SECURITY / A CONCEPT NOTE
AuthN vs AuthZ
who you are vs what you may do
Overview · mechanism
pitfall · examples
01 / THE SHORT VERSION
The idea in a few sentences.
Authentication (AuthN) verifies your identity (who you are). Authorization (AuthZ) verifies your access privileges (what resources you are permitted to open or modify).
02 / FOLLOW THE MECHANISM
How identity to permission flows
Authentication (AuthN)
user logs in with password and MFA. System issues ID token.
Identity confirmed
system validates token signature: 'this user is indeed John Doe'.
Authorization (AuthZ)
John requests admin page. Policy checker evaluates roles.
Access decision
John is not an admin, so system throws a 403 Forbidden error.
04 / COMMAND NOTES
Read the command, then the result.
Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.
authenticate via Basic Auth
curl -u username:password https://api.example.com05 / CHECK YOURSELF
Could you explain AuthN vs AuthZ to a teammate?
Try it out loud in two sentences: what it is, and the one detail that changes the picture. If you stall, the gap is the part to reread.
Up next in Security & identityPublic-key Cryptographythe math behind SSH and TLS