Machine identity is identity for non-human actors — services, workloads, containers, and agents — as opposed to human users. It covers how software proves who it is to other software.
Why it matters
Most traffic is machine-to-machine, and the old answer (a shared secret baked into config) is brittle and hard to rotate. Modern practice derives identity from what and where a workload is.
- Workload identity (SPIFFE) issues cryptographic identities to services, so they authenticate without long-lived secrets. A SPIFFE ID uniquely identifies a workload; SPIRE implements it.
- Zero trust (NIST SP 800-207) treats identity and per-request policy as the basis for access, not network location, which depends on strong machine identity.
- Signed agent traffic (Cloudflare Web Bot Auth) extends the idea to agents: HTTP message signatures let a bot or agent prove cryptographically that it is a registered actor.
- Digital identity guidelines (NIST SP 800-63) establish the broader assurance vocabulary that machine identity extends to non-persons.
Machine identity vs agent identity
Machine identity answers what is this workload? Agent identity additionally answers whose agent is it, and what is it mandated to do? Machine identity is a necessary foundation for KYA, not a substitute for it.
How it works in practice
In a SPIFFE/SPIRE deployment, the platform attests a workload’s properties and the workload receives a short-lived identity document it can present to other services — no shared password to leak or rotate by hand. Zero trust then evaluates each request against policy rather than assuming that anything on the internal network is trusted.
Agents inherit this machinery but need more. A workload identity can tell a service that a process is the expected binary in the expected place; it does not, on its own, say which principal that process is acting for or what it is authorised to do. That extra layer is KYA. See Why agent identity is a new problem, What is Know Your Agent? and the verification guide.
Related terms
Sources
- SPIFFE, SPIFFE Concepts (accessed 2026-10-03)
- NIST, SP 800-207, Zero Trust Architecture (accessed 2026-10-03)
- Cloudflare, Web Bot Auth (accessed 2026-10-03)
- NIST, SP 800-63-4, Digital Identity Guidelines (accessed 2026-10-03)
Know Your Agent (KYA) explains agent identity, verification and accountability. This is an explainer, not legal or compliance advice — see our Sources & methodology. New to KYA? Start with What is Know Your Agent? and the glossary.