Authentication & Authorization
Proving who someone is, then deciding what they're allowed to do.
Almost every backend has to answer two questions on each request: who is this? (authentication) and are they allowed to do this? (authorization). Get the first wrong and attackers log in as your users. Get the second wrong and a logged-in user reads someone else’s data, which is the more common bug in practice.
As a junior, focus on the basics: hash passwords, understand sessions vs tokens, and return the right status codes. Token lifecycles, OAuth, and permission models come next. Key management and identity architecture can wait until you own a system.
Backend Engineer track
Junior
Write correct code, ship small changes safely, ask good questions.
Core: start here
- 401 Unauthorized vs 403 Forbidden401 means "I don't know who you are"; 403 means "I know who you are, and you can't do this."
- Authentication vs AuthorizationAuthentication proves who you are; authorization decides what you may do.
- Password HashingStoring a one-way, deliberately slow fingerprint of a password instead of the password itself.
- Secrets in GitWhy passwords and keys must never be committed, and what to do when one is.
- SessionServer-side memory of a logged-in user, referenced by a random ID the browser sends on each request.
8 more junior concepts
- API KeyA long random secret identifying a calling application rather than a user.
- Basic AuthenticationSending a username and password with every request, Base64-encoded.
- bcryptA widely supported password hashing algorithm with a tunable cost factor.
- Bearer TokenA token that grants access to whoever presents it, sent in the Authorization header.
- CookieA small piece of data the server asks the browser to store and send back automatically on later requests.
- CredentialAnything used to prove identity: a password, key, token or certificate.
- JWT (JSON Web Token)A signed, self-contained token carrying claims like user ID and expiry, verifiable without a database lookup.
- SaltA random value added to each password before hashing so identical passwords get different hashes.
Mid-level
Own a feature end to end without hand-holding.
Core: start here
- CSRFCross-Site Request Forgery: tricking a logged-in browser into sending a request the user didn't intend.
- OAuth 2.0A framework for letting an app act on a user's behalf without seeing their password.
- OpenID Connect (OIDC)An identity layer on top of OAuth 2.0 that adds login and a standard ID token.
- RBACRole-Based Access Control: permissions are granted to roles, and users are given roles.
- Refresh TokenA long-lived credential used only to get new short-lived access tokens without logging in again.
13 more mid-level concepts
- Access TokenA short-lived token sent with each API request to prove the caller is authenticated.
- Account EnumerationLeaking whether an email is registered through login, signup or reset responses.
- Argon2The current recommended password hashing algorithm; memory-hard to resist GPU cracking.
- Identity Provider (IdP)The service that authenticates users for other apps, like Okta, Auth0 or Google.
- JWT ClaimsThe fields inside a JWT payload, such as sub, exp, iat, iss and aud, and which to check.
- JWT Signing AlgorithmsHS256 (shared secret) vs RS256/ES256 (key pair), and when each fits.
- Login Rate LimitingSlowing or blocking repeated login attempts to stop password guessing.
- Multi-Factor Authentication (MFA)Requiring two or more kinds of proof: something you know, have, or are.
- Password Reset FlowDesigning reset links that are single-use, short-lived and don't leak account existence.
- PKCEAn OAuth extension that stops stolen authorization codes from being exchanged by attackers.
- SameSite CookiesA cookie attribute controlling whether cookies are sent on cross-site requests.
- Token ExpiryChoosing how long tokens live, and handling what happens when they run out.
- TOTPTime-based one-time passwords, the 6-digit codes from authenticator apps.
Senior
Own a system, its failure modes, and its trade-offs.
Core: start here
- Refresh Token RotationIssuing a new refresh token on every refresh and invalidating the old one, so reuse of an old token reveals theft.
13 more senior concepts
- ABACAttribute-Based Access Control: decisions based on attributes of user, resource and context.
- Client Credentials FlowThe OAuth 2.0 flow for machine-to-machine calls with no user involved.
- Credential StuffingAutomated logins using username/password pairs leaked from other sites.
- DAC, MAC and PBACOwner-controlled, centrally mandated and policy-based access control.
- JWKSJSON Web Key Set: a published endpoint of public keys used to verify signed tokens.
- mTLSMutual TLS: both client and server present certificates, common for service-to-service auth.
- Passkeys (WebAuthn)Phishing-resistant login with device-bound key pairs instead of passwords.
- ReBACRelationship-Based Access Control, as in Google Zanzibar: access follows relationships like owner or member.
- SAMLAn older XML-based standard for enterprise SSO, still common in B2B.
- Session FixationAn attack where the attacker sets a victim's session ID before login; fixed by rotating the ID on login.
- Signing Key RotationReplacing token signing keys regularly without invalidating every live token.
- Single Sign-On (SSO)Logging in once with an identity provider and accessing many apps.
- Token RevocationStrategies for invalidating tokens before they expire: denylists, versioning, short lifetimes.
Staff
Shape how many teams build, across systems.
- Auth System MigrationMoving users to a new identity system or hashing scheme without forcing everyone to log in again.
- Build vs Buy for IdentityDeciding between an in-house auth system and a provider like Auth0, Keycloak or Cognito.
- Identity ArchitectureDesigning how identity, sessions and permissions work across many services and teams.
- Zero TrustTreating every request as untrusted regardless of network location, verifying identity everywhere.
Principal
Set technical direction for the organization.
Nothing here yet.
Frontend Engineer track
Junior
Build UI that works, ship small changes safely, ask good questions.
Core: start here
- Authentication vs AuthorizationAuthentication proves who you are; authorization decides what you may do.
- CookieA small piece of data the server asks the browser to store and send back automatically on later requests.
- JWT (JSON Web Token)A signed, self-contained token carrying claims like user ID and expiry, verifiable without a database lookup.
- Secrets in GitWhy passwords and keys must never be committed, and what to do when one is.
6 more junior concepts
- 401 Unauthorized vs 403 Forbidden401 means "I don't know who you are"; 403 means "I know who you are, and you can't do this."
- API KeyA long random secret identifying a calling application rather than a user.
- Basic AuthenticationSending a username and password with every request, Base64-encoded.
- Bearer TokenA token that grants access to whoever presents it, sent in the Authorization header.
- CredentialAnything used to prove identity: a password, key, token or certificate.
- SessionServer-side memory of a logged-in user, referenced by a random ID the browser sends on each request.
Mid-level
Own a feature end to end without hand-holding.
Core: start here
- CSRFCross-Site Request Forgery: tricking a logged-in browser into sending a request the user didn't intend.
- OAuth 2.0A framework for letting an app act on a user's behalf without seeing their password.
- Refresh TokenA long-lived credential used only to get new short-lived access tokens without logging in again.
8 more mid-level concepts
- Access TokenA short-lived token sent with each API request to prove the caller is authenticated.
- Identity Provider (IdP)The service that authenticates users for other apps, like Okta, Auth0 or Google.
- Multi-Factor Authentication (MFA)Requiring two or more kinds of proof: something you know, have, or are.
- OpenID Connect (OIDC)An identity layer on top of OAuth 2.0 that adds login and a standard ID token.
- Password Reset FlowDesigning reset links that are single-use, short-lived and don't leak account existence.
- PKCEAn OAuth extension that stops stolen authorization codes from being exchanged by attackers.
- SameSite CookiesA cookie attribute controlling whether cookies are sent on cross-site requests.
- Token ExpiryChoosing how long tokens live, and handling what happens when they run out.
Senior
Own an app's architecture, performance, and failure modes.
- Account EnumerationLeaking whether an email is registered through login, signup or reset responses.
- Passkeys (WebAuthn)Phishing-resistant login with device-bound key pairs instead of passwords.
- Refresh Token RotationIssuing a new refresh token on every refresh and invalidating the old one, so reuse of an old token reveals theft.
- Single Sign-On (SSO)Logging in once with an identity provider and accessing many apps.
Staff
Shape how many teams build, across apps.
Nothing here yet.
Principal
Set technical direction for the organization.
Nothing here yet.