A non-human identity is a digital identity assigned to software or services rather than a person, such as a service account, API key, OAuth app, certificate or AI agent.
Non-human identities authenticate machines to other machines. They often have no MFA, no owner and no expiry, and they outnumber human accounts in most environments. AI agents add a new kind: identities that decide their next action on their own.
Our non-human identity security guide covers the risks and controls in detail.
A non-human identity is a digital identity assigned to software or services rather than a person, such as a service account, API key, OAuth app, certificate or AI agent.
The parts that make it up, in an environment with AI agents.
Accounts that let software act in cloud platforms and directories.
Static secrets that authenticate scripts, CI jobs and integrations.
Third-party applications acting on a user’s behalf within scopes.
A new kind of NHI that decides its own next action.
A real path shape, drawn the way the Elmoz security graph shows it.
Short answers about Non-human identity (NHI).
Service accounts, API keys, access tokens, OAuth apps, certificates, workload identities and AI agents.
They often have no MFA, no clear owner and no expiry, and their credentials end up in code, CI and config files. Many of them hold broad access that nobody reviews.
Yes. An AI agent authenticates with credentials like any other NHI, but it also decides which actions to take, which makes its reach more important than its permission list.
Terms that belong to the same picture.
Book a demo and we walk through the access paths in an environment like yours.