Skip to content
>devspeak
← glossary
level 5APIs & Communication

Authorization

also: authz, authorize, authorized, access control, permission check

Deciding what someone is allowed to do once you know who they are. For example, only admins can delete posts, and customers only see their own orders.

a bit more technical

Enforcing permissions for an authenticated identity: which data it can read and which actions it can take. Implemented as role checks, ownership checks ("is this your order?") or database rules like Postgres row-level security. It must be enforced on the server, not just hidden in the interface.

picture it

Your hotel key card. Every guest has shown ID at the desk, but your card only opens your room and the gym, not anyone else's room.

why it matters

Agents sometimes hide a button and call it done. Real authorization is checked on the server for every request. Knowing the difference lets you ask the question that prevents data leaks.

what your agent might say
agent
Any logged-in user can currently call DELETE /api/posts/:id. I'll add an authorization check so only the author or an admin can delete a post.
how you might use it
you → your agent
Check every endpoint that returns customer data. Confirm the server verifies the record belongs to the logged-in user, not just that someone is logged in.
common mistake

Thinking hiding a button is enough. If the server doesn't check permissions, anyone can call the endpoint directly.

builds on