Auth and identity · Concept

Authentication and authorization

Authentication checks who someone is, for example with a password or a passkey. Authorisation then decides what that person may see and do, such as editing their own posts but not anyone else's.

Basics · updated

How it works

Authentication (AuthN for short) answers 'who are you?'. It happens at sign-in, using something the person knows (a password), has (a phone or security key) or is (a fingerprint), and ends with the app issuing a session or token that carries the answer to later requests. Authorisation (AuthZ) answers 'what may you do?' and runs on every request: may this user read this invoice, delete this project, open the admin page?

The two fail in different ways. Broken sign-in lets a stranger in; a missing authorisation check lets a real, signed-in user read other people's data, which is why broken access control sits at the top of the OWASP Top 10. Checks belong on the server or in the database, because anything enforced only by hiding it in the interface can be bypassed. HTTP status codes mirror the split: 401 means 'not signed in' and 403 means 'signed in, but not allowed'.

More in Auth and identity

Basics

All 17 Auth and identity terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.