Existing credential to validate. When set and no client_secret is
provided, the stored secret is validated server-side, so clients can test
a saved credential without sending (or knowing) the secret. When a
client_secret is provided, that secret is validated instead.