← All terms

Identity and security

Authorization

Authorization decides whether a caller may perform a particular action on a particular resource. It uses rules such as ownership, role or purchased access. The trusted server or database enforces those rules; hiding a button only changes the interface.

You might see: AuthZ, access control, permissions

In a real project

Two people are signed in, but each may edit only their own reading list. Before saving a change, the server checks the caller against the list's owner instead of trusting an owner ID submitted by the browser.

A common mistake

Checking permission only when a page opens. Direct API requests and later changes still need their own checks, including which account owns the specific resource.

Put it into practice

These lessons open through your account. Your kit determines which are available.

Go to the source

Sources checked .