Proving who someone is and deciding what they are allowed to do, on every request and for every object.
Topics
- Authentication
- Passwords and password hashing, multi-factor authentication and passkeys.
- Sessions and Tokens
- Cookies, bearer tokens and signed tokens, and how to handle expiry and revocation.
- Authorization Models
- Roles, attributes and ownership, with permission checked on the server for every action.
- Object-Level Authorization
- Confirming the caller may access this specific record, a check endpoints often skip once login is confirmed.
- Delegated Access
- OAuth-style flows that let one system act for a user with limited, revocable scope.