FormsAuthenticationCredentials Class

Configures user credentials for ASP.NET applications that use form-based authentication.

Namespace: System.Web.Configuration
Assembly: System.Web (in system.web.dll)

public sealed class FormsAuthenticationCredentials : ConfigurationElement
public final class FormsAuthenticationCredentials extends ConfigurationElement
public final class FormsAuthenticationCredentials extends ConfigurationElement
Not applicable.

The FormsAuthenticationCredentials class provides a way to programmatically access and modify the credentials element of a forms section in the authentication section of the configuration file. This type is part of a group that includes the FormsAuthenticationConfiguration, the FormsAuthenticationUserCollection, and the FormsAuthenticationUser types. With the exception of the collection type, all the others directly affect the underlying configuration tags.


The FormsAuthenticationCredentials can write information into the related section of the configuration file according to the restrictions defined by MachineToApplication. Any attempt to write in a configuration file at a level not allowed in the hierarchy will result in an error message generated by the parser. However, you can use this class to read configuration information at any level in the hierarchy. For safety and scalability, it is recommended that you use an external repository, such as a database, to keep the users' credentials.

This example demonstrates how to specify values declaratively for several attributes of the credentials section, which can also be accessed as members of the FormsAuthenticationCredentials class.

The following configuration file example shows how to specify values declaratively for the credentials section.

<credentials passwordFormat="SHA1">
  <user name="aspnetuser1"
  <user name="aspnetuser2"

If you use the credentials section, be sure to follow the guidelines explained at ASP.NET Authentication. For scalability and better security, it is recommended that you use an external database to store the users' credentials. For more information about building secure ASP.NET applications, search the Microsoft MSDN Web site ( for "Securing Your ASP.NET Application" and "Building Secure ASP.NET Applications: Authentication, Authorization, and Secure Communication."

The following code example demonstrates how to use the FormsAuthenticationCredentials class.

// Get the Web application configuration.
System.Configuration.Configuration configuration = 

// Get the authentication section.
AuthenticationSection authenticationSection = 

// Get the forms credentials collection .
FormsAuthenticationCredentials formsAuthenticationCredentials =


Any public static (Shared in Visual Basic) members of this type are thread safe. Any instance members are not guaranteed to be thread safe.

Windows 98, Windows Server 2000 SP4, Windows Server 2003, Windows XP Media Center Edition, Windows XP Professional x64 Edition, Windows XP SP2, Windows XP Starter Edition

The Microsoft .NET Framework 3.0 is supported on Windows Vista, Microsoft Windows XP SP2, and Windows Server 2003 SP1.

.NET Framework

Supported in: 3.0, 2.0