Field Manual PHP / Laravel reference
← Security

Authentication versus authorization

Authentication identifies the actor; authorization determines permitted actions.

What it is

Authentication identifies the actor; authorization determines permitted actions.

When to use it

Apply both when handling protected financial data.

Syntax

Route::middleware("auth")->group(function () {
    // Then Gate::authorize(...) for each resource operation.
});

Example

public function show(Account $account)
{
    Gate::authorize("view", $account);
    return response()->json(["id" => $account->id]);
}
// Protect the route with auth middleware too.

Common mistakes

Login alone does not establish account ownership; do not trust a client-provided role.

Related topics

AuthenticationAuthorizationAuthentication