What is the difference between authentication and authorization?
PICTURE THIS: 1, 2, 2, 8
Simple meaning
Authentication proves who the user is, usually with a password, OTP, or OAuth login.
WHY — Auth instead of guessing?
Why interviewers care about Auth:
contrast on Auth, not two memorised paragraphs.
the developer, then one case where picking wrong hurts.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens step by step?
Before you speak the answer, walk the interviewer through these steps:
- 1Authentication proves who the
user is, usually with a password, OTP, or OAuth login.
- 2Authorization decides what that
user is allowed to do afterward.
- 3How it works
A 401 typically means unauthenticated
- 4a 403 means authenticated
but not allowed.
- 5Common mistake
What juniors usually get wrong.
- 6Close
When you pick this over the alternative.
EXAMPLE — See it in action
Here's a short line you can speak, broken into clear beats:
Note: Adapt this scaffold to your own project — keep it under 60–90 seconds.
Key takeaway
Authentication proves who the user is, usually with a password, OTP, or OAuth login. Authorization decides what that user is allowed to do afterward.