Authentication
also: authn, authenticate, authenticated, unauthenticated, authenticating
Checking who someone is, usually by having them log in. It answers one question: are you really who you say you are?
Verifying the identity of a user or system, via passwords, magic links, OAuth ("Sign in with Google"), passkeys or API keys. Afterward the server issues a session or token so later requests are recognized. It's separate from authorization, which decides what that identity may do.
Showing your ID at a hotel front desk. The clerk confirms you're the person on the booking. Which rooms you can enter is a separate question.
Login problems are common and high-stakes. Knowing authentication is only about identity helps you tell your agent exactly what's broken: proving who someone is, or what they can do afterward.
The API returns 401 because the request has no session cookie, so the user isn't authenticated. The frontend isn't sending credentials.
Add email sign-in links (magic links) using the auth library we already have. Don't build our own password storage.
Using "auth" for both authentication and authorization. Logging in proves who you are. It doesn't decide what you're allowed to see.