Authentication establishes a requester’s identity. A service verifies evidence such as a password, passkey, or one-time code and then creates a session.
The identity badge changes only after the evidence passes the check. A valid session does not grant access to every resource; each action still needs authorization.
When to use
Use it to establish identity for sign-in, API calls, and administrative actions.