Identity vs authentication: why a login is not an ID
Identification, identity proofing, authentication and authorisation are four different things. What separates them and what it means for passkeys and eID.
Digital identityPublished
Authentication answers “is this the same person as before?”, while identification and identity proofing answer “who is this person?”. A login can be extremely secure and still tell a service nothing reliable about who you are. Mixing these questions up is behind many security failures and many privacy problems, because services collect identity documents when a login would do, and trust a login when they actually need proof of identity.
Four questions, four names
| Question | Name | Example | Typical technology |
|---|---|---|---|
| Who do you say you are? | Identification | Typing a username, giving a name or customer number | Identifier, claim |
| Is that claim true in the real world? | Identity proofing or verification | A bank checks your passport, an authority checks the national register | eID, document check, in-person check |
| Are you the same one who registered? | Authentication | Signing in with a passkey, a one-time code or a hardware key | Passwords, passkeys, TOTP, security keys |
| What are you allowed to do? | Authorisation | Read-only access versus admin rights, approve a payment | Roles, policies, OAuth 2.0 scopes |
The US National Institute of Standards and Technology draws the same line in its Digital Identity Guidelines (SP 800-63), which treat identity proofing, authentication and federation as separate parts with separate assurance levels. The eIDAS Regulation in Europe also grades both aspects, as we explain under levels of assurance.
Why a login is not an ID
Think of a gym membership. The staff scan your card at the door, and that is authentication: the card is the same one issued to you. It tells the gym nothing about your legal name unless they asked for ID when you joined. Online it works the same way:
- A passkey proves that you hold a private key registered on an account. The service does not learn your name from it. See passkeys explained.
- A second factor such as an authenticator app raises the confidence that the person logging in is the account owner. It does not add any identity information. See two-factor authentication.
- An email address is an identifier you control, not proof of a legal identity. Anyone can create one with any name.
- A “Sign in with” button tells the service that an identity provider authenticated someone it calls by a certain identifier. The name and email claims are whatever the provider has on file, and the provider may not have verified them.
This is why a platform can have millions of users it can recognise instantly and still not know who any of them really are. Anonymity or pseudonymity is often fine and even desirable: you do not need to prove your name to read a forum. The trouble starts when a service that needs real identity, such as a bank or a government portal, relies on a plain login.
Where OpenID Connect fits
OpenID Connect (OIDC) is the standard that lets one service rely on another to authenticate a user. It is built on OAuth 2.0 (see OAuth 2.0), which handles authorisation, and adds an ID token: a signed statement that a user authenticated at a certain provider at a certain time, with optional claims such as name or email. The specification is at openid.net, and our page on OpenID Connect explains it in more detail.
What OIDC does not do by itself is guarantee that the claims are verified. The relying service decides how much to trust the provider. If it needs verified identity data, it must ask for it and the provider must be able to supply it, for example through the OpenID Connect for Identity Assurance extension or through a government-grade eID. Our history section, for example the story of how OpenID became OpenID Connect, shows how the original OpenID was also an authentication protocol and why it did not carry identity proof.
What this means for EU digital identity
In the EU framework the separation is explicit.
- eID schemes under eIDAS combine identity proofing and authentication. A scheme at assurance level “high” requires a strict enrolment check and a strong authenticator, which is why it can be used for government services and bank onboarding.
- The EUDI Wallet keeps the two apart. The wallet holds attestations, such as person identification data issued by a government. Unlocking it with a PIN or biometrics is local authentication. Presenting an attestation to a service is proof of identity attributes. The service chooses which attributes it asks for.
- Age and attribute checks often need no identity at all. Proving “over 18” is a claim about an attribute, not about a person’s name.
The EUDI Wallet guide covers how these pieces fit together.
Practical rules of thumb
- For services: ask yourself whether you need to recognise a returning user or know who they are. Recognition needs authentication. Knowing needs identity proofing at a stated assurance level. Collect the minimum.
- For users: strengthen authentication everywhere with passkeys or a second factor, and share identity documents only with services that have a legal reason to ask for them.
- For developers: do not treat an OIDC email claim as verified identity unless the provider says it is. Check the claims about verification.
- For everyone: if someone says “we verified you with a login”, ask what was verified and by whom. See also our primer on what a digital identity is for the broader picture.
Frequently asked questions
What is the difference between identification and authentication?
Identification is the claim or determination of who someone is, for example giving a name or an ID number. Authentication is proving that you control the credential tied to that claim, for example a password, passkey or hardware key. Identity proofing is the separate step of checking real-world evidence.
Does a passkey prove who I am?
It proves that you control a particular key that the service registered earlier. It does not prove your name unless the account was linked to a verified identity at sign-up. Passkeys are about authentication, not identity proofing.
Does OpenID Connect verify my identity?
OpenID Connect delivers a login result and some claims from an identity provider. Whether those claims were verified in the real world depends on the provider. Extensions such as OpenID Connect for Identity Assurance exist for providers that want to deliver verified identity data.
Where does authorisation fit in?
Authorisation decides what an authenticated user may do, for example read a file or approve a payment. It is a third question after who you are and whether it is really you. OAuth 2.0 is the common standard for delegated authorisation.
What do eIDAS levels of assurance cover?
They grade both parts: how reliably the identity was verified at enrolment and how strong the authentication method is. A scheme with a high level combines careful identity proofing with a strong authenticator.
More in Digital identity
Digital identity for banking: eID vs video ident
How banks verify your identity online: eID, video identification or bank-issued IDs. What the new AML rules from 2027 and the EUDI Wallet change for onboarding.
eIDAS 2.0 explained: what the EU identity law changes
eIDAS 2.0 (Regulation (EU) 2024/1183) obliges every EU country to offer a digital identity wallet. Key dates, what changes for citizens, and who must accept it.
EU age verification app: the blueprint explained
The EU age verification blueprint lets you prove you are over 18 without revealing who you are. How it works, who pilots it and how it ties into the DSA.
EU Digital Identity Wallet (EUDI Wallet) explained
What the EU Digital Identity Wallet is, what you can store in it, how it works technically and where it stands in October 2026. Free and voluntary.
EU Digital Identity Wallet FAQ: your questions answered
Quick answers on the EU Digital Identity Wallet: cost, whether it is mandatory, availability by country, privacy, lost phones, children and non-EU residents.
EU wallet security: phishing, lost phones, fake verifiers
How secure is the EU Digital Identity Wallet? Risks such as phishing, a lost phone, malware and fake verifiers, built-in protections and your checklist.