SECURITY / A CONCEPT NOTE

AuthN vs AuthZ

who you are vs what you may do

~60 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

Authentication (AuthN) verifies your identity (who you are). Authorization (AuthZ) verifies your access privileges (what resources you are permitted to open or modify).

02 / FOLLOW THE MECHANISM

How identity to permission flows

  1. Authentication (AuthN)

    user logs in with password and MFA. System issues ID token.

  2. Identity confirmed

    system validates token signature: 'this user is indeed John Doe'.

  3. Authorization (AuthZ)

    John requests admin page. Policy checker evaluates roles.

  4. Access decision

    John is not an admin, so system throws a 403 Forbidden error.

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · REFERENCE

authenticate via Basic Auth

curl -u username:password https://api.example.com

Explore command anatomy in the CLI lab