TRACK: BASICS
The OWASP Non-Human Identities Top 10, in plain terms
SHORT ANSWER
OWASP's 2025 list names ten ways service accounts, keys, tokens and similar identities go wrong. Most come down to three problems: nobody owns them, they last too long, and they can do too much.
Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29
2 min read
OWASP published its Non-Human Identities Top 10 for 2025. Here is each item in one or two sentences.
- Improper Offboarding: service accounts and keys that stay active after the project or person that needed them has gone.
- Secret Leakage: API keys, tokens, encryption keys and certificates ending up in places they should not, such as code or chat.
- Vulnerable Third-Party NHI: a compromised third-party extension or integration that holds access to your systems.
- Insecure Authentication: identities that authenticate with deprecated or weak methods.
- Overprivileged NHI: identities with far more permissions than their job requires.
- Insecure Cloud Deployment Configurations: static credentials or weak OIDC validation in CI/CD pipelines.
- Long-Lived Secrets: keys and tokens that expire far in the future, or never.
- Environment Isolation: the same identity used in both testing and production.
- NHI Reuse: one identity shared across several applications or services.
- Human Use of NHI: people using a service account for manual work that should be done under their own identity.
Where AI agents fit
The list covers non-human identities in general, and AI agents inherit every item on it. An agent given a long-lived key has risk 7; an agent that reuses a shared service account has risks 9 and 10. The difference is that an agent chooses its own actions, so over-privilege (risk 5) is more likely to be exercised.
See non-human identity tools compared
Related pages
Sources
- OWASP Non-Human Identities Top 10 (2025): https://owasp.org/www-project-non-human-identities-top-10/
NEXT LESSON
What ITDR covers, and what it does not
2 min read