"The Windows Credential Manager is anything but secure. It's "secure" at the user account level, which means that any process that the user ever runs and the user themselves must necessarily be trusted in order to call this system "secure" with a straight face.
The only semi secure way of using the Windows Credential Manager is to store values pre-hashed, then verify those hashes. "
с этим не разбирался, но звучит логично, иначе это была бы магия.