches and retrying, never by ignoring it. See Storage Quotas & Persistence.

R

Redundant
The final state of a service worker version: it failed to install, was replaced by a newer version, or its registration was unregistered. A redundant worker never receives events again. ServiceWorker.state === "redundant" and a statechange event mark the transition. See Lifecycle.
Registration
The ServiceWorkerRegistration object that ties a scope URL to up to three worker versions (installing, waiting, active) and to per-registration features such as pushManager, sync, periodicSync, navigationPreload and backgroundFetch. Created or retrieved with navigator.serviceWorker.register(scriptURL, options). See Registration & Scope.
related_applications
A manifest member that lists native apps (for example a Play Store app, platform: "play") or other PWAs related to the site. With prefer_related_applications: true, Chromium on Android promotes the native app instead of installing the PWA. Desktop browsers mostly ignore it, except that desktop Chromium suppresses install promotion when a chrome_web_store entry (or play on ChromeOS with Android apps) is listed. It also feeds getInstalledRelatedApps(). See Advanced & Integration Members.
Rich install UI
Chromium's app-store-style install dialog, shown when the manifest has a description and screenshots (with form_factor for desktop versus mobile). It shipped on Android in Chrome 94 and on desktop in Chrome 108. Safari and Firefox ignore these members. See Rich Install UI.
Runtime caching
Caching responses as the app requests them, in the fetch handler, rather than ahead of time. Runtime caches need explicit limits (entry counts, maximum age, quota-error purging) because they grow with use. See Precaching & Runtime Caching.

S

Scope (manifest)
The manifest's scope member: the URL prefix that defines which pages belong to the installed app. Navigations outside it show browser UI (an out-of-scope banner or a Custom Tab on Android). If absent, it defaults to the directory of start_url. It is unrelated to the service worker scope, although the two usually match. See App Identity & Updates.
Scope (service worker)
The URL prefix a registration controls, set with register(url, { scope }) and defaulting to the script's directory. Matching is a string-prefix test on the full URL, and the longest matching scope wins. A scope wider than the script's directory needs the Service-Worker-Allowed response header. See Registration & Scope.
scope_extensions
A Chromium manifest member (desktop, Chrome 139 after an origin trial; MDN lists 138) that lets an installed app treat other origins as in scope, confirmed by a .well-known/web-app-origin-association file on each extra origin. See Advanced & Integration Members.
Screenshots
The manifest's screenshots member: an array of images with src, sizes, type, optional form_factor (narrow or wide) and label, used by Chromium's rich install dialog and by store packaging tools. See Rich Install UI.
Secure context
A document or worker delivered over HTTPS (or from localhost, or a file-like scheme the browser trusts) whose ancestors are also secure. window.isSecureContext reports it. Service workers, push, notifications, storage persistence and nearly every capability API require it. See Service Worker Security.
Service worker
An event-driven JavaScript worker, registered by a page for a URL scope, that runs separately from any page, intercepts network requests from the pages it controls, and receives push, sync and notification events while no page is open. It has no DOM access, is terminated when idle, and must be served same-origin over HTTPS. See Service Workers.
Service-Worker header
A request header (Service-Worker: script) that browsers attach to the fetch of a service worker script. Servers can use it to refuse to serve anything but the real worker to such requests, which blocks an attacker from registering an arbitrary same-origin script as a worker. See Service Worker Security.
Service-Worker-Allowed
A response header on the worker script that raises the maximum scope a registration may claim above the script's own directory, for example Service-Worker-Allowed: / for a script at /js/sw.js. Send it only on the worker script. See Registration & Scope.
Share target
A manifest member (share_target) that registers an installed app in the OS share sheet, receiving shared text, URLs and files through a GET or POST navigation to its action URL. Supported by Chrome on Android (compiled into the WebAPK) and ChromeOS, and documented by Microsoft for Edge-installed PWAs on Windows; not by Safari, Firefox or Chrome on Windows, macOS and Linux. See Web Share Target.
short_name
The manifest member used where space is limited: the label under a Home Screen or launcher icon, and the app name in some task switchers. name is used in install dialogs, window titles and app lists. Chromium's installability check accepts either, but supply both, and keep short_name to about 12 characters so launchers don't truncate it. See Members Reference.
skipWaiting()
A service worker method (self.skipWaiting()) that moves a newly installed worker straight to active without waiting for old clients to close. It removes the wait but not the compatibility problem: already-open pages switch to new code mid-session. Most apps call it only after the user accepts an update prompt. See Updating Service Workers.
Splash screen
The screen shown while an installed app starts. Chromium on Android generates it from name, background_color, theme_color and the largest suitable icon. iOS uses apple-touch-startup-image link elements, one per device size and orientation, or shows a blank screen. See Splash Screens & Theming.
Stale-while-revalidate
A caching strategy that answers immediately from the cache and updates the cached copy from the network in the background, so the next request gets fresh content. Also the name of a Cache-Control extension (RFC 5861) that asks the HTTP cache to do the same. See Caching Strategies.
Standalone
The standalone display mode: the app runs in its own window without browser UI such as the address bar or tab strip, but with the OS status bar or title bar. It is the default choice for installed PWAs and the mode most platforms support. See Display Modes.
start_url
The manifest member naming the URL the app opens when launched from its icon. It must be same-origin with the manifest's document and inside scope. Without an explicit id, it also becomes the app's identity, so changing it creates a new app. See Members Reference.
Static routing
The Service Worker Static Routing API: event.addRoutes(rules) in the install handler declares rules whose conditions (urlPattern, requestMethod, requestMode, requestDestination, runningStatus, combined with or and not) send matching requests to a source: "network", "cache", "fetch-event" or "race-network-and-fetch-handler". Requests routed to the network or a cache skip the worker's startup entirely. Shipped in Chrome 123 and Safari 27. See Static Routing API.
Sticky activation
The state a window enters after its first user gesture and keeps until it is closed, reported by navigator.userActivation.hasBeenActive. It is weaker than transient user activation: some APIs (autoplay with sound, navigator.vibrate()) only need sticky activation, while prompts need a fresh, transient one. See Permissions.
Storage bucket
The unit of eviction and persistence within an origin's storage. Today most sites have one default bucket; the Chromium Storage Buckets API (navigator.storageBuckets.open()) lets a site create several with different persistence and durability. See Storage Quotas & Persistence.
Storage key
The key under which the browser stores an origin's data. For first-party contexts it is the origin; for embedded third-party contexts it also includes the top-level site, which is how storage partitioning prevents cross-site tracking. Quota and eviction are per storage key. See Privacy & Storage Partitioning.
Streaming response
A Response whose body is a ReadableStream, which a service worker can assemble from several sources (a cached header, a network body, a cached footer) so the browser starts parsing and rendering before the whole page has arrived. See Streaming Responses.

T

Tabbed mode
An experimental display mode ("tabbed" in display_override) in which an installed app's window has its own tab strip. Chromium supports it on ChromeOS; other desktops need a flag. The tab_strip manifest member configures the home tab. See Display Modes.
theme_color
The manifest member (and the <meta name="theme-color"> tag) that colors browser and OS UI around the app: the title bar on desktop, the status bar and task switcher on Android. The <meta> tag accepts a media attribute, which makes it the only practical way to supply a dark-mode theme color. See Splash Screens & Theming.
Topic
A Web Push header (Topic) that lets a new message replace an undelivered earlier message with the same topic at the push service, for example "latest score". Up to 32 characters from the URL-safe Base64 alphabet. See The Web Push Protocol.
Transient user activation
The short-lived state that a user gesture (click, key press, tap) gives a window, required by APIs that could otherwise be abused: beforeinstallprompt's prompt(), Notification.requestPermission() in Safari and Firefox, navigator.share(), and the file pickers. Some APIs consume it, so one click can't open two prompts. See Permissions.
Trusted Web Activity (TWA)
An Android mechanism (Chrome 72+) that lets a native app open a verified PWA full-screen in the user's browser, without browser UI, by proving ownership through Digital Asset Links. The PWA runs in the real browser, with its cookies, storage, push and service worker, which makes TWAs the standard way to ship a PWA on Google Play. See Trusted Web Activity.
TTL
The mandatory TTL header of a Web Push request: the number of seconds the push service should hold the message if the browser is offline. TTL: 0 means deliver now or drop. Push services may cap the value. See The Web Push Protocol.

U

Update check
The browser's process of re-fetching a registration's service worker script (and imported scripts) and comparing it byte for byte with the stored version. It runs on every navigation into scope, on functional events and subresource fetches only if the last check was more than 24 hours ago, and when you call registration.update(). There is no periodic 24-hour timer. Any difference starts installing a new version. See Updating Service Workers.
updateViaCache
A registration option ("imports" by default, or "all" or "none") that controls whether update checks may use the HTTP cache for the main worker script and imported scripts. With the default, the main script is always revalidated with the server. See HTTP Caching & Service Workers.
Urgency
A Web Push header (Urgency: very-low | low | normal | high) that lets a push service or device defer delivery of low-priority messages to save battery. See The Web Push Protocol.
userVisibleOnly
A pushManager.subscribe() option by which the site promises that every push will result in a visible notification. Chromium and Safari reject subscriptions without userVisibleOnly: true, so silent push is unavailable there. Firefox accepts userVisibleOnly: false and applies a quota to background messages that show no notification. See Push Notifications.

V

VAPID
Voluntary Application Server Identification (RFC 8292): the application server signs a short-lived ES256 JWT with claims aud (the push service origin), exp (no more than 24 hours ahead) and sub (a mailto: or https: contact), and sends it with its public key in the Authorization: vapid t=…, k=… header. The push service checks that the key matches the subscription's application server key. See The Web Push Protocol.
View Transitions
The View Transition API, which animates between DOM states (document.startViewTransition()) or, for cross-document navigations in multi-page apps, between pages (@view-transition { navigation: auto; }), making web navigations feel like native app transitions. See View Transitions.
Vite PWA plugin
vite-plugin-pwa, a community plugin for the Vite build tool that generates a web app manifest and a Workbox-based service worker (or injects a precache manifest into your own worker), and exposes a virtual module for registration and update prompts. See Vite PWA Plugin.

W

waitUntil()
The ExtendableEvent method that tells the browser to keep the service worker alive until a promise settles. In install a rejection fails the install; in push, sync and notificationclick it extends the event's lifetime, within browser time limits. Calling it asynchronously after the event handler has returned throws unless another waitUntil() is still pending. See Lifecycle.
Waiting worker
A successfully installed service worker version that is waiting to activate because an older version still controls at least one client. It stays in registration.waiting until every client of the old version is closed or navigated away, or until it calls skipWaiting(). Reloading one tab doesn't end the wait. See Lifecycle.
Web App Manifest
The JSON file linked with <link rel="manifest"> that describes an installable web app: name, short_name, id, start_url, scope, display, icons, colors and many optional integration members. It is a W3C specification, with Chromium-only extensions incubated in the WICG. See Web App Manifest and the Manifest Cheat Sheet.
Web Install API
An experimental API (navigator.install()) and companion <install> element, proposed by Microsoft and incubated in the WICG, that let a page install itself or another origin's app from a user gesture. navigator.install() ran as an origin trial in Chrome 143 to 148 (extended through 150) and <install> in Chrome 148 to 153; both trials have ended. An Intent to Ship posted in September 2026 targets desktop Chrome 156 for navigator.install() (Chrome Platform Status also lists <install>, with manifest and manifestId attributes). There is no Android implementation. WebKit opposes the proposal and Gecko has not signaled a position. See Install Prompts & Custom UI.
Web Locks API
navigator.locks.request(name, callback), an origin-wide mutex available in windows and workers of all major engines. In PWAs it elects one tab as the leader that flushes an offline outbox or holds a WebSocket, and guarantees that two tabs never run the same migration or sync at once. The lock is released when the callback's promise settles or the holder's context is destroyed. See Offline-First Data & Sync.
Web Push Protocol
RFC 8030, the HTTP protocol between an application server, a push service and a user agent: the server POSTs an encrypted message to the subscription's endpoint with TTL, optional Urgency and Topic headers, and receives 201 Created when the push service accepts it. See The Web Push Protocol.
Web Share
navigator.share({ title, text, url, files }), which opens the operating system's share sheet from a user gesture. navigator.canShare() checks whether given data, especially files, can be shared. Supported on Safari, Chrome on Android, Chromium on Windows, ChromeOS and macOS, and Firefox for Android. See Web Share API.
WebAPK
A real Android application package that Google Play services generates, signs and installs when a user installs a qualifying PWA from Chrome on Android (and Samsung Internet on Samsung devices). It appears in the app drawer and Android settings, registers intent filters for link capturing and share targets, and is updated when the manifest changes. See Android.
WebKit
Apple's browser engine, used by Safari on every Apple platform and, under App Store Review Guideline 2.5.6, by every browser on iOS and iPadOS outside the EU and Japan exceptions. WebKit decides which PWA features every iPhone and iPad user gets. See iOS & iPadOS.
Window Controls Overlay (WCO)
A Chromium desktop display mode (Chrome 105+, "window-controls-overlay" in display_override) in which the app's content extends into the title bar area, leaving only the OS window controls. navigator.windowControlsOverlay and the titlebar-area-x, -y, -width and -height CSS environment variables tell you where it's safe to draw. See Window Controls Overlay.
WKWebView
The WebKit web view that iOS apps embed, including Chrome, Edge and Firefox for iOS. Apps built on it get a subset of Safari's PWA capabilities. Browser apps that can be the default browser (Chrome, Edge and Firefox for iOS) get the same quota as Safari, up to 60% of disk per origin; other apps that embed it get 15%. App wrappers such as Capacitor use it to put a web app in the App Store. See Publishing to App Stores.
Workbox
Google's set of service worker libraries and build tools (workbox-build, workbox-webpack-plugin, workbox-cli) for precaching with revision manifests, routing requests to caching strategies, expiration, background sync queues and navigation preload. Most PWA frameworks and plugins generate Workbox service workers. See Workbox Fundamentals.

Further reading

On this site

External references