The easiest way to remember it is:
Authentication = Who are you?
**Authorization = What are you allowed to do?**
Authentication always happens before authorization.
1. Authentication
Authentication is the process of verifying a user's identity.
The server asks:
"Can you prove that you are who you claim to be?"
Example
Login page:
Email: john@example.com
Password: ********
Request:
POST /login
Server checks:
- Does this email exist?
- Does the password match?
If yes:
Authenticated
The server then issues a way to identify the user for future requests, such as:
- A session ID
- A JWT
- Another authentication token
Authentication Examples
- Username + Password
- OTP
- Fingerprint
- Face ID
- Google Login (OAuth)
- GitHub Login
All of these answer the same question:
"Who is this user?"
2. Authorization
Once the server knows who you are, it decides what you can do.
It asks:
"Does this authenticated user have permission to perform this action?"
Example
Suppose:
Alice
Role: Admin
Bob
Role: Customer
Both log in successfully.
Authentication:
Alice ✓
Bob ✓
Now they try:
DELETE /users/15
Server checks:
Role?
Alice:
Admin
↓
Allowed
Bob:
Customer
↓
403 Forbidden
Both users are authenticated, but only one is authorised.
3. Authentication Flow
User
│
▼
Enter Email & Password
│
▼
Server verifies credentials
│
▼
Identity confirmed
│
▼
Issue Session/JWT
At this point, the user is logged in.
4. Authorization Flow
Later:
DELETE /users/5
Request contains:
Session ID
or
JWT
Server:
Who is this user?
↓
User = Alice
↓
Role = Admin
↓
Allow Request
or
Who is this user?
↓
User = Bob
↓
Role = Customer
↓
403 Forbidden
5. Real Example
Imagine a company dashboard.
Users:
Admin
Manager
Employee
Everyone can log in.
Authentication:
Admin ✔
Manager ✔
Employee ✔
Now consider different actions.
View profile:
Admin ✔
Manager ✔
Employee ✔
Delete employee:
Admin ✔
Manager ✖
Employee ✖
Export payroll:
Admin ✔
Manager ✔
Employee ✖
The login process is authentication.
Permission checks are authorization.
6. HTTP Status Codes
Authentication Failure
User is not logged in or provides invalid credentials.
401 Unauthorized
Despite its name, 401 usually means authentication is required or has failed.
Examples:
- Invalid password
- Missing JWT
- Expired session
- Invalid token
Authorization Failure
User is logged in but lacks permission.
403 Forbidden
Examples:
- Customer trying to delete users
- Employee accessing admin dashboard
- User editing someone else's private resource without permission
7. Common Authorization Models
Role-Based Access Control (RBAC)
Permissions are based on roles.
Example:
Admin
Manager
Employee
Rules:
Admin
↓
Everything
Manager
↓
View Reports
Approve Leave
Employee
↓
View Own Profile
This is the most common approach in business applications.
Permission-Based Access Control
Instead of roles, users have individual permissions.
Example:
read_users
delete_users
create_invoice
export_reports
A user may have any combination of these permissions.
Attribute-Based Access Control (ABAC)
Access depends on attributes such as:
- User department
- Resource owner
- Time of day
- Location
Example:
Allow editing a document only if:
User ID == Document Owner
8. Authentication vs Authorization
| Authentication | Authorization |
| Verifies identity | Verifies permissions |
| Answers "Who are you?" | Answers "What can you do?" |
| Happens first | Happens after authentication |
| Login process | Access control process |
| Uses passwords, OTP, JWT, sessions | Uses roles, permissions, policies |
User
│
▼
Login
│
▼
Authentication
│
▼
Session/JWT issued
│
▼
Future Request
│
▼
Authentication
(Is the token/session valid?)
│
▼
Authorization
(Does this user have permission?)
│
▼
Business Logic
Interview Questions
Can a user be authenticated but not authorised?
Yes.
Example:
- User logs in successfully.
- Tries to access the admin panel.
- They are authenticated but receive 403 Forbidden because they lack permission.
Can authorisation happen without authentication?
In most applications, no.
The server first needs to know who the user is before deciding what they're allowed to do.
What is the difference between 401 and 403?
- 401 Unauthorized → Authentication failed or is missing.
- 403 Forbidden → Authentication succeeded, but the user doesn't have permission.
Notion Notes (Short Version)
Authentication
- Verifies the user's identity.
- Answers: Who are you?
- Uses credentials such as passwords, OTPs, sessions, or JWTs.
- On success, the server issues a session or token.
Authorization
- Determines what an authenticated user can access.
- Answers: What are you allowed to do?
- Uses roles, permissions, or access policies.
- Returns 403 Forbidden if access is denied.
Key Differences
| Authentication | Authorization |
| Identity verification | Permission verification |
| Happens first | Happens after authentication |
| Login process | Access control |
| Returns **401** on failure | Returns **403** on failure |
This topic naturally leads into OAuth 2.0, OpenID Connect, Access Tokens vs Refresh Tokens, and API Keys, which are common authentication and authorisation mechanisms used in modern backend systems.