Authentication vs Authorization: What Developers Need to Know
Signing a person in and granting an application scoped access are related decisions, but they are not the same state.
Authentication answers who is at the keyboard. Authorization answers what a particular application has been allowed to access. A successful sign-in does not give every connected app every identity claim.
Two decisions, one journey
Imagine a person opens a scheduling app. First, Bhauu Auth may authenticate that person with their Bhauu Identity. Then the app requests authorization for documented scopes. The resulting grant belongs to that registered client; it is not a blanket permission for other applications. OAuth is an authorization framework, not a universal authentication protocol by itself.
Four states to keep separate
- Bhauu authentication session: the person's sign-in state at Bhauu Auth.
- OAuth authorization: the connected app's client-specific permission and consent.
- Access token: a time-limited credential for scoped API access, not the application's session cookie.
- Application-owned session: the app's own local login state, which that app must secure and expire.
These states can change at different times. For example, revoking a Bhauu authorization can stop future refresh capability, while an already issued short-lived access token may work until expiry unless current status is checked. A client application's existing local session also needs its own revalidation or expiry policy; Bhauu Auth cannot simply erase that app's cookie.
Where Bhauu Auth fits
Bhauu Auth combines hosted authentication with OAuth authorization for registered applications using one canonical Bhauu Identity. A backend can validate the authorization result and create its own protected application session. Client registration, scopes, and server policy govern access; merely knowing the user's identity does not grant another app's data.
Takeaway
Name the state you are checking before making a security decision. The OAuth guide covers the authorization flow; Sessions and continuity explains the different session boundaries.