Select the credentials to use to verify the signature of incoming hooks. Both GLOBAL and SYSTEM scoped credentials are eligible as the management of hooks is run in the context of Jenkins itself and not in the context of the individual items.

If the automatic management of web hooks is disabled than you have to setup manually in each repository selected credentials or any untrusted hook will be discarded.