---
title: "Credential"
description: "a held identity that is a key, a token, a certificate or a signed request; only in the secrets manager, never returned"
section: concepts
address: /concepts/credential
contract: 0476e35e6e275db5
---

# Credential

a held identity that is a key, a token, a certificate or a signed request; only in the secrets manager, never returned

[figure: Credential is a definition at follows scope. The drawing shows its fields and the objects that they point at.]

| property | value |
|---|---|
| kind | definition |
| scope | follows |
| key |  |
| store | vault |
| family | sources |



## Fields


| field | type | required | note |
|---|---|---|---|
| `platform` | `text` | yes |  |
| `kind` | `one of an API key \| a bearer token \| OAuth 2 \| OAuth 1 \| basic \| a signed request \| a service account \| a client certificate \| an SSH key \| a webhook secret` | yes |  |
| `scopes` | `[text]` | yes | as granted, never as asked |
| `owner` | [Scope](/concepts/scope) | yes | the platform, or a tenant |
| `vault_entry` | `id` | yes |  |
| `last_probe` | [ControlResult](/concepts/controlresult) | no |  |
| `rotation` | `duration` | no | the rule |
| `state` | [Readiness](/concepts/readiness) | yes |  |



## Routes that use it
No route takes or returns Credential directly. The record holds it, and the objects that point at it reach it.
