Methods, credentials, and factors
The sign-in experience
When you sign in, one website asks for a password. Another sends you a code. Your work account might ask you to approve a notification, while your phone lets you use a fingerprint. These experiences look different because they collect different kinds of evidence that you control the account.
Imagine Alex starting a new job at Cedar Inc., a fictional company. Alex has an employee account and needs to open the staff portal. Typing an email address tells the service which account Alex wants to use. It does not show whether the person at the keyboard controls that account.
Authentication is the process of checking the evidence supporting that claim. Throughout this series, ask: what evidence did the service actually verify? That question is the question we're looking to answer.
Naming the pieces
A few related terms help us describe the journey. Products sometimes use them differently, so pay attention to the role each piece plays.
| Term | Meaning in this series | Example |
|---|---|---|
| Identifier | A value used to locate or distinguish an account. | Alex's account ID or sign-in email address. |
| Credential | Authentication material associated with an account. Formal standards may use the term more specifically for the binding between an identity and an authenticator. | A password, or a registered public-key credential. |
| Authenticator | Something the person controls and uses to produce authentication evidence. | A memorized password, an authenticator app, or a security key. |
| Method | The procedure used to obtain and verify the evidence. | Password verification or a WebAuthn challenge and response. |
| Factor | The kind of evidence involved. | Knowledge of a secret or possession of an authenticator. |
An authentication service, or verifier, checks the evidence. When that service signs people in for other applications, we commonly call it an identity provider. We will return to that arrangement in Authentication policy and SSO.
Three kinds of evidence
Something you know is a secret such as a password or an authenticator's activation PIN. Knowing a public email address, employee number, or birthday is not useful secret evidence.
Something you have is possession and control of an authenticator. A service does not simply accept the claim that Alex owns a phone. It checks evidence produced using an enrolled app, a cryptographic key, or another supported mechanism.
Something you are involves a biometric characteristic, such as a fingerprint. In a typical passkey sign-in, the device checks the fingerprint locally before permitting use of a key. The website verifies the resulting cryptographic response, not a fingerprint image.
The same device can participate in more than one factor. Conversely, using two devices does not guarantee that two different factors were verified. Other signals can affect what evidence a service asks for. A familiar location or an unusual browser may influence that decision, but neither proves something you know, have, or are. This real-time decision making about your authentication signals is known as conditional access.
Following the evidence
Alex signs in to Cedar Inc.'s staff portal with an email address and password. The address tells the service which account to check. When the password matches, the service has evidence that the person signing in knows a secret tied to that account. It then creates a session so Alex can move through the portal without entering the password on every page.
Now suppose someone enters Alex's email address but cannot provide the password. The identifier still matches an account, but the authentication attempt has not succeeded. The service should not disclose unnecessary account details while explaining that the sign-in could not be completed.
Successful authentication also has limits. It does not, by itself, establish a person's legal identity or grant every permission in the application. Identity proofing establishes a relationship to a real-world identity. Authorization determines which actions and resources the authenticated account may use.
In the next lesson, we will follow a password from the sign-in form to the verifier, then compare that journey with a PIN used only on a local device.