Back-end development (also server-side development)
is the branch of software engineering concerned with the parts of an
application that run on servers rather than on a user's device. It covers the
business logic, data storage, authentication, and integration with other
systems that users do not see directly.
Quick answer: Back-end development is the creation
and maintenance of the server-side components of software. These include
application logic, databases, and application programming interfaces (APIs).
They receive requests from client software such as web browsers or mobile apps,
process them, store or retrieve data, and return a response. Back-end work
emphasizes correctness, security, performance, and reliability.
Back-end development is usually contrasted with front-end
development, which concerns the interface a person sees and interacts with.
The two communicate over a network, most commonly using the HTTP protocol. The
term applies to websites, mobile applications, games, and enterprise systems
alike.
|
Field |
Software engineering |
|
Also known as |
Server-side development, backend engineering |
|
Practitioners |
Back-end developers, back-end engineers |
|
Typical components |
Application server, database, API, authentication,
background jobs |
|
Common languages |
Python, Java, JavaScript (Node.js), C#, PHP, Ruby, Go,
Rust, Kotlin |
|
Related fields |
Front-end development, full-stack development, DevOps |
Overview

Most networked software follows a client–server model.
A client, such as a browser or mobile app, sends a request. A server receives
it, performs the necessary work, and sends back a response. The back end is
everything on the server side of that exchange.
A typical request, such as loading an account page,
illustrates the process:
- The
client sends an HTTP request to a server.
- The
server verifies the user's identity and permissions.
- Application
code queries a database or other services.
- The
server formats the result, often as HTML or JSON, and returns it.
Back-end developers write and maintain the code behind these
steps. They also decide how data is structured, how failures are handled, and
how the system behaves under heavy use.
History
Early web servers in the early 1990s mainly delivered static
files. The Common Gateway Interface (CGI), introduced around 1993,
allowed servers to run programs in response to requests and produce dynamic
pages. Scripting languages followed, including PHP, which Rasmus Lerdorf
began developing in 1994, and Java Servlets, introduced in the late 1990s.
Relational databases predate the web. E. F. Codd
proposed the relational model in 1970, and SQL later became a standard query
language. Open-source systems such as MySQL (1995) and PostgreSQL (named in
1996, with roots in earlier POSTGRES work) became common choices for web
applications.
Web frameworks emerged in the 2000s to reduce repetitive
work. Django (public release in 2005) and Ruby on Rails (released
in 2004) are widely cited examples. In 2000, Roy Fielding described the
REST architectural style in his doctoral dissertation, which later shaped many
API designs.
Several shifts followed in the 2009–2015 period:
- Node.js
(2009) allowed JavaScript to run on servers.
- NoSQL
databases gained prominence as alternatives to relational systems for some
workloads.
- Docker
(2013) popularized containerization, and Kubernetes (2014) became a
common container orchestrator.
- AWS
Lambda (2014) brought "serverless" computing into wide use.
- GraphQL,
developed at Facebook, was open-sourced in 2015.
Core components
Servers and application logic
The application server runs code that implements an
application's rules, such as calculating an order total or checking whether a
user may edit a record. Developers commonly build this layer with a framework
that handles routing, request parsing, and error handling.
Databases and data storage
Data is typically held in a database. The main categories
differ in structure and trade-offs:
|
Type |
Data model |
Examples |
Typical use |
|
Relational (SQL) |
Tables with defined schemas |
PostgreSQL, MySQL |
Structured records, transactions |
|
Document |
JSON-like documents |
MongoDB |
Flexible or varying records |
|
Key–value |
Simple key to value pairs |
Redis |
Caching, sessions |
|
Graph |
Nodes and relationships |
Neo4j |
Highly connected data |
Choice of database depends on consistency requirements,
query patterns, and scale. Many systems combine several types.
APIs
An application programming interface (API) defines
how clients and other services communicate with the back end. Common styles
include REST, GraphQL, and gRPC. Each defines conventions for requests,
responses, and error reporting. Versioning and documentation are important
because other software depends on them.
Authentication and authorization
Authentication confirms who a user is, while authorization
determines what that user may do. Common mechanisms include session cookies,
tokens, and delegated sign-in protocols such as OAuth 2.0. These two concepts
are frequently confused but address different questions.
Architecture patterns

Back-end systems are commonly organized in one of several
ways:
- Monolithic:
A single deployable application contains all functionality. This is
simpler to develop and test initially.
- Microservices:
Functionality is divided into small, independently deployed services that
communicate over a network. This allows independent scaling but adds
operational complexity.
- Serverless:
Code runs in short-lived functions managed by a cloud provider, which
handles server provisioning.
Whether microservices or monoliths are preferable is debated
among practitioners, and the answer depends on team size, product maturity, and
operational capacity.
Responsibilities and practices
Back-end developers commonly work on:
- Designing
database schemas and writing queries
- Building
and documenting APIs
- Implementing
security controls
- Writing
automated tests
- Monitoring,
logging, and debugging production systems
- Optimizing
performance through caching, indexing, and load balancing
Security is a central concern because servers hold
sensitive data. The Open Worldwide Application Security Project (OWASP)
periodically publishes a list of common web application risks, including
injection flaws and broken access control, that back-end developers use as a
reference.
Scalability refers to a system's ability to handle
growth in users or data. Techniques include horizontal scaling (adding
servers), database replication, and message queues that process work
asynchronously.
Comparison with related roles
|
Aspect |
Front-end |
Back-end |
Full-stack |
|
Location of code |
User's device |
Servers |
Both |
|
Main concerns |
Layout, interaction, accessibility |
Data, logic, security, performance |
Whole application |
|
Typical technologies |
HTML, CSS, JavaScript |
Server languages, databases, APIs |
Combination |
A common misconception is that the back end is entirely
separate from the user experience. In practice, response time, error handling,
and data accuracy on the back end strongly affect what users encounter. Another
is that the term applies only to websites; mobile apps, desktop software with
online features, and internet-connected devices also rely on back-end systems.
Current status
Back-end development continues to change with cloud
computing, container-based deployment, and managed database services. Specific
tool popularity shifts over time, and readers seeking current usage figures
should consult recent developer surveys.