API & Security

Authentication

15•Medium

Authentication is the process of verifying the identity of a user, application, or service before allowing it to access a system.

In simple terms:

Authentication answers: "Who are you?"

For example, when you log in to an application using an email and password, the application verifies that those credentials belong to you.

1.1 Authentication vs Authorization

Authentication and authorization are related but solve different problems.

AuthenticationAuthorization
Verifies identityDetermines permissions
Answers "Who are you?"Answers "What can you access?"
Happens firstUsually happens after authentication
Uses passwords, tokens, sessions, OAuth, etc.Uses roles, permissions, policies, scopes, etc.

1.2 Stateful vs Stateless Authentication

Authentication systems generally follow one of two approaches for maintaining the user's authentication state:

  • Stateful Authentication — the server stores authentication state.
  • Stateless Authentication — the server does not store authentication state for each user session.

The main difference is where the authentication state is maintained.

Stateful Authentication

  • In stateful authentication, the server maintains information about the user's authenticated session.
  • After successful login, the server creates a session and stores it in a session store such as memory, Redis, or a database.
  • The client receives a session ID, usually through a cookie.

The important point is that the session ID itself does not contain the complete authentication information.

The server uses the ID to find the corresponding session.

Stateless Authentication

  • In stateless authentication, the server does not maintain a session for each authenticated user.
  • Instead, the authentication information is contained inside a token.
  • A common implementation is JWT (JSON Web Token).
  • After successful login, the server generates a token and sends it to the client.

Stateful vs Stateless

FeatureStatefulStateless
Server stores sessionYesNo
Client storesSession IDToken
Server-side lookupUsually requiredUsually not required
Common implementationSession + CookieJWT / Access Token
Horizontal scalingMore complexEasier
Session revocationEasyMore difficult
Server-side controlHighLower
Token sizeSmall session IDUsually larger
Distributed systemsRequires shared session stateEasier to distribute

When to Prefer Stateful Authentication

  • Immediate session revocation is important.
  • The application requires strong server-side session control.
  • Sessions contain frequently changing server-side state.
  • The application is relatively simple and centralized.
  • The infrastructure already has a reliable shared session store.

When to Prefer Stateless Authentication

  • The system has many application servers.
  • Horizontal scaling is important.
  • Requests can be handled by any server.
  • Microservices need to validate authentication independently.
  • Reducing per-request session lookups is desirable.

Types of Authentication

There are many types of authentication mechanisms used in modern systems. Some of the commonly used ones are:

Next Topic Session-Based Authentication