Authentication vs Authorization: What’s the Difference?
Authentication proves who you are; authorization decides what you may do. They run in that order and are separate concerns: a system first establishes identity — a password, a passkey, a certificate — then checks that identity against a policy to permit or deny an action. Confusing them is a common source of security bugs. For agents the split is sharper still: proving which agent acts is one problem, bounding what it may do is another.
Two questions, two answers
A valid login proves identity but says nothing about permissions; a permission check assumes identity is already established. Systems get this wrong by conflating them — trusting that a logged-in user may do anything, or checking permissions without really knowing who is asking.
For an agent the two map to distinct estate layers: authentication is a key the agent holds and proves; authorization is the scoped, least-privilege grant that says what that proven identity may commit — which is why the estate separates identity from the grant that governs it.
Related standards
Questions
Which comes first?
Authentication — you must know who the actor is before you can decide what it is allowed to do.
Is OAuth authentication or authorization?
OAuth is an authorization framework; it is often paired with an identity layer (like OpenID Connect) to also handle authentication.
Keep reading
By Michael Gord · published 2026-10-09 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.