Methods, credentials, and factors
The sign-in experience
When you sign in, one website asks for a password. Another sends you a code. Your work account might ask you to approve a notification, while your phone lets you use a fingerprint. These experiences look different because they collect different kinds of evidence that you control the account.
Imagine Avery starting a new job at Cedar Inc., a fictional company. Avery has an employee account and needs to open the staff portal. Typing an email address tells the service which account Avery wants to use. It does not show whether the person at the keyboard controls that account.
Authentication is the process of checking the evidence supporting that claim. Throughout this series, ask: what evidence did the service actually verify?
Naming the pieces
A few related terms help us describe the journey. Identifiers and credentials will be familiar from Secrets and key pairs. Products sometimes use these terms differently, so pay attention to the role each piece plays.
| Term | Meaning in this series | Example |
|---|---|---|
| Identifier | A value used to locate or distinguish an account. | Avery's account ID or sign-in email address. |
| Credential | The secret or key a person uses to prove that an account belongs to them. Formal standards may use the term more specifically for the record that binds an account to an authenticator. | A password, or a passkey registered to the account. |
| Authenticator | Something the person controls and uses to produce authentication evidence. | A memorized password, an authenticator app, or a security key. |
| Method | The procedure used to obtain and verify the evidence. | Checking a password, or checking a signature over a fresh challenge. |
| Factor | The kind of evidence involved. | Knowledge of a secret or possession of an authenticator. |
An authentication service, or verifier, checks the evidence. When that service signs people in for other applications, we commonly call it an identity provider. We will return to that arrangement in Authentication policy and SSO.
Three kinds of evidence
Something you know is a secret such as a password or an authenticator's activation PIN. Knowing a public email address, employee number, or birthday is not useful secret evidence.
Something you have is possession and control of an authenticator. A service does not simply accept the claim that Avery owns a phone. It checks evidence produced using an enrolled app, a cryptographic key, or another supported mechanism.
Something you are involves a biometric characteristic, such as a fingerprint. In a typical passkey sign-in, the device checks the fingerprint locally before permitting use of a key. The website verifies the resulting cryptographic response, not a fingerprint image.
Following the evidence
Avery signs in to Cedar Inc.'s staff portal with an email address and password. The address tells the service which account to check. When the password matches, the service has evidence that the person signing in knows a secret tied to that account. It then creates a session so Avery can move through the portal without entering the password on every page.
Now suppose someone enters Avery's email address but cannot provide the password. The identifier still matches an account, but the authentication attempt has not succeeded. The service should not disclose unnecessary account details while explaining that the sign-in could not be completed.
Successful authentication also has limits. It does not, by itself, establish a person's legal identity or grant every permission in the application. Identity proofing establishes a relationship to a real-world identity. Authorization determines which actions and resources the authenticated account may use.
The next lesson, Passwords and PINs, follows a password from the sign-in form to the verifier, then compares that journey with a PIN used only on a local device.