Skip to main content

Credential and Authenticator

Distinguish a bound credential, an authenticator, its secret or key, a factor type, and protocol output.

Separate the objects

An authenticator is something the claimant possesses and controls that can produce authentication output. Its secret can be memorized, stored as a key, or derived from a biometric characteristic through an activation process. A credential is the data object that binds an identity or account to one or more authenticators. A factor type describes the evidence: something known, possessed, or inherent.

Binding and use

Enrollment binds the authenticator to the subscriber account. During authentication, the claimant proves control through a protocol. The verifier validates the output and its context. A public-key authenticator can keep the private key on the device and send a signature instead of a reusable shared secret.

Lifecycle controls

Protect issuance, binding, activation, storage, replacement, duplication, suspension, revocation, and recovery. Record which authenticators are active. Notify the subscriber of changes. Require suitable authentication before adding or replacing an authenticator.

Failure and residual risk

A possession factor can be copied when its secret is exportable. A biometric is not a secret and can be difficult to replace. A one-time code can still be phished in real time. Recovery or authenticator replacement can provide an easier takeover path than normal authentication.

Pomerium boundary

The identity provider verifies the user's authenticators. Pomerium receives the resulting federated authentication and creates a Pomerium session. Pomerium does not make a weak provider enrollment or recovery process stronger.

Evaluation checklist

  • Is each authenticator bound to the intended subscriber account?
  • Can its secret be copied, exported, replayed, or phished?
  • Which independent factor types does the ceremony use?
  • How are authenticators added, replaced, suspended, and revoked?
  • Is recovery at least as well controlled as ordinary authentication?

Sources and further reading

Keep learning

Identity and Authentication

Authentication

Verify that a claimant controls one or more authenticators bound to an account without confusing that result with authorization.

Learn this term
Identity and Authentication

Security Keys

A security key is a roaming or dedicated hardware cryptographic authenticator, such as a USB, NFC, or Bluetooth key.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo