A non-human identity (NHI) is any digital identity that authenticates software rather than a person. Service accounts, API keys, OAuth tokens issued to applications, certificates on workloads, and the identities assigned to AI agents are all NHIs. They let systems connect to each other without a human logging in, which is why they now sit at the center of enterprise access risk.
Human identity management assumes a person who logs in, passes multi-factor authentication, works a session and logs out. NHIs break most of those assumptions. They are created by code, often in large numbers. They authenticate machine to machine with no prompt to approve. Many run continuously with no natural session end, and nobody notices odd behavior in real time.
That makes ownership the hardest part. A human account belongs to an employee with a manager and an offboarding date. An API key created for a project two years ago may have no clear owner at all.
AI agents add a new class of NHI that behaves differently from a fixed integration. An agent chooses which tools to call based on the task, may hand work to another agent, and can act across many systems in one run. A shared or over-broad credential in that setting is both a security risk and an attribution problem, because nobody can tell which agent took which action.
The OWASP Non-Human Identities Top 10 lists the most common failure points, including improper offboarding, secret leakage and over-privileged identities.
Good NHI management follows a lifecycle:
Zamp gives each AI employee its own identity with scoped access, so every action is attributable and one agent can be revoked without touching others. For the full access model, see why AI agents need their own access model. For step-by-step implementation, see our guide to AI agent identity management, and for the broader context, the complete guide to AI employees.
A non-human identity is a credential that authenticates software instead of a person. Examples include service accounts, API keys, OAuth tokens issued to applications, workload certificates, and the identities assigned to AI agents.
Yes. An AI agent that logs into systems, calls APIs or writes data needs credentials, and those credentials make it a non-human identity. Because agents decide which tools to use at run time, they need tighter scoping and monitoring than a fixed integration.
The OWASP Non-Human Identities Top 10 lists risks such as improper offboarding, secret leakage, insecure authentication and over-privileged identities. In practice, most incidents trace back to a long-lived key with broad access that nobody owns or rotates.
Keep an inventory of every NHI and its owner, give each one only the access it needs, prefer short-lived tokens over static keys, log every action against the specific identity, and retire credentials when the workload or agent is decommissioned.