Remix.run Logo
▲ 0xWTF 4 hours ago

Uh, not sure I agree with your terminology - one does not authorize who you are. You authenticate yourself, certain tokens authenticate your identity with varying levels of strength (e.g. within a corporate enclave, you may have elevated authorizations if you are authenticating from a corporate device).

Authorizations are what are granted to an authenticated identity, typically with a specified scope and duration.

▲Knufferlbert 3 hours ago | parent | next [-]

Maybe related. I was always confused with the authorization header and 401 status code (unauthorized).

I've only ever seen authorization header containing credentials (i.e. authentication, who you are) instead of authorization (what you can do).

Also everyone returns 401 when unauthorized (i.e. can't do a thing), instead of 403 (forbidden, i.e. can't do the thing). When 401 should probably be "unauthenticated" (we don't know who you are, so we can't authorize you).

Always messes with my head a bit.

▲x401throaway 3 hours ago | parent | prev [-]

thank you for the clarification - thankfully some much smarter people than I are working on the protocol aspects :)

when I say `authorize who you are` I mean to say that you're saying both "hello I am in fact john doe" and "john doe the human is also saying this is ok to do".

I think this is interesting in the lens of Muse, GrokBot, Dots, OpenClaw, etc; if my agent wanted to rent a car on my behalf, it would forcibly have to get approval from me to do so