Answer
Authentication verifies user identity in Web API.
Common implementations:
- JWT Bearer Tokens – stateless authentication for SPA and mobile apps.
- OAuth2 / OpenID Connect – external identity providers.
- Cookie authentication – mainly for browser-based apps.
Configured using AddAuthentication() and UseAuthentication().