freecoding.school100% FREE · NO SIGNUP
Endpoint BayISSUE #30 of 45

authentication · who are you

RestaVSThe 401 Bandit
Resta saysAuthentication answers "who are you?" — proving the caller’s identity.

Before an API trusts a request, it must establish who is calling. Authentication verifies identity via a credential the caller presents: an API key, a token, a session cookie, or a signed assertion. It's distinct from authorization (what you're allowed to do). Get auth wrong and everything downstream is insecure.

Power-ups you unlock

The 401 Bandit attacks — common mistakes

Boss battleState the one-line difference between authentication and authorization.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>authentication: who are you?   (identity)
authorization:  what can you do? (permission)</pre></body></html>
▶ Open the interactive comic issue
‹ Polling Vs Long-Polling Vs PushAuthorization · What Can You Do ›