<a id="credential"></a>

# Credential

See also: [How to manage credentials](https://documentation.ubuntu.com/juju/4.0/howto/manage-credentials.md#manage-credentials)

In Juju, a **credential** represents a collection of authentication material (like username & password, or client id & secret key) that is specific to a Juju [user](https://documentation.ubuntu.com/juju/4.0/reference/user.md#user) and a [cloud](https://documentation.ubuntu.com/juju/4.0/reference/cloud.md#cloud) and allows that user to interact with that cloud.

#### IMPORTANT
In Juju a ‘credential’ always refers to authentication material used to access a *cloud*.

Clouds can have one or more sets of credentials associated with them.

When you create a  [model](https://documentation.ubuntu.com/juju/4.0/reference/model.md#model) in Juju it must always be associated with a cloud/credential pair – the model needs that to create resources on the underlying cloud.

## Credential definition

The structure of a credential and its supported authentication types depend on the cloud. See the relevant [cloud reference page](https://documentation.ubuntu.com/juju/4.0/reference/cloud/list-of-supported-clouds.md#list-of-supported-clouds) for details.

## Client vs. controller credential

Juju credentials can be created for either the Juju client or the Juju controller or both – where a **client credential** (previously known as a ‘local credential’) denotes a credential that the client is aware of and a **controller credential** (previously known as a ‘remote credential’) denotes a credential that a controller is aware of. When you bootstrap a controller and use a client credential, this credential gets automatically uploaded to the controller, so it becomes a controller credential also.

#### IMPORTANT
The set of client credentials and controller credentials can end up being the same. However, they don’t have to.
