Before an API trusts a request, it must establish who is calling. Authentication verifies identity via a credential the caller presents: an API key, a token, a session cookie, or a signed assertion. It's distinct from authorization (what you're allowed to do). Get auth wrong and everything downstream is insecure.