Authentication
Authentication is the process of verifying the identity of a user, application, or service before allowing it to access a system.
In simple terms:
Authentication answers: "Who are you?"
For example, when you log in to an application using an email and password, the application verifies that those credentials belong to you.
1.1 Authentication vs Authorization
Authentication and authorization are related but solve different problems.
| Authentication | Authorization |
|---|---|
| Verifies identity | Determines permissions |
| Answers "Who are you?" | Answers "What can you access?" |
| Happens first | Usually happens after authentication |
| Uses passwords, tokens, sessions, OAuth, etc. | Uses roles, permissions, policies, scopes, etc. |
1.2 Stateful vs Stateless Authentication
Authentication systems generally follow one of two approaches for maintaining the user's authentication state:
- Stateful Authentication — the server stores authentication state.
- Stateless Authentication — the server does not store authentication state for each user session.
The main difference is where the authentication state is maintained.
Stateful Authentication
- In stateful authentication, the server maintains information about the user's authenticated session.
- After successful login, the server creates a session and stores it in a session store such as memory, Redis, or a database.
- The client receives a session ID, usually through a cookie.

The important point is that the session ID itself does not contain the complete authentication information.
The server uses the ID to find the corresponding session.
Stateless Authentication
- In stateless authentication, the server does not maintain a session for each authenticated user.
- Instead, the authentication information is contained inside a token.
- A common implementation is JWT (JSON Web Token).
- After successful login, the server generates a token and sends it to the client.

Stateful vs Stateless
| Feature | Stateful | Stateless |
|---|---|---|
| Server stores session | Yes | No |
| Client stores | Session ID | Token |
| Server-side lookup | Usually required | Usually not required |
| Common implementation | Session + Cookie | JWT / Access Token |
| Horizontal scaling | More complex | Easier |
| Session revocation | Easy | More difficult |
| Server-side control | High | Lower |
| Token size | Small session ID | Usually larger |
| Distributed systems | Requires shared session state | Easier to distribute |
When to Prefer Stateful Authentication
- Immediate session revocation is important.
- The application requires strong server-side session control.
- Sessions contain frequently changing server-side state.
- The application is relatively simple and centralized.
- The infrastructure already has a reliable shared session store.
When to Prefer Stateless Authentication
- The system has many application servers.
- Horizontal scaling is important.
- Requests can be handled by any server.
- Microservices need to validate authentication independently.
- Reducing per-request session lookups is desirable.
Types of Authentication
There are many types of authentication mechanisms used in modern systems. Some of the commonly used ones are:
-
Session-Based Authentication
-
Token-Based Authentication
-
JWT-Based Authentication
-
OAuth 2.0
-
OpenID Connect (OIDC)
-
API Key Authentication
-
Basic Authentication
-
SSO (Single Sign-On)
-
Multi-Factor Authentication (MFA)
-
Certificate-Based Authentication
-
Passwordless Authentication