Glossary · Non-human identity (NHI)

What is a non-human identity (NHI)?

A non-human identity is a digital identity assigned to software or services rather than a person, such as a service account, API key, OAuth app, certificate or AI agent.

Book a demoAll terms
Non-human identities
Service accountsCloud and directory accounts for softwareNHI
API keys and tokensStatic secrets in code, CI and vaultsNHI
OAuth appsGrants to third-party applicationsNHI
CertificatesMachine-to-machine authenticationNHI
AI agentsIdentities that choose their next actionNew
NON-HUMAN IDENTITY (NHI)

In practice

Non-human identities authenticate machines to other machines. They often have no MFA, no owner and no expiry, and they outnumber human accounts in most environments. AI agents add a new kind: identities that decide their next action on their own.

Our non-human identity security guide covers the risks and controls in detail.

DEFINITION

A non-human identity is a digital identity assigned to software or services rather than a person, such as a service account, API key, OAuth app, certificate or AI agent.

HOW IT WORKS

How it works. Step by step.

The parts that make it up, in an environment with AI agents.

01Service accounts

Accounts that let software act in cloud platforms and directories.

02Keys and tokens

Static secrets that authenticate scripts, CI jobs and integrations.

03OAuth apps

Third-party applications acting on a user’s behalf within scopes.

04AI agents

A new kind of NHI that decides its own next action.

EXAMPLE

What it looks like in Elmoz

A real path shape, drawn the way the Elmoz security graph shows it.

Security GraphFocus: cron agentAll assetsIdentitiesData stores
ATTACK PATH3 agents on one identity · 2 access steps
cron agentAI agent · nightlyreport agentSame usersync agentSame user3!backup-writerService accountawsprod-accountAWS account!OwnerLeft the companyaws!prod-backup roleWrite and delete3Findings3 issuesProd backupsS3 bucketDatabase dumpsCustomer dataConfig exportsSecrets inside
FAQ

Questions, answered.

Short answers about Non-human identity (NHI).

What are examples of non-human identities?

Service accounts, API keys, access tokens, OAuth apps, certificates, workload identities and AI agents.

Why are non-human identities risky?

They often have no MFA, no clear owner and no expiry, and their credentials end up in code, CI and config files. Many of them hold broad access that nobody reviews.

Are AI agents non-human identities?

Yes. An AI agent authenticates with credentials like any other NHI, but it also decides which actions to take, which makes its reach more important than its permission list.

See what your agents can reach. Before someone else does.

Book a demo and we walk through the access paths in an environment like yours.