Identity security university

SHORT ANSWER

Definitions and short lessons for the terms used across this site, arranged in four tracks. Start with Basics if identity is new to you, or jump to the track for the problem you are working on.

Looking for a quick answer? See the FAQ.

Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29

Glossary: 49 terms

Short definitions of the terms used on this site, in alphabetical order.

Basics

What an identity provider does, what an agent identity is, and the common risk list for non-human identities.

What an identity provider does, and what it signs

An identity provider checks who someone is and then vouches for them to every application with a signed token or assertion. Everything downstream trusts that signature, which is why the signing key is one of the most valuable secrets in the stack.

3 min read

Agent identities explained

An agent identity is an account for the agent itself, linked to the person or team who answers for it. It lets an agent have narrow permissions, its own log entries and an off switch that does not disable anyone else.

3 min read

The OWASP Non-Human Identities Top 10, in plain terms

OWASP's 2025 list names ten ways service accounts, keys, tokens and similar identities go wrong. Most come down to three problems: nobody owns them, they last too long, and they can do too much.

2 min read

Threats and detection

How identity attacks work, and what detection and stronger sign-in each cover.

What ITDR covers, and what it does not

ITDR watches identity systems for attacks and responds to them. It covers directory attacks well, sessions and tokens less evenly, and it does not replace good sign-in or good hygiene.

2 min read

Phishing-resistant sign-in: passkeys, FIDO2 and assurance levels

A sign-in method resists phishing when it only works with the real site. Passkeys and FIDO2 security keys do that by design; passwords and one-time codes do not, because a fake page can relay them in real time.

3 min read

Token theft, replay and forgery

Once someone signs in, their access travels as a token. An attacker who steals, replays or forges that token skips the password and the MFA entirely. NIST IR 8587, final since 15 September 2026, is the reference on protecting tokens.

3 min read

AI agents and MCP

How agents authenticate, how MCP authorization works, and why each call gets checked.

How MCP authorization works

MCP uses OAuth 2.1. The MCP server is a resource server, the client finds the authorization server through published metadata, and every token is bound to one specific MCP server.

2 min read

Per-call authorization and human approval for AI agents

Per-call authorization checks every tool call or operation against policy at the moment it runs. For AI agents it matters more than for ordinary software, because the agent decides its own next step. Risky calls can wait for a person to approve them.

3 min read

AI agent authentication, step by step

An AI agent should authenticate as itself, on behalf of a named person, with a short-lived token that is valid for one resource. The MCP specification sets the rules for tool calls; vendors add agent identities, per-call checks and credential brokering on top.

3 min read · GUIDE

Buying

How to read vendor material and apply zero trust and hygiene work in order.

How to read a vendor's security page

Sort every claim into three piles: stated plainly, implied, and missing. Compare vendors on the first pile, and turn the other two into questions. That is how every score on this site is built.

3 min read

Zero trust identity: what NIST SP 800-207 asks of the identity layer

Zero trust makes identity the checkpoint for every request. In practice that means three things: decide access per request rather than per network, authenticate with methods that resist phishing, and protect the tokens that carry the decision once it is made.

4 min read · GUIDE

An identity hygiene checklist for people, machines and agents

Identity hygiene is removing access that should not exist. Work in this order: inventory everything, give each identity an owner, remove what is stale, close MFA and SSO gaps, replace long-lived secrets, then put AI agents under the same rules from day one.

3 min read · GUIDE