Side by side
AuthenticationvsAuthorization
What is the difference between authentication and authorization?
Updated 2 min read7 differences
In short
Authentication verifies who you are, for example with a password or passkey, while authorization decides what you are allowed to do once your identity is known.
Authentication
Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
Read the page on AuthenticationAuthorization
Authorization is the process of deciding what an authenticated user or service is allowed to do, such as which data it can read, change, or delete.
Read the page on AuthorizationAuthentication and Authorization compared
| Aspect | Authentication | Authorization |
|---|---|---|
| Question it answers | Who are you? | What are you allowed to do? |
| When it happens | First, usually at login | After authentication, on every protected action |
| Based on | Passwords, passkeys, one-time codes, biometrics | Roles, permissions, policies and ownership |
| User involvement | The user provides credentials | Mostly invisible; the system applies rules |
| Failure status | 401 Unauthorized | 403 Forbidden |
| Changed by | The user, for example by resetting a password | An admin or owner, for example by granting a role |
| Common standards | OpenID Connect, SAML, WebAuthn | OAuth 2.0 scopes, RBAC and ABAC policies |
The difference, explained
Authentication, often shortened to authn, is the process of proving identity: the system checks a password, a one-time code, a passkey or a certificate and concludes that you are user 42. Authorization, or authz, is the process of checking permissions: given that you are user 42, may you view this invoice or change these settings?
They are separate because they answer different questions and change at different times. Your identity stays the same for a whole session, but permissions depend on the resource and the action, and may come from roles (RBAC), attributes or ownership rules. Keeping them apart lets you change how people log in without rewriting permission rules, and the other way around.
In practice they run one after the other on every protected request: authentication first, then authorization. HTTP even has a status code for each failure: 401 Unauthorized means the caller is not authenticated, and 403 Forbidden means the caller is known but not allowed. Standards follow the same split: OpenID Connect handles login, while OAuth 2.0 handles granting access.
A common misconception is that OAuth is an authentication protocol. OAuth 2.0 was designed for authorization, letting an app access resources on a user's behalf, and identity on top of it comes from OpenID Connect. Another is that logging in is enough: an authenticated user without proper authorization checks can often read other users' data.
Which one should you use?
Choose Authentication when…
- You need to confirm a user's identity before anything else happens.
- You are building login, sign-up, password reset or multi-factor flows.
- You must verify which service or device is calling your API.
Choose Authorization when…
- Different users should see or change different things.
- You are designing roles, permissions or admin features.
- You need to limit what a third-party app can do with a user's data.
Two separate checks in web server middleware
// Authentication: who is making this request?
function authenticate(req, res, next) {
const user = verifyToken(req.headers.authorization);
if (!user) return res.status(401).send("Please log in");
req.user = user;
next();
}// Authorization: may this user perform this action?
function requireRole(role) {
return (req, res, next) => {
if (!req.user.roles.includes(role)) {
return res.status(403).send("Not allowed");
}
next();
};
}Readers ask
What is the difference between 401 and 403?
401 Unauthorized means the request lacks valid credentials, so the server doesn't know who you are. 403 Forbidden means the server knows who you are, but you don't have permission.
Is OAuth authentication or authorization?
OAuth 2.0 is an authorization framework: it grants an app limited access to resources. OpenID Connect adds an identity layer on top of OAuth for authentication.
Which comes first, authentication or authorization?
Authentication comes first, because the system must know who you are before it can decide what you may do. Public pages that anyone can see skip both steps.