Machine identity is identity for non-human actors — services, workloads, containers, and agents — as opposed to human users. It covers how software proves who it is to other software.
Why it matters
Most traffic is machine-to-machine, and the old answer (a shared secret baked into config) is brittle and hard to rotate. Modern practice derives identity from what and where a workload is.
- Workload identity (SPIFFE) issues cryptographic identities to services, so they authenticate without long-lived secrets. A SPIFFE ID uniquely identifies a workload; SPIRE implements it.
- Zero trust (NIST SP 800-207) treats identity and per-request policy as the basis for access, not network location, which depends on strong machine identity.
- Signed agent traffic (Cloudflare Web Bot Auth) extends the idea to agents: HTTP message signatures let a bot or agent prove cryptographically that it is a registered actor.
- Digital identity guidelines (NIST SP 800-63) establish the broader assurance vocabulary that machine identity extends to non-persons.
Machine identity vs agent identity
Machine identity answers what is this workload? Agent identity additionally answers whose agent is it, and what is it mandated to do? Machine identity is a necessary foundation for KYA, not a substitute for it.
Related
Sources
- SPIFFE, SPIFFE Concepts — https://spiffe.io/docs/latest/spiffe-about/spiffe-concepts/ (accessed 2026-10-03)
- NIST, SP 800-207 — https://csrc.nist.gov/pubs/sp/800/207/final (accessed 2026-10-03)
- Cloudflare, Web Bot Auth — https://developers.cloudflare.com/bots/reference/bot-verification/web-bot-auth/ (accessed 2026-10-03)
- NIST, SP 800-63-4 — https://pages.nist.gov/800-63-4/ (accessed 2026-10-03)