Authentication请求头与Authorization请求头的区别及最佳实践探讨
Great question—this is a common point of confusion, especially when mixing standard HTTP specs with custom implementations. Let’s break this down clearly so you can clean up that code with confidence.
First: What’s the Difference Between the Two Headers?
Authorization(Standard HTTP Header)
This is defined in the official HTTP spec (RFC 7235) and is the universal way to send authentication credentials from a client to a server. Spring Security is built to recognize this header by default—when you use aBearertoken here, Spring’s authentication filters will automatically pick it up to validate the user’s identity. Every developer familiar with HTTP or Spring Security will immediately understand what this header does.Authentication(Custom/Non-Standard Header)
This is not part of any official HTTP standard. It’s usually a custom header created by developers who mix up the naming, or for very specific business scenarios (like dual authentication requiring two separate credentials). There’s no universal behavior for this header—your Spring Security setup won’t process it unless you explicitly configure a custom filter to look for it.
Should You Use Both in Your Code?
In 99% of cases, no—you don’t need both. Here’s why:
- Redundancy: If
authorizationandauthenticationin your code hold the same token value, you’re sending duplicate data for no reason. This adds unnecessary overhead and confuses other developers reading your code. - Compatibility: Only the
Authorizationheader is supported out of the box by Spring Security. Unless you’ve written custom logic to handle theAuthenticationheader, your server will ignore it entirely—it’s just wasted bytes in the request. - Clarity: Sticking to standard headers makes your code more maintainable. Other developers won’t have to guess what a custom
Authenticationheader is supposed to do.
How to Fix Your Code
If your two token variables hold the same value, simplify your headers to only use the standard one:
const customHeaders = new HttpHeaders({ 'clientId': env.apiKey, 'Authorization': `Bearer ${authorization}` }); return this.http.get<UserInfo>(`${env.baseApi}/login`, { headers: customHeaders });
If authorization and authentication are actually different credentials (e.g., two separate tokens for dual-factor auth), you’ll need to:
- Confirm that your Spring Security backend is explicitly configured to process the
Authenticationheader via a custom filter. - Add clear comments in your code explaining why both headers are needed—this will save future developers from confusion.
Final Takeaway
Stick to the standard Authorization header unless you have a very specific, documented reason to use a custom Authentication header. It’s the most compatible, readable, and maintainable approach for Spring Security projects.
内容的提问来源于stack exchange,提问作者Stéphane GRILLON

