Skip to content

Authentication & Authorization

Authentication (AuthN) = who are you? Authorization (AuthZ) = what are you allowed to do?


MethodHow It WorksProsCons
Session-basedServer stores session, client sends cookieSimple, server controls sessionsStateful, harder to scale
JWT (JSON Web Token)Server signs a token, client stores itStateless, scales easilyCan’t revoke tokens (until expiry)
OAuth 2.0Third-party authorization (Google, GitHub)No password management for youComplex flow, depends on external provider
SSO (SAML/OIDC)One login for multiple appsSingle sign-on across appsComplex setup

sequenceDiagram
participant Client as 📱 Client
participant Server as 🖥️ Auth Server
participant API as 📡 API Server
Client->>Server: POST /login (email + password)
Server->>Server: Verify credentials
Server-->>Client: ✅ JWT Token
Note over Server: JWT = header.payload.signature
Client->>API: GET /orders (Authorization: Bearer <JWT>)
API->>API: Verify signature (no DB call!)
API-->>Client: ✅ Orders data

JWT structure: header.base64(payload).signature

// JWT Payload (decoded)
{
"sub": "user_123",
"name": "Alice",
"role": "admin",
"iat": 1700000000, // issued at
"exp": 1700086400 // expires
}

sequenceDiagram
participant User as 👤 User
participant App as 📱 Your App
participant Auth as 🔐 Google/GitHub
User->>App: Click "Login with Google"
App->>Auth: Redirect to Google login
User->>Auth: Enter credentials
Auth-->>App: Authorization code
App->>Auth: Exchange code for access token
Auth-->>App: Access token
App->>App: Use token to get user info (email, name)
App-->>User: ✅ Logged in

ModelHow It WorksExample
RBAC (Role-Based)Roles → permissionsAdmin can delete, User can read
ABAC (Attribute-Based)Rules based on attributes”Managers can edit their department’s budgets”
ACL (Access Control List)Explicit list per resource”User 123 can read file X”

  • Session-based is simpler but doesn’t scale horizontally without a shared session store (Redis).
  • JWT scales beautifully but can’t be revoked — set short expiry times (15 min) and use refresh tokens.
  • OAuth 2.0 is the standard for third-party logins but adds flow complexity.
  • Never roll your own auth — use proven libraries and providers.

  • AuthN = proving who you are (login, password, biometrics).
  • AuthZ = what you can do (read, write, delete).
  • JWT is the most common API auth — the server signs a token, the client presents it.
  • Use OAuth 2.0 for “Login with Google/GitHub.”