Credential
Pronunciation: krih-DEHN-chul
Definition
A credential is information, a cryptographic object, or a device used to establish identity, authority, qualification, or access rights. A credential provides evidence supporting a claim about a person, service, device, organization, or account. Examples include passwords, API keys, certificates, access tokens, identity documents, private keys, security devices, and digitally signed attestations. Their reliability depends on issuer trust, enrollment, binding to the holder, integrity, scope, expiration, revocation, presentation, and protection against copying or replay.
Overview
A credential provides evidence supporting a claim about a person, service, device, organization, or account. Examples include passwords, API keys, certificates, access tokens, identity documents, private keys, security devices, and digitally signed attestations.
Some credentials authenticate identity, while others prove authorization, status, or qualification. Their reliability depends on issuer trust, enrollment, binding to the holder, integrity, scope, expiration, revocation, presentation, and protection against copying or replay.
Organizations should inventory credentials, apply least privilege, protect secrets, separate environments, rotate or renew appropriately, and revoke access promptly. A credential should never be treated as permanent truth when the underlying identity, role, or authorization can change. Presentation does not necessarily prove current possession.
For Credential, inventory and version history are important because obsolete rules, credentials, models, or documentation can silently remain active.
Unlike an identity record, a Credential is used to present evidence or authority within a specific verification process; for example, possession of an API key can authenticate a client without proving a human identity.
A credential is information, a cryptographic object, or a device used to establish identity, authority, qualification, or access rights. A credential supports a claim only within its issuer, scope, validity, holder-binding, and revocation rules.
For Credential, the trust decision should establish information, a cryptographic object, or a device used to establish identity, authority, qualification, or access rights and bind the result to the requested action and protected resource. Teams should test issuance, storage, validation, expiry, revocation, recovery, and privileged override for information, cryptographic object, and device used to establish identity, rather than checking only a successful request. Logs concerning the Credential context and information, cryptographic object, and device used to establish identity should support investigation without exposing reusable secrets or unnecessary personal data.
Key Takeaway
A credential supports a claim only within its issuer, scope, validity, holder-binding, and revocation rules.
Sources
- NIST Documentation: Cryptographic Standards And Guidelines — NIST (2026-07-30)