Authorizations are what are granted to an authenticated identity, typically with a specified scope and duration.
I've only ever seen authorization header containing credentials (i.e. authentication, who you are) instead of authorization (what you can do).
Also everyone returns 401 when unauthorized (i.e. can't do a thing), instead of 403 (forbidden, i.e. can't do the thing). When 401 should probably be "unauthenticated" (we don't know who you are, so we can't authorize you).
Always messes with my head a bit.
when I say `authorize who you are` I mean to say that you're saying both "hello I am in fact john doe" and "john doe the human is also saying this is ok to do".
I think this is interesting in the lens of Muse, GrokBot, Dots, OpenClaw, etc; if my agent wanted to rent a car on my behalf, it would forcibly have to get approval from me to do so