Non-Human Identity (NHI)
Also known as: Non-Human Identity · NHI · Machine Identity
Definition
A non-human identity (NHI) is any identity that authenticates without a human present — service accounts, API keys, OAuth client credentials, certificates, workload identities, and AI agents. NHIs typically outnumber human identities 10-to-1 in modern estates.
NHIs are the fastest-growing identity population and the least-governed. The lifecycle controls routine for human identities — provisioning, least privilege, rotation, deprovisioning — are rarely applied to NHIs, making them a leading breach vector.
The OWASP Non-Human Identity Top 10 (2025-2026) codifies the risk classes: improper offboarding, secret leakage, over-privileged NHIs, vulnerable third-party NHIs, and insecure authentication.