close
breadcrumb right arrowGlossary
breadcrumb right arrowNon-Human Identity (NHI)
Non-Human Identity (NHI)

A non-human identity (NHI) is any digital identity that authenticates software rather than a person. Service accounts, API keys, OAuth tokens issued to applications, certificates on workloads, and the identities assigned to AI agents are all NHIs. They let systems connect to each other without a human logging in, which is why they now sit at the center of enterprise access risk.

Common types of non-human identities

  • Service accounts that let one application read or write data in another, such as an integration between an ERP and a payments platform.
  • API keys and tokens that grant programmatic access to a SaaS tool or internal service.
  • Certificates and workload identities that prove a server, container or cloud function is who it claims to be.
  • AI agent identities that let an autonomous agent log into systems, call tools and take actions on a company's behalf.

How NHIs differ from human identities

Human identity management assumes a person who logs in, passes multi-factor authentication, works a session and logs out. NHIs break most of those assumptions. They are created by code, often in large numbers. They authenticate machine to machine with no prompt to approve. Many run continuously with no natural session end, and nobody notices odd behavior in real time.

That makes ownership the hardest part. A human account belongs to an employee with a manager and an offboarding date. An API key created for a project two years ago may have no clear owner at all.

Why NHIs matter more with AI agents

AI agents add a new class of NHI that behaves differently from a fixed integration. An agent chooses which tools to call based on the task, may hand work to another agent, and can act across many systems in one run. A shared or over-broad credential in that setting is both a security risk and an attribution problem, because nobody can tell which agent took which action.

The OWASP Non-Human Identities Top 10 lists the most common failure points, including improper offboarding, secret leakage and over-privileged identities.

Managing non-human identities

Good NHI management follows a lifecycle:

  • Inventory every NHI and assign it an accountable owner.
  • Scope each identity to least privilege, giving one agent or integration only the access its job needs.
  • Prefer short-lived, rotating tokens over static keys.
  • Log every action against the specific identity in an audit trail.
  • Retire credentials as soon as the workload or agent is decommissioned.

Zamp gives each AI employee its own identity with scoped access, so every action is attributable and one agent can be revoked without touching others. For the full access model, see why AI agents need their own access model. For step-by-step implementation, see our guide to AI agent identity management, and for the broader context, the complete guide to AI employees.

Frequently asked questions

What is a non-human identity?

A non-human identity is a credential that authenticates software instead of a person. Examples include service accounts, API keys, OAuth tokens issued to applications, workload certificates, and the identities assigned to AI agents.

Is an AI agent a non-human identity?

Yes. An AI agent that logs into systems, calls APIs or writes data needs credentials, and those credentials make it a non-human identity. Because agents decide which tools to use at run time, they need tighter scoping and monitoring than a fixed integration.

What are the biggest risks with non-human identities?

The OWASP Non-Human Identities Top 10 lists risks such as improper offboarding, secret leakage, insecure authentication and over-privileged identities. In practice, most incidents trace back to a long-lived key with broad access that nobody owns or rotates.

How do you manage non-human identities?

Keep an inventory of every NHI and its owner, give each one only the access it needs, prefer short-lived tokens over static keys, log every action against the specific identity, and retire credentials when the workload or agent is decommissioned.