You open a Japanese business app and the screen says 承認待ち. You try to install a mobile app and it asks for 許可. You log in and are prompted for 認証コード. Then a developer colleague mentions OAuth認可. Four different words — all vaguely translatable as “approval,” “permission,” or “authorization” in English — and all used in completely different situations.
This confusion is not unique to learners. Even fluent Japanese speakers sometimes conflate 認証(にんしょう)and 認可(にんか)in casual speech. But in business workflows, IT systems, and administrative documents, these four words carry distinct meanings that matter. Using the wrong one in a workplace email or a technical specification will quietly mark you as someone who is guessing.
This article breaks down all four words — 承認(しょうにん), 許可(きょか), 認証(にんしょう), and 認可(にんか)— explains where each one belongs, and gives you the example sentences and decision rules you need to use them confidently.
| Word | Reading | Core Meaning | Who/What Acts | Typical Context | JLPT |
|---|---|---|---|---|---|
| 承認 | しょうにん | approval | A person or authority reviews and OKs a request or content | Business workflows, internal requests, project sign-off | N3–N2 |
| 許可 | きょか | permission | A person or authority allows an action that would otherwise be restricted | Photography rules, app permissions, entry permits | N4 |
| 認証 | にんしょう | authentication | A system verifies who you are | Login screens, two-factor auth, biometrics, verification codes | N2–N1 |
| 認可 | にんか | authorization / official authorization | A system or authority grants access rights or official sanction | OAuth flows, access rights, government licensing, permits | N2–N1 |
Quick Answer — 承認 vs 許可 vs 認証 vs 認可
承認 means approval (a person reviews and OKs content or a request)
承認(しょうにん)is the word for when a human being — a manager, an approver, a committee — looks at a request or document and formally says “yes, this is accepted.” The emphasis is on a person reviewing content and giving their stamp of approval. It is the vocabulary of business workflows: expense requests waiting in a queue, project proposals needing a director’s sign-off, and purchase orders traveling up an approval chain.
許可 means permission (a person allows an action)
許可(きょか)is about allowing an action that would otherwise be off-limits. The key distinction from 承認 is that 許可 focuses on the action being permitted, not on content being reviewed. A no-photography sign lifted by a curator is 許可. A smartphone app asking to access your location is requesting 許可. A building supervisor allowing contractors to enter the site grants 許可.
認証 means authentication (a system verifies who you are)
認証(にんしょう)belongs to the IT and security domain. It answers the question: is this person who they claim to be? When you enter a password, receive a six-digit code by SMS, scan your fingerprint, or pass a face recognition check, you are going through 認証. The system is not deciding what you can do — it is first confirming your identity.
認可 means authorization (a system or authority grants access rights)
認可(にんか)answers a different question: what is this (now-verified) person allowed to do? After 認証 confirms who you are, 認可 determines your permissions — which files you can read, which API endpoints you can call, which features you can access. In the government context, 認可 means official authorization: a business license, an operating permit, a regulated activity sanctioned by a ministry.
Why English speakers mix these up
English collapses much of this into two overloaded words: “approval” (which can mean 承認 or 認可) and “authorization” (which is used for both 認証 and 認可 — and even sometimes 許可). The IT shorthand “auth” compounds the problem because it is used for both authentication and authorization interchangeably. Japanese keeps these four concepts cleanly separated, which is precisely why the vocabulary is so useful once you learn it.
So 認証 is about identity, and 認可 is about what you are allowed to do?


Exactly. A common phrase in IT is "認証は誰か、認可は何ができるか" — authentication is who, authorization is what you can do. That one sentence covers the core distinction.
What Does 承認 Mean?
承認 as approval in business workflows
承認(しょうにん)is the cornerstone of Japanese workplace culture around decision-making. Nearly every internal request — a purchase order, a business trip expense, a new vendor contract, a policy change — travels through an approval chain where one or more approvers must formally 承認 it before it proceeds. This reflects the broader Japanese organizational value of 合意(ごうい)and collective decision-making.
The word 承認 itself combines 承(うけたまわる, to receive/accept)and 認(みとめる, to recognize/acknowledge). Together they convey the idea of receiving and formally acknowledging — accepting something as legitimate.
承認待ち / 承認済み / 承認フロー
In business software and workplace communication, you will frequently encounter these compound forms:
- 承認待ち(しょうにんまち) — awaiting approval; a request that has been submitted but not yet reviewed
- 承認済み(しょうにんずみ) — already approved; a request that has passed through the approval process
- 承認フロー(しょうにんフロー) — approval workflow; the sequence of approvers a request must pass through
- 承認者(しょうにんしゃ) — the approver; the person responsible for reviewing and approving
- 承認依頼(しょうにんいらい) — approval request; a notification asking someone to review and approve
稟議(りんぎ)and 上長承認
A concept closely tied to 承認 in Japanese companies is 稟議(りんぎ) — the circulating proposal document. A 稟議書(りんぎしょ)is a written proposal that gets passed around (physically or digitally) for multiple approvers to stamp or sign before a decision is made. It embodies the consensus-building approach to approval and is deeply embedded in Japanese corporate culture. Even in modern companies using workflow software, the 稟議 concept persists — the digital form goes through a 承認フロー where each 上長(じょうちょう, superior/manager)must 承認 it before it advances.
Common example sentences
申請が上長に承認されました。
My application was approved by my superior.
この企画書(きかくしょ)はまだ承認待ちです。
This project proposal is still awaiting approval.
承認フローが3段階(だんかい)あります。
The approval workflow has three stages.
稟議書を承認してください。
Please approve the circulating proposal document.
経費(けいひ)申請が承認済みになりました。
The expense request has been approved.
What Does 許可 Mean?
許可 as permission
許可(きょか)is about an authority permitting an action that would otherwise be restricted or prohibited. The focus is always on the action — what is being allowed — rather than on a document or request being reviewed. 許可 can come from a rule-setter (a venue, a company, a local government) or from a system (an operating system, a mobile app framework). When you see 許可する, think “to allow,” “to grant permission for.”
The word 許(ゆるす)means to forgive or allow, and 可(よし)indicates approval or feasibility — together they convey the sense of “it is acceptable to do this.”
写真撮影を許可する / 使用許可
In everyday Japanese life, 許可 appears frequently in signage, notices, and announcements:
- 写真撮影許可(しゃしんさつえいきょか) — photography permission; a sign or notice indicating that photography is (or is not) allowed
- 使用許可(しようきょか) — permission to use; commonly seen on forms, licenses, or when requesting the right to use content, space, or equipment
- 入場許可(にゅうじょうきょか) — entry permission; authorization to enter a restricted area
- 営業許可(えいぎょうきょか) — business operating permission; the permit a restaurant or shop must obtain from a local authority to operate
アプリの許可(カメラ・位置情報・通知)
In the mobile and digital context, 許可 is the standard word for the permission pop-ups that appear when an app requests access to device features. When your phone asks “このアプリにカメラへのアクセスを許可しますか?” (Do you want to allow this app to access your camera?), the word 許可 is being used in exactly this sense. Common app permission requests include:
- カメラの許可 — camera permission
- 位置情報(いちじょうほう)の許可 — location permission
- 通知(つうち)の許可 — notification permission
- マイクの許可 — microphone permission
- アクセス許可(アクセスきょか) — access permission (general term used in file systems, networks, and apps)
Common example sentences
この建物では写真撮影が許可されています。
Photography is permitted in this building.
アプリが位置情報へのアクセスを許可するよう求めています。
The app is asking you to allow access to your location.
使用許可を取得してから作業を始めてください。
Please obtain permission to use it before starting the work.
館長が特別展示室への入場を許可した。
The museum director permitted entry to the special exhibition room.
その操作(そうさ)は許可されていません。
That operation is not permitted.
What Does 認証 Mean?
認証 as authentication (proving identity)
認証(にんしょう)is the process of verifying identity. Before a system decides what you are allowed to do, it must first confirm that you are who you claim to be. That confirmation step is 認証. The word combines 認(みとめる, to recognize)and 証(しょう, proof/certificate)— together: “recognized proof” or “identity confirmed.”
In IT security, 認証 maps directly to the English term “authentication” (abbreviated “authn”). It answers the question: Is this really the user they say they are? Passwords, verification codes, biometric scans, and security keys are all 認証 mechanisms.
ログイン認証 / 二段階認証 / 生体認証
You will encounter 認証 in a wide range of security and login contexts:
- ログイン認証(ログインにんしょう) — login authentication; the standard process of verifying your identity when signing in
- 二段階認証(にだんかいにんしょう) — two-step verification; adding a second check (such as an SMS code) after a password
- 二要素認証(によそにんしょう) — two-factor authentication (2FA); technically distinct from two-step but used interchangeably in casual Japanese
- 生体認証(せいたいにんしょう) — biometric authentication; fingerprint, face ID, retina scan
- 多要素認証(たようそにんしょう) — multi-factor authentication (MFA)
- 認証済み(にんしょうずみ) — verified/authenticated; the status after successfully passing authentication
本人認証 / 認証コード
本人認証(ほんにんにんしょう) — literally “self-identity authentication” — is the phrase used when a system or service needs to confirm that the person interacting with it is actually the registered account holder. You see this phrase on banking apps, government portals (such as マイナンバー-related services), and e-commerce sites that handle sensitive information.
認証コード(にんしょうコード) is the one-time code sent to your phone or email to complete a verification step. You may also see 認証番号(にんしょうばんごう), which means the same thing. These are direct equivalents of “verification code” or “authentication code” in English.
Login and security examples
二段階認証を有効(ゆうこう)にすることをおすすめします。
We recommend enabling two-step verification.
認証コードをSMSに送りました。
We sent an authentication code to your SMS.
生体認証でスマートフォンのロックを解除(かいじょ)できます。
You can unlock your smartphone with biometric authentication.
ログイン認証に失敗しました。パスワードを確認してください。
Login authentication failed. Please check your password.
本人認証が完了(かんりょう)しました。
Identity verification has been completed.
What Does 認可 Mean?
認可 as authorization (granting access rights)
認可(にんか)picks up where 認証 leaves off. Once a system has confirmed who you are (認証), it needs to decide what you are allowed to do (認可). 認可 is the granting — or withholding — of access rights. In IT, it maps to “authorization” (abbreviated “authz”).
The word combines 認(みとめる, to recognize/acknowledge)and 可(よし/か, feasible/permitted)— “acknowledged as permitted.” In the IT world, 認可 determines which resources a verified identity can access and what operations they can perform on those resources.
In the administrative and legal world, 認可 has an additional, distinct meaning: official authorization by a public authority. A ministry or local government grants 認可 to a business, school, or organization, allowing it to operate in a regulated space. This is distinct from everyday 許可 in that 認可 implies a thorough vetting process and a legally recognized status.
アクセスを認可する / OAuth認可
In modern IT and API development, you will encounter 認可 primarily in these contexts:
- アクセスを認可する(アクセスをにんかする) — to authorize access; granting a user or system the right to access a resource
- 認可サーバー(にんかサーバー) — authorization server; the server in an OAuth flow responsible for issuing access tokens
- 認可コード(にんかコード) — authorization code; the temporary code issued in an OAuth authorization code flow
- 権限付与(けんげんふよ) — permission grant; the act of assigning access rights or roles to a user
- OAuth認可(OAuthにんか) — OAuth authorization; the protocol by which users grant third-party apps limited access to their data
行政認可 / 事業認可
Outside of IT, 認可 has deep roots in administrative and regulatory language:
- 行政認可(ぎょうせいにんか) — administrative authorization; official approval by a government body for an activity or entity to exist or operate legally
- 事業認可(じぎょうにんか) — business authorization; official sanction for a business to operate in a regulated sector (e.g., financial services, childcare, transportation)
- 認可保育所(にんかほいくしょ) — licensed daycare center; a childcare facility that has received official authorization from the local government (distinct from 認可外保育所, which operates without this official status)
- 認可取得(にんかしゅとく) — obtaining authorization; the process of receiving official government approval
IT and official authorization examples
このユーザーはそのリソースへのアクセスを認可されていません。
This user has not been authorized to access that resource.
認可サーバーがアクセストークンを発行(はっこう)します。
The authorization server issues the access token.
OAuth認可フローを通じて、アプリはユーザーのデータにアクセスできます。
Through the OAuth authorization flow, the app can access the user’s data.
その事業は国土交通省(こくどこうつうしょう)の認可を受けています。
That business has received authorization from the Ministry of Land, Infrastructure, Transport and Tourism.
認可保育所に子どもを預けたい。
I want to place my child in a licensed daycare center.


So 認証 happens first, and then 認可 happens after? They are in sequence?


In IT systems, yes — always in that order. You authenticate first (confirm identity), then the system authorizes what that identity can do. You can never have 認可 without 認証 first. But in the government context, 認可 stands alone and means official licensing — no authentication involved.
Pairwise Comparisons
承認 vs 許可 — approving content vs allowing action
These two words both involve a human authority giving a “yes,” but they differ in what the “yes” applies to.
| 承認 | 許可 | |
|---|---|---|
| Focus | Content / request is reviewed and accepted | An action is allowed |
| Actor | Approver (person with review authority) | Rule-setter (person or system with gate-keeping authority) |
| Object | A document, proposal, or request | An action (entering, photographing, accessing) |
| Typical verb pattern | 申請を承認する (approve the application) | 撮影を許可する (permit photography) |
| Status words | 承認待ち, 承認済み | 許可済み, 無許可 |
A practical way to distinguish them: if a manager is looking at a form and clicking “Approve,” that is 承認. If a security guard waves you through a gate, or a phone OS pops up asking if you want to let an app use your microphone, that is 許可.
認証 vs 認可 — “who you are” vs “what you can do”
In IT security this distinction is foundational. The mnemonic used by Japanese developers is:
認証は「誰か」を確認する。認可は「何ができるか」を決める。
Authentication confirms “who.” Authorization decides “what you can do.”
| 認証 | 認可 | |
|---|---|---|
| English term | Authentication (authn) | Authorization (authz) |
| Question answered | Who is this? | What can they do? |
| Timing | First step | Second step (after authentication) |
| Typical mechanism | Password, biometrics, OTP code | Roles, permissions, access tokens |
| Example | ログイン認証, 二段階認証 | OAuth認可, アクセス認可 |
許可 vs 認可 — everyday permission vs official authorization
Both 許可 and 認可 can be translated as “authorization” or “permission” in some contexts, which is why they get confused. The key difference is formality and institutional weight.
- 許可 is granted by anyone with the relevant authority — a venue manager, a system OS, a supervisor. It is transactional and situational.
- 認可 (in the administrative sense) is granted by a public authority after a formal vetting process. It creates a legal status — the entity that receives 認可 is now officially licensed to operate. You cannot simply withdraw it the next day.
A restaurant gets 営業許可 (operating permission) from the local health authority for its kitchen setup — that is actually a form of 認可 in formal legal language, though 許可 is the commonly used term in this specific context. A daycare center, on the other hand, specifically seeks 認可 status — because 認可保育所 vs 認可外保育所 is a formal legal distinction that affects subsidies and standards.
承認 vs 認可 in IT contexts
In IT, both 承認 and 認可 might seem to map to “approve,” but they are used in very different layers:
- 承認 in IT often refers to a human business process — a manager approving a pull request, a security team approving an access request ticket, or an admin approving a new user’s account creation.
- 認可 in IT is a system-level concept — the authorization layer that controls what an authenticated identity can do. It is the domain of access control lists, role-based access control (RBAC), and OAuth scopes.
Common Places You See These Words
社内申請 / 稟議フロー (business approval)
In Japanese workplace software — 経費精算システム, 勤怠管理ツール, 購買申請プラットフォーム — the language of 承認 is everywhere. Emails land in your inbox saying 「承認依頼が届いています」(You have an approval request). Buttons say 「承認する」or「差し戻す(さしもどす)」(approve / send back for revision). Status labels show 「承認待ち」or「承認済み」. Learning this vocabulary is essential for any professional working in or with Japanese companies.
アプリ権限リクエスト (app permission pop-up)
When you install an app on iOS or Android in Japan, permission requests appear in Japanese. The phrasing follows a consistent template: 「[アプリ名]が[機能]へのアクセスを求めています。許可しますか?」(App Name is requesting access to [feature]. Do you allow this?) The word 許可 is the standard choice here, not 承認 or 認可. Settings menus use terms like 「アプリの許可」or「アクセス許可の管理」.
ログイン画面 (login authentication)
Login and security screens in Japanese apps and services use 認証 vocabulary extensively. You will see 「認証中(にんしょうちゅう)」(authenticating) as a loading state, 「認証に失敗しました」(authentication failed) as an error message, and 「認証が完了しました」(authentication completed) as a success state. Two-factor authentication settings use 「二段階認証を設定する」, and email verification links say 「メールアドレスを認証する」.
API連携 / OAuth (authorization flow)
In modern web and app development, the OAuth 2.0 authorization framework is described in Japanese using 認可 as the core term. The authorization screen that appears when you click “Connect with Google” or “Sign in with Twitter” is called 認可画面(にんかがめん). The process of a user granting an app access to their data is 認可を与える(にんかをあたえる). Technical documentation for Japanese APIs uses phrases like 「認可サーバーにリクエストを送る」and 「認可コードをトークンと交換する」.
行政手続き (government authorization)
In Japan’s administrative context, 認可 signals that an entity has been officially vetted and licensed by a public authority. You will see this on signage, legal documents, and official websites: 認可保育所, 認可特定目的会社(にんかとくていもくてきがいしゃ), 認可通信事業者(にんかつうしんじぎょうしゃ). Seeking 認可 involves submitting detailed applications to the relevant ministry or local government and meeting specific legal standards. The outcome is a legally recognized status that changes how the entity is regulated, subsidized, and publicly trusted.
Common Mistakes English Speakers Make
Using 認証 when 認可 is needed (auth vs authz confusion)
This is by far the most common error among developers and tech learners. Because English uses “auth” as a shorthand for both authentication and authorization, it is tempting to reach for 認証 in both cases. But 認証 is specifically about verifying identity — not about what someone can do. If you are writing about access control, permission scopes, or OAuth access grants, the correct word is 認可, not 認証.
❌ Wrong: このユーザーは管理者権限の認証が必要です。
✅ Correct: このユーザーは管理者権限の認可が必要です。
This user needs authorization for administrator privileges.
Using 許可 for a formal business approval (should be 承認)
When talking about a manager formally reviewing and approving a business request, 許可 sounds too casual and action-oriented. The correct word for the business approval process is 承認. 許可 implies “allowing an action” — not “reviewing a document and signing off.”
❌ Wrong: 経費申請が部長に許可されました。
✅ Correct: 経費申請が部長に承認されました。
The expense request was approved by the department head.
Confusing 承認 and 認可 in IT contexts
In IT documentation, some writers use 承認 where 認可 is technically more precise, particularly when describing OAuth flows or access control systems. 承認 implies a human review process. If the process is automated and system-driven, 認可 is more accurate. However, in some company-internal access request processes — where a human manager must approve an employee’s request for elevated permissions — 承認 is used because a human is genuinely reviewing and approving the request.
Missing 承認待ち status in workflow emails
Non-native speakers sometimes miss the significance of the phrase 承認待ち in workplace communications. 承認待ち does not just mean “pending” — it means specifically “awaiting someone’s formal approval.” If you receive an email notification that says 「申請が承認待ちです」and you are listed as the 承認者, you are expected to take action. Treating it as a status update rather than a request for you to act is a cultural and linguistic miscommunication.
Translating “authorization” as 認証 (should be 認可)
English-Japanese machine translation frequently renders “authorization” as 認証, because the two words share the 認 character and both relate to “auth.” This is incorrect. Authorization = 認可. Authentication = 認証. When reviewing translated IT documentation or localizing software, always double-check that 認可 is used where “authorization” appears in the source text.
Decision Rule: Which Approval or Auth Word Should You Use?
Use this flowchart to choose the right word quickly:
Is a human reviewing and formally approving content or a request?
YES → 承認(しょうにん)
Examples: 経費申請の承認, 稟議の承認, プロジェクト承認
Is a person or rule-setter allowing an action that would otherwise be restricted?
YES → 許可(きょか)
Examples: 写真撮影許可, アプリのカメラ許可, 入場許可
Is a SYSTEM verifying WHO someone is?
YES → 認証(にんしょう)
Examples: ログイン認証, 二段階認証, 生体認証
Is a SYSTEM deciding WHAT someone can do (access rights/scopes)?
OR is an authority granting official regulatory status?
YES → 認可(にんか)
Examples: OAuth認可, アクセス認可, 行政認可, 認可保育所Here is a complete summary comparison table:
| Word | Reading | Domain | Core question | Who acts | Example compound |
|---|---|---|---|---|---|
| 承認 | しょうにん | Business / workflow | Is this content/request accepted? | Human approver | 承認待ち, 承認フロー |
| 許可 | きょか | Rules / access / apps | Is this action allowed? | Human or system rule-setter | アクセス許可, 使用許可 |
| 認証 | にんしょう | IT / security | Who is this person? | System (verifying identity) | 二段階認証, 生体認証 |
| 認可 | にんか | IT / government | What can they do? / Is this entity licensed? | System or public authority | OAuth認可, 行政認可 |
Quick Quiz
Fill in each blank with the correct word: 承認, 許可, 認証, or 認可.
1. 「スマートフォンのロックを解除するために指紋(しもん)_____ を使用しました。」
(I used fingerprint _____ to unlock my smartphone.)
2. 「部長が経費申請を_____ しました。」
(The department head _____ the expense request.)
3. 「このアプリは位置情報へのアクセス_____ を求めています。」
(This app is requesting location access _____。)
4. 「OAuthの_____ フローを実装(じっそう)してください。」
(Please implement the OAuth _____ flow.)
5. 「その保育園(ほいくえん)は市(し)の_____ を取得しています。」
(That nursery school has obtained city _____。)
6. 「稟議書が上長の_____ 待ちです。」
(The circulating proposal is awaiting superior _____。)
Answers: 1. 認証 | 2. 承認 | 3. 許可 | 4. 認可 | 5. 認可 | 6. 承認
If you want to practice these words further with a native speaker, italki connects you with Japanese tutors who can walk you through real-world business and IT contexts where these distinctions matter most.
Which of these four words have you seen most in your Japanese learning or workplace? Drop a comment below — we would love to hear where you encountered them and whether the distinction was clear!
Keep Learning





