Authentication vs Authorization
Authentication verifies identity (who you are). Authorization decides permissions (what you can do). Errors in each layer have different fixes.
AuthN
HTTP 401 Unauthorized
The request has no valid authentication credentials — you need to log in or send a valid token.
Causes & fixes →
AuthZ
HTTP 403 Forbidden
The server understood the request but refuses to authorize it — you (or the server process) are not allowed to access this resource.
Causes & fixes →| AuthN | AuthZ | |
|---|---|---|
| Question | Who are you? | What are you allowed to do? |
| Happens | First | After authentication |
| Examples | Password, OTP, OAuth login, API key, JWT | Roles, scopes, ACLs, file permissions, IAM policies |
| HTTP status on failure | 401 Unauthorized | 403 Forbidden |
| Typical errors | Invalid token, expired JWT, invalid_grant | AccessDenied, insufficient scope, permission denied |
Rule of thumb
AuthN failures: fix credentials. AuthZ failures: fix permissions/policies.