Non-Human Identity (NHI)

Digital identities assigned to machines, services, applications, bots, and automated workloads rather than to human users. NHIs include service accounts, API keys, OAuth tokens, certificates, and secrets used by software to authenticate and authorise actions. As identity attack surfaces expand, managing and securing NHIs has become a critical discipline alongside traditional human IAM.

Why It Matters

The majority of credentials in enterprise environments now belong to non-human entities. Compromised NHIs — such as leaked API keys or service account tokens — are a primary attack vector, making NHI governance essential for fraud and security teams.

Category: cybersecurity. Part of the Identity Technologist Glossary — more than 200 practitioner-grade definitions covering identity verification, KYC/AML, biometrics, fraud prevention, and compliance. See all terms at https://identitytechnologist.com/glossary.