Security › Authentication & Authorization
Credential
Anything used to prove identity: a password, key, token or certificate.
Also known as: credentials, login credentials
A credential is anything you present to prove who you are: a password, an API key, a token, a certificate, a passkey. It is the “authentication” half of authentication vs authorization.
Common kinds, by what they rely on:
| Kind | Examples |
|---|---|
| Something you know | Password, PIN |
| Something you have | Hardware key, phone with an authenticator app, client certificate |
| Something you are | Fingerprint, face |
| Issued to a program | API key, access token |
Why it matters
Whoever holds a credential is that identity as far as the system can tell. That is why so many breaches start with a leaked or guessed credential rather than a clever exploit.
The habits that follow from this:
- Never store passwords as plain text. Store a salted slow hash (see password hashing).
- Keep credentials out of code and Git. A key committed once should be treated as leaked. See secrets in Git.
- Don’t log them. Request logs, error messages and analytics events are common accidental leaks.
- Make them revocable and short-lived where you can, so a stolen one stops working.
- Add a second factor (MFA) so a password alone isn’t enough.
Credentials you hand to your own software at runtime belong in a secrets store; see secrets management.