The easiest way to remember it is:

Authentication = Who are you?

**Authorization = What are you allowed to do?**

Authentication always happens before authorization.

1. Authentication

Authentication is the process of verifying a user's identity.

The server asks:

"Can you prove that you are who you claim to be?"

Example

Login page:

Email: john@example.com
Password: ********

Request:

POST /login

Server checks:

If yes:

Authenticated

The server then issues a way to identify the user for future requests, such as:


Authentication Examples

All of these answer the same question:

"Who is this user?"


2. Authorization

Once the server knows who you are, it decides what you can do.

It asks:

"Does this authenticated user have permission to perform this action?"


Example

Suppose:

Alice
Role: Admin
Bob
Role: Customer

Both log in successfully.

Authentication:

Alice ✓

Bob ✓

Now they try:

DELETE /users/15

Server checks:

Role?

Alice:

Admin

↓

Allowed

Bob:

Customer

↓

403 Forbidden

Both users are authenticated, but only one is authorised.

3. Authentication Flow

User
   │
   ▼
Enter Email & Password
   │
   ▼
Server verifies credentials
   │
   ▼
Identity confirmed
   │
   ▼
Issue Session/JWT

At this point, the user is logged in.

4. Authorization Flow

Later:

DELETE /users/5

Request contains:

Session ID

or

JWT

Server:

Who is this user?

↓

User = Alice

↓

Role = Admin

↓

Allow Request

or

Who is this user?

↓

User = Bob

↓

Role = Customer

↓

403 Forbidden

5. Real Example

Imagine a company dashboard.

Users:

Admin
Manager
Employee

Everyone can log in.

Authentication:

Admin ✔

Manager ✔

Employee ✔

Now consider different actions.

View profile:

Admin ✔

Manager ✔

Employee ✔

Delete employee:

Admin ✔

Manager ✖

Employee ✖

Export payroll:

Admin ✔

Manager ✔

Employee ✖

The login process is authentication.

Permission checks are authorization.

6. HTTP Status Codes

Authentication Failure

User is not logged in or provides invalid credentials.

401 Unauthorized

Despite its name, 401 usually means authentication is required or has failed.

Examples:


Authorization Failure

User is logged in but lacks permission.

403 Forbidden

Examples:


7. Common Authorization Models

Role-Based Access Control (RBAC)

Permissions are based on roles.

Example:

Admin

Manager

Employee

Rules:

Admin

↓

Everything
Manager

↓

View Reports

Approve Leave
Employee

↓

View Own Profile

This is the most common approach in business applications.

Permission-Based Access Control

Instead of roles, users have individual permissions.

Example:

read_users

delete_users

create_invoice

export_reports

A user may have any combination of these permissions.

Attribute-Based Access Control (ABAC)

Access depends on attributes such as:

Example:

Allow editing a document only if:

User ID == Document Owner

8. Authentication vs Authorization

Authentication Authorization
Verifies identity Verifies permissions
Answers "Who are you?" Answers "What can you do?"
Happens first Happens after authentication
Login process Access control process
Uses passwords, OTP, JWT, sessions Uses roles, permissions, policies
--- # 9. Complete Request Flow
User
   │
   ▼
Login
   │
   ▼
Authentication
   │
   ▼
Session/JWT issued
   │
   ▼
Future Request
   │
   ▼
Authentication
(Is the token/session valid?)
   │
   ▼
Authorization
(Does this user have permission?)
   │
   ▼
Business Logic

Interview Questions

Can a user be authenticated but not authorised?

Yes.

Example:


Can authorisation happen without authentication?

In most applications, no.

The server first needs to know who the user is before deciding what they're allowed to do.

What is the difference between 401 and 403?


Notion Notes (Short Version)

Authentication

Authorization

Key Differences

Authentication Authorization
Identity verification Permission verification
Happens first Happens after authentication
Login process Access control
Returns **401** on failure Returns **403** on failure

This topic naturally leads into OAuth 2.0, OpenID Connect, Access Tokens vs Refresh Tokens, and API Keys, which are common authentication and authorisation mechanisms used in modern backend systems.