Non-Human Identity (NHI)

Non-Human Identity (NHI) is a collective term for digital identities that are not assigned to a natural person but are used by software, services or devices. These include service accounts, API keys, OAuth tokens, certificates, workload identities in cloud platforms, bots and, increasingly, AI agents.

In many organizations, there are significantly more non-human than human identities. They usually authenticate with static secrets, work without interactive login and thus without multi-factor authentication, often possess far-reaching rights and rarely have a clearly named owner. Typical risks – such as missing offboarding, exposed secrets, over-privileged accounts or long-lived credentials – are described by the OWASP project Non-Human Identities Top 10.

Protection includes inventorying, clear responsibilities, minimal rights, short lifetimes and automatic rotation of credentials, as well as monitoring of usage behavior. Sub-forms with their own focus are Machine Identity with cryptographic proofs and AI Agent Identity for autonomously acting AI systems. The management of non-human identities extends Identity Security beyond classic user accounts.