Machine Identity
Machine Identity is the digital identity of servers, devices, applications, containers or other workloads with which they identify themselves to other systems. It is usually proven cryptographically, for example via X.509 certificates, SSH keys or signed tokens.
Machine identities secure a large part of automated communication – from TLS-encrypted connections and mutually authenticated microservices to code signatures. Machine identity management comprises inventorying, issuing, rotating and revoking these proofs in good time. Expired or unknown certificates lead to outages, compromised keys to unnoticed access. Additional automation requirements are created by the gradual shortening of the validity of public TLS certificates to 47 days by 2029, decided by the CA/Browser Forum in 2025. For workloads in cloud environments, the open SPIFFE standard has also become established.
The terms machine identity and Non-Human Identity (NHI) are often used synonymously. Strictly speaking, machine identity emphasizes the cryptographic proof of identity of systems, whereas NHI as an umbrella term also covers accounts, API keys and AI agents. The management of machine identities is part of Identity Security and closely linked to Cloud Security.