Authentication vs authorization.
Proving who you are at the door, versus what that identity is actually allowed to do inside.
- Name? ID, please.1
Authentication asks one thing: who are you? Prove it.
- Checks out. You’re Alice.2
You show ID — password, passkey, token. The door now knows you’re really Alice.
- 3
That badge gets you into the building. But it doesn’t say what you may touch.
- Alice the viewer, says your role.4
Authorization asks the second question: now that we know you, what are you allowed to do?
- Read: yes. Delete: no.5
The server-room door stays locked — Alice’s role grants reading, not deleting.
- Knowing who ≠ letting them in.6
Skip that second check and a real user overreaches — the classic broken-access-control hole.
Semicolony semicolony.dev/eli5/authn-vs-authz/comic