Identity security university
SHORT ANSWER
Looking for a quick answer? See the FAQ.
Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29
Glossary: 49 terms
Short definitions of the terms used on this site, in alphabetical order.
Basics
What an identity provider does, what an agent identity is, and the common risk list for non-human identities.
What an identity provider does, and what it signs
An identity provider checks who someone is and then vouches for them to every application with a signed token or assertion. Everything downstream trusts that signature, which is why the signing key is one of the most valuable secrets in the stack.
3 min read
Agent identities explained
An agent identity is an account for the agent itself, linked to the person or team who answers for it. It lets an agent have narrow permissions, its own log entries and an off switch that does not disable anyone else.
3 min read
The OWASP Non-Human Identities Top 10, in plain terms
OWASP's 2025 list names ten ways service accounts, keys, tokens and similar identities go wrong. Most come down to three problems: nobody owns them, they last too long, and they can do too much.
2 min read
Threats and detection
How identity attacks work, and what detection and stronger sign-in each cover.
What ITDR covers, and what it does not
ITDR watches identity systems for attacks and responds to them. It covers directory attacks well, sessions and tokens less evenly, and it does not replace good sign-in or good hygiene.
2 min read
Phishing-resistant sign-in: passkeys, FIDO2 and assurance levels
A sign-in method resists phishing when it only works with the real site. Passkeys and FIDO2 security keys do that by design; passwords and one-time codes do not, because a fake page can relay them in real time.
3 min read
Token theft, replay and forgery
Once someone signs in, their access travels as a token. An attacker who steals, replays or forges that token skips the password and the MFA entirely. NIST IR 8587, final since 15 September 2026, is the reference on protecting tokens.
3 min read
AI agents and MCP
How agents authenticate, how MCP authorization works, and why each call gets checked.
How MCP authorization works
MCP uses OAuth 2.1. The MCP server is a resource server, the client finds the authorization server through published metadata, and every token is bound to one specific MCP server.
2 min read
Per-call authorization and human approval for AI agents
Per-call authorization checks every tool call or operation against policy at the moment it runs. For AI agents it matters more than for ordinary software, because the agent decides its own next step. Risky calls can wait for a person to approve them.
3 min read
AI agent authentication, step by step
An AI agent should authenticate as itself, on behalf of a named person, with a short-lived token that is valid for one resource. The MCP specification sets the rules for tool calls; vendors add agent identities, per-call checks and credential brokering on top.
3 min read · GUIDE
Buying
How to read vendor material and apply zero trust and hygiene work in order.
How to read a vendor's security page
Sort every claim into three piles: stated plainly, implied, and missing. Compare vendors on the first pile, and turn the other two into questions. That is how every score on this site is built.
3 min read
Zero trust identity: what NIST SP 800-207 asks of the identity layer
Zero trust makes identity the checkpoint for every request. In practice that means three things: decide access per request rather than per network, authenticate with methods that resist phishing, and protect the tokens that carry the decision once it is made.
4 min read · GUIDE
An identity hygiene checklist for people, machines and agents
Identity hygiene is removing access that should not exist. Work in this order: inventory everything, give each identity an owner, remove what is stale, close MFA and SSO gaps, replace long-lived secrets, then put AI agents under the same rules from day one.
3 min read · GUIDE