CredentialsFor

This secret/credential authenticates as the target. Zero-cost link completing credential chains.

credential CREDENTIAL nature: explicit walkable weight 0 high value
Secret, Credential, AccessKey, Token, Certificate  ── CredentialsFor ──▸  Identity, Data, ServiceIdentity

Target types

IdentityDataServiceIdentity

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

natureexplicit

Rules that emit CredentialsFor 16

An exported ACM private key authenticates as the certificate's DNS/TLS server identity.
awsderived
A CA-issued certificate authenticates as the downstream identity a trust consumer maps it to.
awsderived
An AppFlow connector profile's stored credential (OAuth token / API key) authenticates to the external SaaS system - reading the Secrets Manager secret yields a usable credential for that SaaS identity.
awsderived
A Lightsail bucket access key authenticates to the bucket's data plane.
awsderived
A SecureString parameter's value authenticates as the target identity/service.
awsderived
An IMDS bearer token minted from a host+MI pair is valid authentication as that MI.
azurederived
A cert signed by the CA authenticates as the subject/SAN it names to a consuming trust.
gcpderived
A CMEK-encrypted Secret Manager payload authenticates as another identity, completing CanExecuteAs -> CanReadSecret -> CredentialsFor.
gcpderived
The secret's payload authenticates as another identity / service account / data store.
gcpderived
move · open · esc close