Skip to content

Glossary

What is user authentication?

User authentication is how an application confirms who a user is, through passwords, sign-in links, single sign-on or other methods, before giving access.

What it means

Authentication answers "who are you". Authorization, which usually comes next, answers "what are you allowed to do". Common methods include passwords with two-factor codes, email sign-in links, sign-in with Google or Microsoft, and single sign-on for companies.

Role-based access control then gives each user the permissions that fit their role.

Why it matters for a business

Weak authentication is one of the most common causes of breaches. Getting it right protects customer data and makes business customers more willing to buy, since many require single sign-on and two-factor sign-in.

A business example

Things to watch

  • Offer two-factor sign-in, at least for staff and admins.

  • Store passwords only as secure hashes, or avoid them.

  • Check permissions on the server for every request.

  • Log sign-ins and unusual activity.

Keep exploring

FAQ

Questions about user authentication

Have a question that is not here? Ask us directly.

Start a project

Tell us what you want to build. We will show you a faster path.

Send a short brief. We reply with questions, a suggested plan and an estimate you can compare with other offers.

Your privacy choices

We use necessary storage to run this site. With your permission we also use Google Analytics to see which pages help people, and load maps from Google. You can change this at any time. Read the cookie policy.