The reference for securing AI

Agentic AI Security
Glossary

Plain-language definitions for the vocabulary of AI security: agent and workload identity, MCP security, AI threats, and governance.

12Terms
6Categories
Jul ’26Last updated
Featured termAgent Identity

Non-Human Identity

A non-human identity (NHI) is a unique descriptor assigned to a technological system, such as a machine, application or AI agent, for authentication and authorization.

SecureW2 Editorial Team5 min read
Agentic AIIdentity
Read definition
Browse by Topic

Glossary categories

Six clusters spanning AI threats, agent & workload identity, MCP security, and governance.

View all terms
Full index

Explore the glossary

Showing 12 of 12 terms
Agent Identity

Agent Identity

Agent identity, or AI agent identity, is a digital identity assigned to an AI agent. The identity is unique, verifiable, and distinct from human users or static service accounts.

Agentic AIIdentity
● 5 min read
Governance & Compliance

Identity and Access Management (IAM)

Identity and access management (IAM) comprises the protocols and tools that determine whether specific users, devices, and services can use certain systems — and how.

AuthorizationComplianceGovernance
● 4 min read
MCPs

MCP Authentication

Model Context Protocol (MCP) authentication is the process that verifies the identity of clients requesting access to a server’s tools, resources or data. It requires new validation with every request.

AuthenticationAuthorizationMCP
● 4 min read
Workload Identity

mTLS for AI Agents

Mutual Transport Layer Security (mTLS) for AI agents is a security protocol where both the agent and the connecting service verify each other with X.509 digital certificates.

Agentic AIIdentitymTLS
● 5 min read
Agent Identity

Non-Human Identity

A non-human identity (NHI) is a unique descriptor assigned to a technological system, such as a machine, application or AI agent, for authentication and authorization.

Agentic AIIdentity
● 5 min read
Security

Phishing-Resistant MFA

Phishing-resistant multi-factor authentication (MFA) is an advanced verification method that combines public key cryptography (protects credentials) and origin binding (links logins to specific domains).

AttackAuthenticationDefense
● 5 min read
AI Threats

Prompt Injection Attacks

Prompt injection attacks manipulate large language model (LLM) inputs with malicious instructions to override intended behaviors or trigger unauthorized actions. It’s like command injection or SQL injection, but for AI.

AttackInjectionLLM
● 5 min read
Workload Identity

SPIFFE

Secure Production Identity Framework for Everyone (SPIFFE) is an open-source standard for establishing cryptographic identities for software workloads, microservices and containers.

CertificatesIdentityStandards
● 5 min read
Workload Identity

SPIRE Server

A SPIRE Server is the control plane for SPIFFE environments. It acts as the central certificate authority and trust anchor for assigning cryptographic identities (known as SPIFFE Verifiable Identity Documents or SVIDs) to workloads, AI agents and containers.

IdentityStandardsWorkload Identity
● 5 min read
Workload Identity

SVIDs

A SPIFFE Verifiable Identity Document (SVID) is a credential that establishes identity for a workload, service or container to a resource or another service. The credential is cryptographically signed and encodes a unique SPIFFE ID issued in either X.509 or JWT format.

CertificatesIdentityWorkload Identity
● 5 min read
Workload Identity

Workload Identity

Workload identity is a unique, cryptographically verifiable identity assigned to a non-human software workload such as a microservice, application, container, serverless function or scripts.

IdentityWorkload Identity
● 5 min read
Workload Identity

X.509 Certificate

An X.509 certificate is a standardized digital file which cryptographically binds a public key to an identity such as a person, device, server, workload or AI agent.

AuthenticationCertificatesIdentity
● 5 min read