Credential handling is a blast-radius problem, not a password form problem
Most credential systems do not fail because somebody picked the wrong cipher. They fail because the credential crosses too many boundaries: the API layer sees it, the queue stores it, the worker logs