I dont see a place where a reference to WHAT credential is being used is stored, unless it's just compared to the list of authorized credentials' fields to look for a match when you go to edit that node, I dont know how they know. but,
The credentials themselves are stored in plaintext and everything (I was worried to it would be hashed with the type you put in)