> How are authn and authz different? To put it simply, authn has to do with identity, or who someone is, while authz has to do with permissions, or what someone is allowed to do.
> How are authn and authz different? To put it simply, authn has to do with identity, or who someone is, while authz has to do with permissions, or what someone is allowed to do.
I guess it's awkward that those two related but different concepts share the same first 4 letters. But I think authc would have been clearer for disambiguation than authn.
I now agree with you that "autho" would have been better for the same reason. Although "authz" sounds cooler :)
I can say "auth service" and it's well understood, even to the user, that service identifies them and determines their permissions.
And we kind of do, in other (but closely related) contexts; e.g., the common cloud systems for managing both are “identity and access management systems" not “authentication and authorization management systems”.
(Though, yes, “access" sometimes means something else; nothing is perfect.)
<https://www.etymonline.com/word/authority>
<https://www.etymonline.com/word/author>
So an author is one who creates, but also a "source of authoritative information or opinion".
Confusingly, authentic seems to have a different etymology, *autos "self" (see auto-) + hentes* "doer, being".
<https://www.etymonline.com/word/authentic>
So to authenticate an author as an authority derives three meanings from two separate roots.