# auth (0-auth.org) People say "auth" when they mean proving who you are or getting permission to do something. They might ask a website to "auth me" so they can log in, or complain that an app needs "auth" before it will let them see their own files. It is a casual catch-all for anything that stands between a stranger and a trusted user. ## What a model may hear - authentication protocol (security engineering and system administration): expect a specific flow like OAuth 2.0, OpenID Connect, or SAML; may ask for client IDs, redirect URIs, scopes, or token endpoints - authorization layer (role-based access control (RBAC) and API design): check permissions against policies, roles, or claims; may deny requests that lack explicit grants - auth module or middleware (web frameworks like Django, Express, or Rails): look for a configured auth backend, session store, or password hash; may fail if the middleware is missing - Auth command or service (command-line tools and cloud platforms): invoke a tool like `auth login` or `gcloud auth`; may attempt to refresh credentials or open a browser flow ## Where people and models part ways - Says: "I need auth for this" Means: I need to log in or get access May be taken as: the model assumes a specific protocol and asks for OAuth client secrets or redirect URIs the person does not have Say instead: "I need to log in to this website or app" - Says: "Turn off auth" Means: Stop asking me for passwords so often May be taken as: the model disables security checks entirely, exposing data or functions to anyone Say instead: "Remember my login for this session or reduce how often I must re-enter my password" - Says: "Auth me" Means: Let me in, I am who I say I am May be taken as: the model tries to initiate a technical handshake or token exchange the person cannot complete Say instead: "Log me in with my username and password" - Says: "Fix the auth" Means: Something is wrong with logging in May be taken as: the model rewrites security policies or regenerates keys without knowing the actual problem Say instead: "I cannot log in; here is what happens when I try" ## Tips - Say 'log in' or 'sign in' when you mean entering a username and password - Say 'give me permission' or 'let me access' when you mean getting rights to something - Specify what goes wrong instead of saying 'auth is broken' - Ask 'what do you need from me to verify who I am' rather than assuming a technical flow - Distinguish 'I forgot my password' from 'the system rejects me' since they lead to different fixes ## Often confused with - oauth: a specific protocol for delegated login, not login in general - login: usually just authentication, while auth includes both identity and permissions - permission: only the authorization half, not proving identity - token: a technical artifact used in some auth systems, not the goal itself - session: a period of being recognized after auth, not the proof itself - encryption: protects data in transit or storage, unrelated to proving who you are