Authentication
- In Turkish
- Kimlik Doğrulama
In short
Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
What is authentication?
Authentication answers the question who are you? Before an application shows private data or accepts changes, it needs evidence that the person or program making the request really owns the account. That evidence is called a credential, and after a successful check the server usually creates a session cookie or issues a token so the user does not have to log in again on every request.
Credentials fall into three classic factors: something you know, such as a password or PIN; something you have, such as a phone or a hardware security key; and something you are, such as a fingerprint or face scan. Combining two or more factors is called multi-factor authentication. Passkeys, based on the WebAuthn standard, use public-key cryptography tied to a device and resist phishing, which is why they are increasingly replacing passwords.
Authentication is constantly confused with authorization. Authentication proves identity, while authorization decides what that identity is allowed to do: at an airport, showing your passport is authentication, and your boarding pass deciding which plane you may board is authorization. A request that fails authentication usually gets a 401 Unauthorized response, while a known user without permission gets 403 Forbidden.
To protect logins, store passwords only as salted hashes with Argon2id or bcrypt, offer two-factor authentication or passkeys, and rate-limit login attempts to slow down password guessing and credential stuffing, where attackers try passwords leaked from other sites. Use a generic error such as "Invalid email or password" so attackers cannot learn which accounts exist, and prefer a well-tested identity provider or library over writing authentication code from scratch.
At a glance
Key takeaways
- Authentication verifies identity; it answers the question who are you?
- Factors are something you know, something you have, and something you are.
- After login, a session cookie or token keeps the user authenticated.
- Authentication is not authorization, which decides what a user may do.
- Protect logins with hashed passwords, 2FA or passkeys, and rate limiting.
Example
app.post("/login", loginRateLimit, async (req, res) => {
const { email, password } = req.body;
const user = await db.users.findByEmail(email);
// Compare with the stored bcrypt hash, never a plain-text password
const ok = user && (await bcrypt.compare(password, user.passwordHash));
if (!ok) {
// Same message either way, so attackers cannot probe which emails exist
return res.status(401).send("Invalid email or password");
}
req.session.userId = user.id; // the user is now authenticated
res.redirect("/dashboard");
});Readers ask
What is the difference between authentication and authorization?
Authentication verifies who a user is, for example by checking a password or passkey. Authorization happens afterward and decides what that verified user is allowed to access or change.
What is a passkey?
A passkey is a login credential based on public-key cryptography, stored on a device or in a password manager and unlocked with a fingerprint, face scan, or PIN. The private key never leaves the device and only works on the real website, and the server stores only a public key, so passkeys resist phishing and are useless to attackers who steal the server's database.
What does HTTP 401 mean?
Despite its name, 401 Unauthorized means the request lacks valid authentication, such as a missing or expired token. When the user is authenticated but not allowed to do something, the correct status is 403 Forbidden.
Often compared
See also
- AuthorizationSecurity, p. 3Authorization is the process of deciding what an authenticated user or service is allowed to do, such as which data it can read, change, or delete.
- Two-Factor AuthenticationSecurity, p. 46Two-factor authentication is a login method that requires two different kinds of proof, such as a password plus a code or security key, to confirm identity.
- HashingSecurity, p. 14Hashing is the process of turning any input into a fixed-length value with a one-way function, used to verify data integrity and store passwords safely.
- OAuthSecurity, p. 22OAuth is an open standard for authorization that lets an app access a user's data on another service without ever seeing the user's password.
- JWTSecurity, p. 19A JWT is a compact, signed token that carries claims like a user ID and expiry time, letting a server verify requests without looking up a session.
- CookieWeb Development, p. 6A cookie is a small piece of data a website asks the browser to store and send back with later requests, often used to keep users logged in.
Spotted a mistake or something missing on this page?Suggest an edit