Identity security glossary

SHORT ANSWER

Short definitions of the 49 terms used on this site, in alphabetical order. Where a term comes from a standard, the entry links to it.

Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29

A

Access token
A short-lived credential an authorization server issues so a client can call a specific API. The API checks the token rather than the user's password.
Agent identity
An account that belongs to an AI agent itself, separate from the person who started it and the platform it runs on, so it can have its own permissions, logs and off switch.
Agentic IAM
Identity and access management extended to AI agents: identities, credentials, policy and audit for agents alongside people.
AiTM phishing
Adversary-in-the-middle phishing. A fake sign-in page relays the victim's credentials and one-time code to the real site in real time and captures the resulting session.
Authenticator assurance level (AAL)
NIST's three levels of confidence in an authentication, defined in SP 800-63B-4. Higher levels require stronger authenticators and more protection against attacks such as phishing.

Source: NIST SP 800-63B-4

Authorization server
The OAuth component that authenticates the user or client and issues access tokens. An MCP server points clients to its authorization server through published metadata.

Source: MCP specification: Authorization (2025-06-18)

C

CIAM
Customer identity and access management. Sign-in and account management for a company's customers, as opposed to its employees.
Conditional Access
Microsoft Entra's policy engine, which Microsoft calls its Zero Trust policy engine. It evaluates signals such as user, device, location and risk before granting access.

Source: Microsoft Learn: Conditional Access

Confused deputy
An attack in which a trusted intermediary is tricked into using its own authority for someone else. The MCP specification describes it for proxies that use one static client ID with a third-party API.

Source: MCP specification: Security Best Practices

Continuous Access Evaluation Profile (CAEP)
An OpenID Foundation specification that lets access be re-evaluated continuously rather than only at sign-in.

Source: OpenID Foundation on NIST IR 8587

Credential stuffing
Trying username and password pairs leaked from one site against other sites, relying on people reusing passwords.

D

DCSync
An Active Directory attack in which an attacker with replication rights asks a domain controller for password data as if it were another domain controller.
Dynamic Client Registration
An OAuth mechanism, defined in RFC 7591, that lets a client register itself with an authorization server automatically. The MCP authorization specification builds on it.

Source: MCP specification: Authorization (2025-06-18)

F

FIDO2
A set of open standards, including WebAuthn, for signing in with a key pair held on a device or security key instead of a shared secret. Passkeys are built on it.

G

Golden SAML
An attack in which someone who holds a federation service's token-signing key forges SAML assertions that applications accept as genuine.
Guardian agent
Software that watches what other agents do and can stop an action before it completes.

I

Identity hygiene
The routine removal of identity risk that should not exist: unowned accounts, stale or excessive access, missing MFA and long-lived secrets.
Identity observability
Watching how identities are actually used, not only how they are configured.
Identity provider (IdP)
The system that authenticates users and issues the tokens or assertions applications trust.
ITDR
Identity threat detection and response. Tools that detect attacks on identity systems and respond by blocking, challenging or ending sessions.

J

Just-in-time access
Access granted for a specific task and time window, then removed automatically.

K

Kerberoasting
An Active Directory attack that requests service tickets for service accounts and cracks them offline to recover the account passwords.

L

Lateral movement
An attacker's progress from the first account or machine they control to others, usually by reusing credentials or tickets found along the way.
Least privilege
Giving an identity only the permissions its task needs, for only as long as it needs them.

M

Machine identity
An identity used by software, a workload or a device rather than a person; often used for certificates and keys, and overlapping with non-human identity.
MCP (Model Context Protocol)
A protocol that lets AI applications call external tools and data through MCP servers.

Source: MCP specification: Authorization (2025-06-18)

MCP gateway
A service between agents and MCP servers that authenticates callers, applies policy per call, supplies credentials and records each decision.

N

Non-human identity (NHI)
An identity used by software to reach other software: service accounts, API keys, OAuth tokens, certificates, secrets and AI agents.

Source: OWASP Non-Human Identities Top 10 (2025)

O

OAuth 2.1
A consolidation of the OAuth 2.0 framework and its security recommendations, published as an IETF draft. The MCP authorization specification is based on it.

Source: MCP specification: Authorization (2025-06-18)

OpenID Connect (OIDC)
An identity layer on top of OAuth 2.0 that tells an application who signed in, through a signed ID token.

P

Pass-the-Hash
An attack that uses a stolen password hash to authenticate as a user in a Windows domain, without cracking the password.
Passkey
A FIDO credential that replaces a password with a key pair held on a device or synced between devices; resistant to phishing because it only works with the site it was created for.
Password spraying
Trying a few common passwords against many accounts, slowly, to avoid account lockouts.
Per-call authorization
Checking each tool call or operation against policy when it happens, rather than only when a session starts.
PKCE
Proof Key for Code Exchange. An OAuth extension that stops an intercepted authorization code from being redeemed by someone else; required for MCP clients.

Source: MCP specification: Authorization (2025-06-18)

Protected Resource Metadata
A document, defined in RFC 9728, that a resource server publishes to tell clients which authorization server to use. MCP servers must publish it.

Source: MCP specification: Authorization (2025-06-18)

R

Resource indicator
An OAuth parameter, defined in RFC 8707, that names the resource a token is for. MCP clients must send it, so a token only works at one MCP server.

Source: MCP specification: Authorization (2025-06-18)

S

SAML
Security Assertion Markup Language, an XML-based standard for single sign-on in which the identity provider sends the application a signed assertion.
SCIM
System for Cross-domain Identity Management, an HTTP-based protocol for creating, updating and removing user accounts across systems, defined in RFC 7644.

Source: RFC 7644 (SCIM protocol)

Secret sprawl
Credentials copied into code, configuration files, chat messages and pipelines where they are hard to find, rotate or remove.
Service account
An account used by an application or script rather than a person, often with broad permissions and no expiry.
Session hijacking
Taking over an authenticated session, usually by stealing a session cookie or token, so the attacker is treated as already signed in. The MCP specification forbids using sessions as authentication.

Source: MCP specification: Security Best Practices

Shadow agent
An AI agent running in the organization that was never registered with IT or security. Okta and Silverfort both describe discovering such agents.

Source: Okta: Secure AI

Shared Signals Framework (SSF)
An OpenID Foundation specification that defines how identity providers and relying parties exchange security event signals in a standard way.

Source: OpenID Foundation on NIST IR 8587

Single sign-on (SSO)
Signing in once with the identity provider and then reaching many applications without signing in to each.

T

Token passthrough
An MCP server forwarding a token it received to another API. The MCP specification forbids it.

Source: MCP specification: Security Best Practices

Token replay
Reusing a stolen token or assertion to gain access without the password or MFA that produced it. NIST IR 8587 covers protecting tokens from forgery, theft and misuse.

Source: NIST IR 8587

W

Workload identity
An identity for a piece of software, such as a service, container or pipeline job, used when it calls other systems.

Z

Zero trust
An approach that moves defenses from network perimeters to users, assets and resources, deciding access per request.

Source: NIST SP 800-207