Middleware

An Express 24,430 application is a pipeline. A request enters at the top, passes through a list of functions, and leaves when one of them writes a response. Every function in that list has the same shape — request, response, and a callback named next — and Express calls them in registration order. That one convention is the whole framework: routing, body parsing, static file serving, sessions, compression and error handling are all middleware.

The word covers three jobs. Some middleware observe a request and let it continue (a logger). Some decorate it, attaching data later handlers rely on (express.json filling req.body). Some terminate it, answering without calling next (an auth check that rejects a missing token). Knowing which you are writing tells you whether to call next(), call next(err), or send a response and stop.

Order is not a detail you can fix later. A logger registered after the route it logs records nothing; express.json registered after a route leaves req.body undefined there; an error handler registered before your routes never sees their errors.

Express 5 changes one long-standing rule. In Express 4, an async handler that rejected hung the request unless you wrapped every handler in a helper, and almost every tutorial written before 2025 teaches that wrapper. Express 5 forwards a rejected promise to your error middleware by itself.

Subsections