# Authentication vs Authorization

URL: https://softwaredictionary.org/compare/authentication-vs-authorization
Last updated: 2026-09-30

In short: Authentication verifies who you are, for example with a password or passkey, while authorization decides what you are allowed to do once your identity is known.

## What is the difference between authentication and authorization?

Authentication, often shortened to authn, is the process of proving identity: the system checks a password, a one-time code, a passkey or a certificate and concludes that you are user 42. Authorization, or authz, is the process of checking permissions: given that you are user 42, may you view this invoice or change these settings?

They are separate because they answer different questions and change at different times. Your identity stays the same for a whole session, but permissions depend on the resource and the action, and may come from roles (RBAC), attributes or ownership rules. Keeping them apart lets you change how people log in without rewriting permission rules, and the other way around.

In practice they run one after the other on every protected request: authentication first, then authorization. HTTP even has a status code for each failure: `401 Unauthorized` means the caller is not authenticated, and `403 Forbidden` means the caller is known but not allowed. Standards follow the same split: OpenID Connect handles login, while OAuth 2.0 handles granting access.

A common misconception is that OAuth is an authentication protocol. OAuth 2.0 was designed for authorization, letting an app access resources on a user's behalf, and identity on top of it comes from OpenID Connect. Another is that logging in is enough: an authenticated user without proper authorization checks can often read other users' data.

| Aspect | Authentication | Authorization |
| --- | --- | --- |
| Question it answers | Who are you? | What are you allowed to do? |
| When it happens | First, usually at login | After authentication, on every protected action |
| Based on | Passwords, passkeys, one-time codes, biometrics | Roles, permissions, policies and ownership |
| User involvement | The user provides credentials | Mostly invisible; the system applies rules |
| Failure status | 401 Unauthorized | 403 Forbidden |
| Changed by | The user, for example by resetting a password | An admin or owner, for example by granting a role |
| Common standards | OpenID Connect, SAML, WebAuthn | OAuth 2.0 scopes, RBAC and ABAC policies |

## Choose Authentication when

- You need to confirm a user's identity before anything else happens.
- You are building login, sign-up, password reset or multi-factor flows.
- You must verify which service or device is calling your API.

## Choose Authorization when

- Different users should see or change different things.
- You are designing roles, permissions or admin features.
- You need to limit what a third-party app can do with a user's data.

## Frequently asked questions

**What is the difference between 401 and 403?**

`401 Unauthorized` means the request lacks valid credentials, so the server doesn't know who you are. `403 Forbidden` means the server knows who you are, but you don't have permission.

**Is OAuth authentication or authorization?**

OAuth 2.0 is an authorization framework: it grants an app limited access to resources. OpenID Connect adds an identity layer on top of OAuth for authentication.

**Which comes first, authentication or authorization?**

Authentication comes first, because the system must know who you are before it can decide what you may do. Public pages that anyone can see skip both steps.

---

Software Dictionary: https://softwaredictionary.org/ · https://softwaredictionary.org/llms.txt
