01/10/2026
Authentication vs Authorization is only the beginning of modern application security.
If you work with backend systems, APIs, cloud infrastructure, microservices, or AI agents, these 9 concepts form a practical mental model for understanding identity and access control.
1. Authentication vs Authorization
Authentication proves who you are. Authorization decides what you can do.
Think 401 = identity problem and 403 = permission problem.
2. Sessions vs Tokens
Sessions keep state on the server. Tokens carry signed claims with the client. The trade-off is largely revocation vs scalability.
3. OAuth 2.0 Roles
OAuth is about delegated authorization, not authentication. The four roles are resource owner, client, authorization server, and resource server.
4. Authorization Code + PKCE
The browser carries the authorization code, not the token. PKCE proves that the app exchanging the code is the one that initiated the flow.
5. JWT Structure
A JWT contains header, payload, and signature. Remember: encoded does not mean encrypted.
6. Access vs Refresh Tokens
Short-lived access tokens reduce the blast radius of leakage. Refresh-token rotation and reuse detection add another security layer.
7. SAML vs OIDC
SAML remains important in enterprise SSO. OIDC provides a modern identity layer on OAuth 2.0.
8. Scopes + RBAC
Scopes constrain what an application can request. Roles constrain what the user can do. Effective access is their intersection.
9. Service-to-Service Authentication
For workloads and AI agents, avoid shared static API keys where possible. Workload identity + short-lived, scoped credentials provides stronger attribution and reduces secret exposure.
For developers preparing for system design, backend, cloud, DevOps, or AI engineering interviews, these distinctions are worth understanding—not just memorising.
Save this as your Authentication & Authorization cheat sheet.
[ authentication vs authorization authorization vs authentication OAuth 2.0 PKCE JWT explained access token refresh token SAML OIDC RBAC API security service to service authentication system design ]