Authentication

Authentication vs Authorization: What Developers Need to Know

Signing a person in and granting an application scoped access are related decisions, but they are not the same state.

Authentication answers who is at the keyboard. Authorization answers what a particular application has been allowed to access. A successful sign-in does not give every connected app every identity claim.

Two decisions, one journey

Imagine a person opens a scheduling app. First, Bhauu Auth may authenticate that person with their Bhauu Identity. Then the app requests authorization for documented scopes. The resulting grant belongs to that registered client; it is not a blanket permission for other applications. OAuth is an authorization framework, not a universal authentication protocol by itself.

Four states to keep separate

  • Bhauu authentication session: the person's sign-in state at Bhauu Auth.
  • OAuth authorization: the connected app's client-specific permission and consent.
  • Access token: a time-limited credential for scoped API access, not the application's session cookie.
  • Application-owned session: the app's own local login state, which that app must secure and expire.

These states can change at different times. For example, revoking a Bhauu authorization can stop future refresh capability, while an already issued short-lived access token may work until expiry unless current status is checked. A client application's existing local session also needs its own revalidation or expiry policy; Bhauu Auth cannot simply erase that app's cookie.

Where Bhauu Auth fits

Bhauu Auth combines hosted authentication with OAuth authorization for registered applications using one canonical Bhauu Identity. A backend can validate the authorization result and create its own protected application session. Client registration, scopes, and server policy govern access; merely knowing the user's identity does not grant another app's data.

Takeaway

Name the state you are checking before making a security decision. The OAuth guide covers the authorization flow; Sessions and continuity explains the different session boundaries.