Skip to main content

Side by side

AuthenticationvsAuthorization

What is the difference between authentication and authorization?

Updated 2 min read7 differences

In short

Authentication verifies who you are, for example with a password or passkey, while authorization decides what you are allowed to do once your identity is known.

Authentication

Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.

Read the page on Authentication

Authorization

Authorization is the process of deciding what an authenticated user or service is allowed to do, such as which data it can read, change, or delete.

Read the page on Authorization

Authentication and Authorization compared

AspectAuthenticationAuthorization
Question it answersWho are you?What are you allowed to do?
When it happensFirst, usually at loginAfter authentication, on every protected action
Based onPasswords, passkeys, one-time codes, biometricsRoles, permissions, policies and ownership
User involvementThe user provides credentialsMostly invisible; the system applies rules
Failure status401 Unauthorized403 Forbidden
Changed byThe user, for example by resetting a passwordAn admin or owner, for example by granting a role
Common standardsOpenID Connect, SAML, WebAuthnOAuth 2.0 scopes, RBAC and ABAC policies

The difference, explained

Authentication, often shortened to authn, is the process of proving identity: the system checks a password, a one-time code, a passkey or a certificate and concludes that you are user 42. Authorization, or authz, is the process of checking permissions: given that you are user 42, may you view this invoice or change these settings?

They are separate because they answer different questions and change at different times. Your identity stays the same for a whole session, but permissions depend on the resource and the action, and may come from roles (RBAC), attributes or ownership rules. Keeping them apart lets you change how people log in without rewriting permission rules, and the other way around.

In practice they run one after the other on every protected request: authentication first, then authorization. HTTP even has a status code for each failure: 401 Unauthorized means the caller is not authenticated, and 403 Forbidden means the caller is known but not allowed. Standards follow the same split: OpenID Connect handles login, while OAuth 2.0 handles granting access.

A common misconception is that OAuth is an authentication protocol. OAuth 2.0 was designed for authorization, letting an app access resources on a user's behalf, and identity on top of it comes from OpenID Connect. Another is that logging in is enough: an authenticated user without proper authorization checks can often read other users' data.

Which one should you use?

Choose Authentication when…

  • You need to confirm a user's identity before anything else happens.
  • You are building login, sign-up, password reset or multi-factor flows.
  • You must verify which service or device is calling your API.

Choose Authorization when…

  • Different users should see or change different things.
  • You are designing roles, permissions or admin features.
  • You need to limit what a third-party app can do with a user's data.

Two separate checks in web server middleware

Authenticationjavascript
// Authentication: who is making this request?
function authenticate(req, res, next) {
  const user = verifyToken(req.headers.authorization);
  if (!user) return res.status(401).send("Please log in");
  req.user = user;
  next();
}
Authorizationjavascript
// Authorization: may this user perform this action?
function requireRole(role) {
  return (req, res, next) => {
    if (!req.user.roles.includes(role)) {
      return res.status(403).send("Not allowed");
    }
    next();
  };
}

Readers ask

What is the difference between 401 and 403?

401 Unauthorized means the request lacks valid credentials, so the server doesn't know who you are. 403 Forbidden means the server knows who you are, but you don't have permission.

Is OAuth authentication or authorization?

OAuth 2.0 is an authorization framework: it grants an app limited access to resources. OpenID Connect adds an identity layer on top of OAuth for authentication.

Which comes first, authentication or authorization?

Authentication comes first, because the system must know who you are before it can decide what you may do. Public pages that anyone can see skip both steps.

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings