Machine Identity — KYA Glossary

Machine identity is identity for non-human actors — services, workloads, containers, and agents — as opposed to human users. It covers how software proves who it is to other software.

Why it matters

Most traffic is machine-to-machine, and the old answer (a shared secret baked into config) is brittle and hard to rotate. Modern practice derives identity from what and where a workload is.

  • Workload identity (SPIFFE) issues cryptographic identities to services, so they authenticate without long-lived secrets. A SPIFFE ID uniquely identifies a workload; SPIRE implements it.
  • Zero trust (NIST SP 800-207) treats identity and per-request policy as the basis for access, not network location, which depends on strong machine identity.
  • Signed agent traffic (Cloudflare Web Bot Auth) extends the idea to agents: HTTP message signatures let a bot or agent prove cryptographically that it is a registered actor.
  • Digital identity guidelines (NIST SP 800-63) establish the broader assurance vocabulary that machine identity extends to non-persons.

Machine identity vs agent identity

Machine identity answers what is this workload? Agent identity additionally answers whose agent is it, and what is it mandated to do? Machine identity is a necessary foundation for KYA, not a substitute for it.

Related

Sources

  1. SPIFFE, SPIFFE Concepts — https://spiffe.io/docs/latest/spiffe-about/spiffe-concepts/ (accessed 2026-10-03)
  2. NIST, SP 800-207 — https://csrc.nist.gov/pubs/sp/800/207/final (accessed 2026-10-03)
  3. Cloudflare, Web Bot Auth — https://developers.cloudflare.com/bots/reference/bot-verification/web-bot-auth/ (accessed 2026-10-03)
  4. NIST, SP 800-63-4 — https://pages.nist.gov/800-63-4/ (accessed 2026-10-03)