Identity and security
Authentication
Authentication verifies who a caller claims to be. A sign-in system checks evidence such as a password or a verified sign-in link, then establishes an identity. Knowing that identity does not automatically grant access to every record or action.
You might see: AuthN, sign-in, login, log in
In a real project
You sign in to your reading-list account. The application can now identify your account, but it still needs permission rules before letting you read, edit or delete a particular list.
A common mistake
Using 'the user is signed in' as the entire security check. Authentication establishes identity; authorization decides what that identity may do.
Put it into practice
These lessons open through your account. Your kit determines which are available.
Go to the source
Sources checked .