TRACK: BASICS

The OWASP Non-Human Identities Top 10, in plain terms

SHORT ANSWER

OWASP's 2025 list names ten ways service accounts, keys, tokens and similar identities go wrong. Most come down to three problems: nobody owns them, they last too long, and they can do too much.

Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29

2 min read

OWASP published its Non-Human Identities Top 10 for 2025. Here is each item in one or two sentences.

  1. Improper Offboarding: service accounts and keys that stay active after the project or person that needed them has gone.
  2. Secret Leakage: API keys, tokens, encryption keys and certificates ending up in places they should not, such as code or chat.
  3. Vulnerable Third-Party NHI: a compromised third-party extension or integration that holds access to your systems.
  4. Insecure Authentication: identities that authenticate with deprecated or weak methods.
  5. Overprivileged NHI: identities with far more permissions than their job requires.
  6. Insecure Cloud Deployment Configurations: static credentials or weak OIDC validation in CI/CD pipelines.
  7. Long-Lived Secrets: keys and tokens that expire far in the future, or never.
  8. Environment Isolation: the same identity used in both testing and production.
  9. NHI Reuse: one identity shared across several applications or services.
  10. Human Use of NHI: people using a service account for manual work that should be done under their own identity.

Where AI agents fit

The list covers non-human identities in general, and AI agents inherit every item on it. An agent given a long-lived key has risk 7; an agent that reuses a shared service account has risks 9 and 10. The difference is that an agent chooses its own actions, so over-privilege (risk 5) is more likely to be exercised.

See non-human identity tools compared

Related pages

Sources

NEXT LESSON

What ITDR covers, and what it does not

2 min read