How does the Spring Security filter chain decide 401 versus 403 on a REST API?
PICTURE THIS: A SENTENCE BECOMES TOKENS
The model does not read letters like humans. It reads these pieces, then predicts the next one.
Simple meaning
Authentication filters populate SecurityContext or fail with 401 if the token is missing or invalid.
WHY — Spring Boot instead of guessing?
Why interviewers care about Spring Boot:
contrast on Spring Boot, not two memorised paragraphs.
the developer, then one case where picking wrong hurts.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens with tokens?
Before the model can read a sentence, it goes through these steps:
- 1Authentication filters populate SecurityContext
or fail with 401 if the token is missing or invalid.
- 2Authorization filters then check
roles and methods
- 3Embeddings
failure is 403.
- 4ExceptionTranslationFilter maps AuthenticationException and
AccessDeniedException to those statuses for stateless APIs.
- 5Next token
The model scores what should come next.
- 6Decode
IDs turn back into readable text.
EXAMPLE — See it in action
Here's a short line you can speak, broken into clear beats:
Note: Adapt this scaffold to your own project — keep it under 60–90 seconds.
Key takeaway
Authentication filters populate SecurityContext or fail with 401 if the token is missing or invalid. Authorization filters then check roles and methods