Module
Module 2 of 5Lesson 1 of 3~17 min

Authentication, authorization and sessions

Lesson 1 of the module "Knowing who signs in" in the course "Design authentication and permissions for a product".

Lesson objective

By the end of this lesson, you will be able to distinguish authentication, authorization and session, explain what a session cookie and a token (JWT, refresh token) change, and specify your product's session durations, sign-out and access revocation.

Where it fits

Knowing who signs in

How do you verify users' identity, keep their session and give them access back without opening a security hole?

Lessons in this module

  1. Authentication, authorization and sessions (this lesson)
  2. Passwords and account recovery
  3. Two-factor authentication and passkeys

What you will learn in the course

This lesson is part of the course Design authentication and permissions for a product

  • Distinguish authentication, authorization and session, and specify session durations, sign-out and access revocation.
  • Specify password rules and account recovery journeys following current recommendations (NIST SP 800-63B-4, CNIL, OWASP).
  • Choose strong authentication factors (TOTP app, passkeys), plan their rollout and specify the fallback journeys.
  • Specify delegated sign-in (OpenID Connect, social login) and enterprise SSO (SAML, OIDC, SCIM provisioning) for a B2B product.
  • Design a permission model (roles, attributes, scope) as a roles × actions matrix, enforced on the server side according to least privilege.
  • Specify isolation between customers, invitations, the audit log, support access and account deletion.
  • Specify your product's complete sign-in journeys, with states and errors, and choose between building and using an authentication provider.