Comparison matrix
Authentication vs Authority
One-sentence distinction
Authentication checks identity or credential control; authority defines the recognized power to make a particular decision or action.
Side-by-side matrix
| Dimension | Authentication | Authority |
|---|---|---|
| Primary question | What evidence establishes the first property for a named purpose? | What separate evidence or authority establishes the second property? |
| Evidence | Purpose-specific technical, factual, or institutional records. | Independent records appropriate to the second category. |
| Authority | May be descriptive or technical and may not require legal authority. | May require a competent legal, constitutional, organizational, or operational decision-maker. |
| Currentness | Can be current, stale, disputed, unknown, or unavailable. | Must be assessed separately; the first status does not transfer. |
| Failure condition | Evidence may be authentic but incomplete or unsuitable. | Authority may exist but rely on wrong or stale facts. |
Why the distinction matters
Authentication checks identity or credential control; authority defines the recognized power to make a particular decision or action. Systems and institutions fail when one side is used as a shortcut for the other. The distinction determines what evidence is collected, who may decide, what can be appealed, and which failure modes must be controlled.
Common failure caused by conflation
Allowing any authenticated account to exercise powers that were never lawfully granted.
This error can create false confidence, unauthorized status, misattributed liability, silent loss of correction rights, or an operational claim based only on descriptive material.
Implementation consequences
- Use different fields, identifiers, and claim-status records for each side.
- Require separate evidence and currentness checks.
- Do not let a user-interface label silently merge the categories.
- Preserve correction and supersession history for both.
- Route decisions to the ecosystem authority that owns the relevant function.
Legal consequences
Legal identity is conferred and recognized through applicable institutions and law, not solely through cryptographic proof.
Technical evidence can inform a legal decision but cannot replace jurisdiction, legal basis, procedural authority, due process, or remedy. Conversely, a lawful decision does not make the underlying technical record accurate if the evidence is stale or defective.
Examples
- A valid signature demonstrates control over a key and payload integrity; it does not establish the truth of every signed statement.
- A registry can record a citizenship decision; the registry operator does not thereby acquire constitutional power to create citizenship.
- A static release can show that software exists; it does not prove the service is currently operating.
Sources
- Decentralized Identifiers (DIDs) v1.0 — W3C; DID Core v1.0; W3C Recommendation. Exact claim-support entries: 2. Revalidated 2026-08-14T22:04:09Z.
- Verifiable Credentials Data Model v2.0 — W3C; Verifiable Credentials Data Model v2.0; W3C Recommendation. Exact claim-support entries: 2. Revalidated 2026-08-14T22:04:09Z.
- RFC 5280: Internet X.509 Public Key Infrastructure Certificate and CRL Profile — IETF; RFC 5280 with update chain; Proposed Standard. Exact claim-support entries: 2. Revalidated 2026-08-14T22:04:09Z.
- PROV-O: The PROV Ontology — W3C; W3C Recommendation 30 April 2013; W3C Recommendation. Exact claim-support entries: 2. Revalidated 2026-08-14T22:04:09Z.
Comparison claim record
Each proposition has a stable ID, status, scope, owning route, evidence relationship, currentness qualification, correction state, and synchronized JSON record. Record completeness does not make the proposition true.
Authentication versus Authority
Authentication checks identity or credential control; authority defines the recognized power to make a particular decision or action.
Support relationship
SRC-W3C-DID-CORE· Verification methods · QUALIFIES OR SUPPORTS WITHIN STATED SCOPESRC-W3C-DID-CORE· Services · QUALIFIES OR SUPPORTS WITHIN STATED SCOPESRC-W3C-VC-DM· Abstract · QUALIFIES OR SUPPORTS WITHIN STATED SCOPESRC-W3C-VC-DM· Ecosystem overview · QUALIFIES OR SUPPORTS WITHIN STATED SCOPESRC-RFC-5280· RFC status and update chain · QUALIFIES OR SUPPORTS WITHIN STATED SCOPESRC-RFC-5280· Certificate and CRL profile · QUALIFIES OR SUPPORTS WITHIN STATED SCOPESRC-W3C-PROV-O· Abstract and status · QUALIFIES OR SUPPORTS WITHIN STATED SCOPESRC-W3C-PROV-O· PROV-O at a glance · QUALIFIES OR SUPPORTS WITHIN STATED SCOPE