Short answer
Authentication verifies who you are — with a password, passkey, one-time code or single sign-on. Authorization decides what you are allowed to do once identified — through roles, permissions, attributes or policies. Authentication happens first; authorization is checked on every protected action, ideally on the server and close to the data.
Authorization models
- RBAC — permissions granted through roles.
- ABAC — decisions from attributes of user, resource and context.
- ReBAC — permissions derived from relationships, such as document owners and collaborators.
A classic bug
Insecure direct object references happen when a server authenticates the user but forgets to check they own the resource id in the URL. Always authorise the specific object, not just the endpoint.
How to answer it in an interview
- Use “401 means who are you, 403 means you cannot do that”.
- Mention least privilege.