# What does auth mean?

Auth decides who can sign in and what that person is allowed to do.

> Source: https://www.mainpath.ai/en/wiki/auth/

## What it is

Auth is sign-in and permission, two steps that often share one word. First the system checks who is there. Then it checks what that person may see, change, or publish. The first is authentication, the second is authorization. In everyday speech both are called auth.

Once more than one person works on a project, the question is no longer only whether someone knows the password, but which role that person has.

## What it is made of

Sign-in means an account, a secret or a second factor, a session that lasts for a while, and a way to reset the password. Permission means roles. Someone may read a project, someone may change it, someone may put it on the server. Without that split, every signed-in person is an administrator.

## What goes wrong

Building that yourself repeats. Accounts, sessions, “forgot password”, invites, locking an access when someone leaves the team. Doing it again in every app is a project before the actual product, and mistakes there are not small mistakes.

## What you otherwise look after yourself

Sessions expire. Tokens do not belong in browser storage if they are allowed to do too much. A role that is set once and never checked is not a role.

## How it shows up on MainPath

On MainPath accounts and roles live in the organization. You invite people and say what they may do, instead of inventing a sign-in for every app.

