Security · Fill in the blank

Checking who is calling is blank; checking what that caller is allowed to do is blank.

easy API design

Answer

Checking who is calling is authentication; checking what that caller is allowed to do is authorization.

Also accepted: authn for authentication; authz for authorization.

Why

They fail differently: a missing or bad credential is 401 Unauthorized (despite the name, an authentication failure), a valid user without the right is 403 Forbidden. Authorization must be checked on every object, not only at login: "is this invoice yours?" is the check most often forgotten.

Review this in your daily deck All cards in Security