Contents

Security › Authentication & Authorization

Credential

Anything used to prove identity: a password, key, token or certificate.

Also known as: credentials, login credentials

A credential is anything you present to prove who you are: a password, an API key, a token, a certificate, a passkey. It is the “authentication” half of authentication vs authorization.

Common kinds, by what they rely on:

KindExamples
Something you knowPassword, PIN
Something you haveHardware key, phone with an authenticator app, client certificate
Something you areFingerprint, face
Issued to a programAPI key, access token

Why it matters

Whoever holds a credential is that identity as far as the system can tell. That is why so many breaches start with a leaked or guessed credential rather than a clever exploit.

The habits that follow from this:

  • Never store passwords as plain text. Store a salted slow hash (see password hashing).
  • Keep credentials out of code and Git. A key committed once should be treated as leaked. See secrets in Git.
  • Don’t log them. Request logs, error messages and analytics events are common accidental leaks.
  • Make them revocable and short-lived where you can, so a stolen one stops working.
  • Add a second factor (MFA) so a password alone isn’t enough.

Credentials you hand to your own software at runtime belong in a secrets store; see secrets management.