Authentication vs Authorization

Authentication verifies identity (who you are). Authorization decides permissions (what you can do). Errors in each layer have different fixes.

AuthN

HTTP 401 Unauthorized

The request has no valid authentication credentials — you need to log in or send a valid token.

Causes & fixes →
AuthZ

HTTP 403 Forbidden

The server understood the request but refuses to authorize it — you (or the server process) are not allowed to access this resource.

Causes & fixes →
AuthNAuthZ
QuestionWho are you?What are you allowed to do?
HappensFirstAfter authentication
ExamplesPassword, OTP, OAuth login, API key, JWTRoles, scopes, ACLs, file permissions, IAM policies
HTTP status on failure401 Unauthorized403 Forbidden
Typical errorsInvalid token, expired JWT, invalid_grantAccessDenied, insufficient scope, permission denied

Rule of thumb

AuthN failures: fix credentials. AuthZ failures: fix permissions/policies.