# Principals, Credentials and Factors — Authentication & Authorization

Source: https://www.skillbyai.com/en/authentication/f-identity

> The vocabulary of identity.

## The core terms

A **principal** is any entity that can be authenticated: a person, a service, a device. An **identifier** names it (email, username, client ID); a **credential** is the evidence it presents (password, private key, token). Authentication **factors** fall into three categories: something you **know** (password, PIN), something you **have** (phone, security key, passkey on a device) and something you **are** (biometrics, usually unlocking a local key rather than being sent to the server). **Multi-factor authentication** combines different categories; two passwords are still one factor. After authentication, systems usually issue a **session** or **token** so the principal does not re-present credentials on every request.

## Mapping the terms

Examples of principals, identifiers and credentials.

```text
principal          identifier              credential / factor
---------          ----------              -------------------
human user         alice@example.com       password (know) + passkey (have)
mobile app user    user id from IdP        session cookie or access token
backend service    OAuth client_id         client secret or private-key JWT
CI pipeline        workload identity       short-lived OIDC token from CI provider
IoT device         device serial           X.509 client certificate
```

## Separate identifiers from credentials

Treat email addresses and usernames as public. Security must never depend on an identifier being secret; it depends on the credential.

**Quiz:** Which combination is genuine multi-factor authentication?

- [x] A password plus a code from an authenticator app
- [ ] A password plus a security question
- [ ] Two different passwords
- [ ] A username plus a password

*Answer:* A password plus a code from an authenticator app. MFA needs factors from different categories: know plus have.
