How it works
Authentication (AuthN for short) answers 'who are you?'. It happens at sign-in, using something the person knows (a password), has (a phone or security key) or is (a fingerprint), and ends with the app issuing a session or token that carries the answer to later requests. Authorisation (AuthZ) answers 'what may you do?' and runs on every request: may this user read this invoice, delete this project, open the admin page?
The two fail in different ways. Broken sign-in lets a stranger in; a missing authorisation check lets a real, signed-in user read other people's data, which is why broken access control sits at the top of the OWASP Top 10. Checks belong on the server or in the database, because anything enforced only by hiding it in the interface can be bypassed. HTTP status codes mirror the split: 401 means 'not signed in' and 403 means 'signed in, but not allowed'.
Related terms
More in Auth and identity
Basics