Authentication vs Authorisation

Authentication is about who somebody is. When you log in to a system, you use a login and password to authenticate.

Authorisation is about what they’re allowed to do. For example gaining access to a resource that has restricted permissions.