Skip to main content

Authentication

Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/authentication

In short

Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.

What is authentication?

Authentication answers the question who are you? Before an application shows private data or accepts changes, it needs evidence that the person or program making the request really owns the account. That evidence is called a credential, and after a successful check the server usually creates a session cookie or issues a token so the user does not have to log in again on every request.

Credentials fall into three classic factors: something you know, such as a password or PIN; something you have, such as a phone or a hardware security key; and something you are, such as a fingerprint or face scan. Combining two or more factors is called multi-factor authentication. Passkeys, based on the WebAuthn standard, use public-key cryptography tied to a device and resist phishing, which is why they are increasingly replacing passwords.

Authentication is constantly confused with authorization. Authentication proves identity, while authorization decides what that identity is allowed to do: at an airport, showing your passport is authentication, and your boarding pass deciding which plane you may board is authorization. A request that fails authentication usually gets a 401 Unauthorized response, while a known user without permission gets 403 Forbidden.

To protect logins, store passwords only as salted hashes with Argon2id or bcrypt, offer two-factor authentication or passkeys, and rate-limit login attempts to slow down password guessing and credential stuffing, where attackers try passwords leaked from other sites. Use a generic error such as "Invalid email or password" so attackers cannot learn which accounts exist, and prefer a well-tested identity provider or library over writing authentication code from scratch.

At a glance

Logging in: the browser sends an email and password, the server compares the password with the stored hash and, if it matches, sends back a session cookie, which every later request carries so the server knows who is asking.BrowserServeremail + passworddoes the hash match?session cookienext request + cookieit's Ada
Authentication answers “who are you?”. What that person may then do is a separate check: authorization.

Key takeaways

  • Authentication verifies identity; it answers the question who are you?
  • Factors are something you know, something you have, and something you are.
  • After login, a session cookie or token keeps the user authenticated.
  • Authentication is not authorization, which decides what a user may do.
  • Protect logins with hashed passwords, 2FA or passkeys, and rate limiting.

Example

A password login handler (Express)javascript
app.post("/login", loginRateLimit, async (req, res) => {
  const { email, password } = req.body;
  const user = await db.users.findByEmail(email);

  // Compare with the stored bcrypt hash, never a plain-text password
  const ok = user && (await bcrypt.compare(password, user.passwordHash));
  if (!ok) {
    // Same message either way, so attackers cannot probe which emails exist
    return res.status(401).send("Invalid email or password");
  }

  req.session.userId = user.id; // the user is now authenticated
  res.redirect("/dashboard");
});

Readers ask

What is the difference between authentication and authorization?

Authentication verifies who a user is, for example by checking a password or passkey. Authorization happens afterward and decides what that verified user is allowed to access or change.

What is a passkey?

A passkey is a login credential based on public-key cryptography, stored on a device or in a password manager and unlocked with a fingerprint, face scan, or PIN. The private key never leaves the device and only works on the real website, and the server stores only a public key, so passkeys resist phishing and are useless to attackers who steal the server's database.

What does HTTP 401 mean?

Despite its name, 401 Unauthorized means the request lacks valid authentication, such as a missing or expired token. When the user is authenticated but not allowed to do something, the correct status is 403 Forbidden.

Often compared

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings