Identity security glossary
SHORT ANSWER
Short definitions of the 49 terms used on this site, in alphabetical order. Where a term comes from a standard, the entry links to it.
Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29
A
- Access token
- A short-lived credential an authorization server issues so a client can call a specific API. The API checks the token rather than the user's password.
- Agent identity
- An account that belongs to an AI agent itself, separate from the person who started it and the platform it runs on, so it can have its own permissions, logs and off switch.
- Agentic IAM
- Identity and access management extended to AI agents: identities, credentials, policy and audit for agents alongside people.
- AiTM phishing
- Adversary-in-the-middle phishing. A fake sign-in page relays the victim's credentials and one-time code to the real site in real time and captures the resulting session.
- Authenticator assurance level (AAL)
- NIST's three levels of confidence in an authentication, defined in SP 800-63B-4. Higher levels require stronger authenticators and more protection against attacks such as phishing.
Source: NIST SP 800-63B-4
C
- CIAM
- Customer identity and access management. Sign-in and account management for a company's customers, as opposed to its employees.
- Conditional Access
- Microsoft Entra's policy engine, which Microsoft calls its Zero Trust policy engine. It evaluates signals such as user, device, location and risk before granting access.
- Confused deputy
- An attack in which a trusted intermediary is tricked into using its own authority for someone else. The MCP specification describes it for proxies that use one static client ID with a third-party API.
- Continuous Access Evaluation Profile (CAEP)
- An OpenID Foundation specification that lets access be re-evaluated continuously rather than only at sign-in.
- Credential stuffing
- Trying username and password pairs leaked from one site against other sites, relying on people reusing passwords.
D
- DCSync
- An Active Directory attack in which an attacker with replication rights asks a domain controller for password data as if it were another domain controller.
- Dynamic Client Registration
- An OAuth mechanism, defined in RFC 7591, that lets a client register itself with an authorization server automatically. The MCP authorization specification builds on it.
F
- FIDO2
- A set of open standards, including WebAuthn, for signing in with a key pair held on a device or security key instead of a shared secret. Passkeys are built on it.
G
- Golden SAML
- An attack in which someone who holds a federation service's token-signing key forges SAML assertions that applications accept as genuine.
- Guardian agent
- Software that watches what other agents do and can stop an action before it completes.
I
- Identity hygiene
- The routine removal of identity risk that should not exist: unowned accounts, stale or excessive access, missing MFA and long-lived secrets.
- Identity observability
- Watching how identities are actually used, not only how they are configured.
- Identity provider (IdP)
- The system that authenticates users and issues the tokens or assertions applications trust.
- ITDR
- Identity threat detection and response. Tools that detect attacks on identity systems and respond by blocking, challenging or ending sessions.
J
- Just-in-time access
- Access granted for a specific task and time window, then removed automatically.
K
- Kerberoasting
- An Active Directory attack that requests service tickets for service accounts and cracks them offline to recover the account passwords.
L
- Lateral movement
- An attacker's progress from the first account or machine they control to others, usually by reusing credentials or tickets found along the way.
- Least privilege
- Giving an identity only the permissions its task needs, for only as long as it needs them.
M
- Machine identity
- An identity used by software, a workload or a device rather than a person; often used for certificates and keys, and overlapping with non-human identity.
- MCP (Model Context Protocol)
- A protocol that lets AI applications call external tools and data through MCP servers.
- MCP gateway
- A service between agents and MCP servers that authenticates callers, applies policy per call, supplies credentials and records each decision.
N
- Non-human identity (NHI)
- An identity used by software to reach other software: service accounts, API keys, OAuth tokens, certificates, secrets and AI agents.
O
- OAuth 2.1
- A consolidation of the OAuth 2.0 framework and its security recommendations, published as an IETF draft. The MCP authorization specification is based on it.
- OpenID Connect (OIDC)
- An identity layer on top of OAuth 2.0 that tells an application who signed in, through a signed ID token.
P
- Pass-the-Hash
- An attack that uses a stolen password hash to authenticate as a user in a Windows domain, without cracking the password.
- Passkey
- A FIDO credential that replaces a password with a key pair held on a device or synced between devices; resistant to phishing because it only works with the site it was created for.
- Password spraying
- Trying a few common passwords against many accounts, slowly, to avoid account lockouts.
- PKCE
- Proof Key for Code Exchange. An OAuth extension that stops an intercepted authorization code from being redeemed by someone else; required for MCP clients.
- Protected Resource Metadata
- A document, defined in RFC 9728, that a resource server publishes to tell clients which authorization server to use. MCP servers must publish it.
R
- Resource indicator
- An OAuth parameter, defined in RFC 8707, that names the resource a token is for. MCP clients must send it, so a token only works at one MCP server.
S
- SAML
- Security Assertion Markup Language, an XML-based standard for single sign-on in which the identity provider sends the application a signed assertion.
- SCIM
- System for Cross-domain Identity Management, an HTTP-based protocol for creating, updating and removing user accounts across systems, defined in RFC 7644.
Source: RFC 7644 (SCIM protocol)
- Secret sprawl
- Credentials copied into code, configuration files, chat messages and pipelines where they are hard to find, rotate or remove.
- Service account
- An account used by an application or script rather than a person, often with broad permissions and no expiry.
- Session hijacking
- Taking over an authenticated session, usually by stealing a session cookie or token, so the attacker is treated as already signed in. The MCP specification forbids using sessions as authentication.
- Shadow agent
- An AI agent running in the organization that was never registered with IT or security. Okta and Silverfort both describe discovering such agents.
Source: Okta: Secure AI
- Single sign-on (SSO)
- Signing in once with the identity provider and then reaching many applications without signing in to each.
T
- Token passthrough
- An MCP server forwarding a token it received to another API. The MCP specification forbids it.
- Token replay
- Reusing a stolen token or assertion to gain access without the password or MFA that produced it. NIST IR 8587 covers protecting tokens from forgery, theft and misuse.
Source: NIST IR 8587
W
- Workload identity
- An identity for a piece of software, such as a service, container or pipeline job, used when it calls other systems.
Z
- Zero trust
- An approach that moves defenses from network perimeters to users, assets and resources, deciding access per request.
Source: NIST SP 800-207