Metadata means data about other data.
It’s extra information that describes something, rather than being the main content itself.
Simple example
Suppose you have a photo:
Photo = the actual dataIts metadata could be:
filename: vacation.jpg
size: 3.2 MB
type: image/jpeg
created_at: 2026-09-11
width: 1920
height: 1080The photo is the main data. The information about the photo is metadata.
In your backend
Suppose you have an audit log:
{
"action": "UPDATE_USER_ROLE",
"resource_id": 87,
"metadata": {
"oldRole": "USER",
"newRole": "ADMIN"
}
}Here:
action → what happened
resource_id → what was affected
metadata → additional details about what happenedThe metadata gives you information that isn’t worth creating a separate column for every possible detail.
For example, another audit event could have:
{
"action": "CHANGE_TASK_STATUS",
"resource_id": 15,
"metadata": {
"oldStatus": "TODO",
"newStatus": "DONE"
}
}Different actions can have different metadata.
Metadata appears everywhere
HTTP
A response:
HTTP/1.1 200 OK
Content-Type: application/json
Content-Length: 1500The actual response body is the data:
{
"name": "Reyhan"
}While headers provide metadata about the response:
Content-Type
Content-Length
Cache-ControlDatabase
A database record:
User:
id: 42
username: reyhanMetadata might include:
created_at
updated_at
created_byThese describe the record rather than being the core user information.
Logs
{
"level": "ERROR",
"message": "Database connection failed",
"metadata": {
"service": "user-service",
"requestId": "abc123",
"database": "postgres",
"retryCount": 3
}
}The main data is:
"Database connection failed"The metadata tells you where, when, and in what context it happened.
The easiest definition
Data = the thing.
Metadata = information about the thing.
For example:
Book
├── Data: the actual text of the book
└── Metadata:
├── title
├── author
├── publication date
├── page count
└── ISBNThis concept is useful throughout backend development because you’ll see metadata in HTTP, databases, APIs, logs, files, authentication tokens, and audit logs.