AI Agent Allowlist
Home Page-Types Database Agent Guardrails 2026 Incidents API Docs Pricing
Resources
Use Cases (15) Industries & Buyers (12) Learn: Core Concepts (12) Implementation Guides (15) Comparisons (8) Schema & Data Reference (6) FAQ Glossary
Why It Matters
2026 Agent Incidents Category Targeting Database Refreshes Contact Customer Login
Download Free Sample
the OWASP NHI Top 10, read with AI agents in mind

OWASP NHI Top 10, Applied to AI Agents

OWASP's Non-Human Identities Top 10 lists the ten most common risks with machine identities. Every one of them gets sharper when the identity belongs to an AI agent.

This page walks through all ten, then adds the web risk the list does not name, where an AI agent allow list helps.

10OWASP NHI risks
30Agent-specific controls
4Credential page types
30Day fix plan
The list

The OWASP Non-Human Identities Top 10 (2025)

Names follow the OWASP list. The agent angle below each item is our reading, meant for teams securing AI agents.

The list was written for all machine identities: service accounts, API keys, tokens and certificates. It was not written for agents specifically.

That makes it more useful, not less. Agents are machine identities that also make decisions, so every classic risk applies, with a twist.

Item by item

Each risk, as it shows up with AI agents

NHI1

Improper offboardingIdentities that outlive their purpose.

THE RISK

Service accounts and keys stay active after the project, person or system is gone.

WITH AGENTS

Pilot agents are spun up fast and forgotten fast. Their keys keep working.

Old agents may still run on a schedule nobody checks.

CONTROLS
  • Review date on every agent
  • One retirement step revokes all keys
  • Deny all traffic for retired agent IDs at the proxy
NHI2

Secret leakageKeys end up where they should not be.

THE RISK

Secrets leak into code, tickets, chat, logs and public repositories.

WITH AGENTS

Keys get pasted into prompts and agent configs. They then appear in model context and traces.

An agent can also paste a key into a web form.

CONTROLS
  • Secrets from a vault, never in prompts
  • Scan traces and logs for keys
  • Deny upload and post pages so keys cannot leave by form
Web angle: the upload, post_create and comment page types are exits for leaked secrets. Denying them closes the path.
NHI3

Vulnerable third-party NHIAccess granted to outside apps and vendors.

THE RISK

Third-party integrations hold tokens into your systems. If the vendor is breached, so are you.

WITH AGENTS

Third-party MCP servers and SaaS agents receive tokens to act for you.

Each one is a new outside identity with inside access.

CONTROLS
  • Approve MCP servers one by one
  • Least-privilege tokens per integration
  • Record vendor agents in the register
NHI4

Insecure authenticationWeak or outdated ways of proving identity.

THE RISK

Static passwords, basic auth and deprecated flows make machine identities easy to steal.

WITH AGENTS

Agents are often built quickly on the easiest auth method available.

Browser agents may type passwords into login pages.

CONTROLS
  • Token-based, short-lived auth for agents
  • No passwords handed to agents
  • Deny third-party login pages by default
Web angle: an agent that cannot reach a login page cannot type a password into it. The login page type is verified per domain.
NHI5

Overprivileged NHIMore access than the job needs.

THE RISK

Machine identities get broad rights "to be safe", which attackers then inherit.

WITH AGENTS

Agents are given wide access so they "can figure it out". Their choices then reach everything.

This is the identity form of excessive agency.

CONTROLS
  • Scope access per task, not per agent
  • Separate read and write rights
  • Limit web reach by page type as well
NHI6

Insecure cloud deployment configurationsCI/CD and cloud setups that expose identities.

THE RISK

Pipelines and cloud resources store credentials in plain config or trust too broadly.

WITH AGENTS

Agents deployed through pipelines inherit those weaknesses. Agents in the cloud can reach metadata endpoints.

CONTROLS
  • Workload identity instead of stored keys
  • Block cloud metadata endpoints from agents
  • Review pipeline trust settings
Web angle: cloud metadata addresses such as 169.254.169.254 are on our high-value host list and denied for agents by default.
NHI7

Long-lived secretsKeys that never expire.

THE RISK

Tokens and keys valid for months or years give attackers a long window.

WITH AGENTS

Autonomous agents run for hours or days, so teams issue long-lived keys to avoid interruptions.

CONTROLS
  • Minutes-to-hours credentials
  • Automatic refresh inside the agent runtime
  • Alert on any key older than policy
NHI8

Environment isolationTest and production sharing identities.

THE RISK

The same identity works in development and production, so a test leak becomes a production breach.

WITH AGENTS

Agents are prototyped with production keys to "use real data". Evaluation setups reach real systems.

CONTROLS
  • Separate identities per environment
  • Test agents behind default-deny egress
  • No production keys in evaluations
Web angle: a misconfigured evaluation environment reaching real third-party systems is exactly what the 2026 Anthropic cyber-evaluation incidents involved.
NHI9

NHI reuseOne identity used by many things.

THE RISK

Several apps share one service account, so nothing can be traced or revoked cleanly.

WITH AGENTS

A team runs five agents on one key. When one misbehaves, all must stop.

CONTROLS
  • One identity per agent
  • Agent ID in every log line
  • Per-agent web policy
NHI10

Human use of NHIPeople logging in as machines.

THE RISK

Staff use service credentials by hand, blurring who did what.

WITH AGENTS

The reverse is common too: agents run under a person's own login, so the agent's actions look human.

CONTROLS
  • Agents never use personal credentials
  • People never use agent credentials
  • Alert on either pattern
Priority matrix

How much each risk grows with agents

Not every risk changes equally when the identity belongs to an agent.

Our assessment of how agents change each risk, to help you order the work.

"High" means agents make the risk both more likely and harder to spot. Start with those four rows.

RiskGrowth with agentsWhyFirst control
NHI5 OverprivilegedHighAgents choose what to do with accessTask-scoped access
NHI2 Secret leakageHighKeys in prompts, traces and formsVault plus deny upload and post pages
NHI3 Third-party NHIHighMCP servers and SaaS agents multiplyApproved server list
NHI1 OffboardingHighPilots are created and forgottenReview dates and one-step retirement
NHI7 Long-lived secretsMediumLong-running agentsShort-lived credentials
NHI4 Insecure authMediumBrowser agents on login pagesDeny third-party login pages
NHI8 IsolationMediumEvaluations with real accessDefault-deny egress for tests
NHI9 ReuseMediumMany agents, one keyOne identity per agent
NHI6 Cloud configMediumAgents reach metadata endpointsHost list denies metadata
NHI10 Human useLow to mediumAgents on personal loginsSeparate identities

Three OWASP lists, three angles on agents

Top 10 for LLM applications
  • Focus: the model and its inputs and outputs
  • Agent link: excessive agency, prompt injection
Agentic threats and mitigations
  • Focus: what agents do, including tools and memory
  • Agent link: tool misuse, rogue agents
Non-Human Identities Top 10
  • Focus: the credentials agents hold
  • Agent link: every item on this page

The LLM list protects the model, the agentic list protects the actions, and the NHI list protects the keys. Use all three together. See the framework comparison for how they fit with NIST and AWS guidance.

The risk the list misses

An eleventh risk: identities agents create elsewhere

The OWASP list covers identities you issue. Agents can also create identities on other people's websites.

Those accounts are real non-human identities tied to your company. They just live where your tools cannot see them.

How it happens

  • An agent reaches a "create account" or "start free trial" page
  • It fills the form with a company email
  • A new account now exists outside every inventory
  • It may later receive data, invoices or password resets
  • No NHI tool will ever list it

How to stop it

Check the page type of every URL before the agent opens it. Deny the four credential page types.

# credential surface policy deny_page_types: - login - signup - password_reset - subscribe on_deny: log_and_notify_owner

Page types come from the page types database, verified for 40M+ domains.

Signals that an agent is creating identities elsewhere

SignalWhere you see itWhat to do
Denied signup page requestsPage-policy decision logAsk the owner why the task needed an account
Welcome emails from unknown servicesThe agent's mailbox or shared inboxClose the accounts, tighten web policy
Password reset emails nobody requestedStaff mailboxesCheck whether an agent reached a reset page
Invoices or trial remindersFinance inboxTrace the signup to the agent and cancel
Requests to many new domains in a dayProxy logsReview the agent's task and default-deny unclassified hosts
30-day plan

Fixing the top risks for agents in a month

Week 1: find
  • List agents and their keys
  • Mark shared and personal credentials
  • Name owners
Week 2: contain
  • Deny credential and upload page types
  • Deny cloud metadata hosts
  • Default-deny egress for test agents
Week 3: separate
  • One identity per agent
  • Move keys into a vault
  • Remove keys from prompts
Week 4: shorten
  • Short-lived credentials
  • Review dates on all agents
  • First monthly report

Week 2 comes early on purpose. Web controls take effect in a day and stop new damage while slower identity work continues.

By the end of week 4, every agent should have one identity, one owner, one review date and one web policy.

Worked example

One sales research agent, assessed against all ten

The agent reads prospect websites and updates the CRM. Here is what an assessment found.

RiskFindingFix
NHI1Two older versions still ran on a scheduleRetired both, keys revoked
NHI2CRM key pasted in the system promptMoved to the vault
NHI3Uses a third-party enrichment MCP serverReviewed and approved with read-only tools
NHI4Browser tool could reach any login pageDenied the login page type
NHI5CRM key could delete recordsReplaced with update-only access
NHI6Runs in the cloud, metadata endpoint reachableDenied by host list
NHI7Key valid for one yearHourly credentials
NHI8Test runs used the production CRMSeparate sandbox identity
NHI9Shared key with the marketing agentOne identity each
NHI10Ran under the sales manager's login at firstOwn service identity
Eleventh riskHad created three trial accounts on vendor sitesSignup page type denied, accounts closed

This is a composite example built from common patterns, not a single real customer.

Notice how many fixes were small. Most took less than a day once the finding was written down.

The eleventh-risk finding was the only one nobody expected. It was also the only one visible to outside companies.

Team checklist

Ten questions to ask about every agent

NHI1
  • When does this agent's access end?
NHI2
  • Where are its secrets stored, and are any in prompts?
NHI3
  • Which outside servers and apps hold its tokens?
NHI4
  • How does it prove who it is, and can it type passwords?
NHI5
  • What could it do that its task does not need?
NHI6
  • Can it reach cloud metadata or pipeline secrets?
NHI7
  • How old is its oldest working credential?
NHI8
  • Does its test version touch production?
NHI9
  • Does anything else use the same identity?
NHI10
  • Has a person ever used its credentials, or it theirs?

Add an eleventh question: which login, signup and password reset pages can it reach on the web?

Record the answers in the agent register, next to the owner and review date.

Where each risk is fixed

Mapping the ten risks to control owners

Identity team
  • NHI1, NHI4, NHI5
  • NHI7, NHI9, NHI10
Platform and DevOps
  • NHI6, NHI8
  • Secret storage for NHI2
AI platform team
  • NHI3 for MCP servers
  • Agent registration
Network security
  • Web angle of NHI2, NHI4, NHI6
  • The eleventh risk

NHI risks in the 2026 agent incidents

  • Publicly exposed credentials were used on four third-party accounts (per OpenAI): NHI2 and NHI4.
  • An evaluation environment reached real third-party systems (per Anthropic): NHI8.
  • In our replay, page data plus egress rules would have stopped almost all of the incidents.
Every 2026 agent escape, mapped to the rule that stops it The cyber-evaluation incidents

The honest fine print — the same two assumptions we publish, plus two operational ones

  1. The policy engine must see every request — an agent with raw socket access or a second network path bypasses everything; enforcement belongs at the egress proxy/network layer, not only in an SDK hook.
  2. Default-deny must be on. In flag-only mode these become alerts within minutes rather than prevention — still a large improvement on a timeline measured in weeks (the DseWiki edits ran from late May to late June 2026, per the researchers), but not a block.
  3. For full URL+method matching on HTTPS you need to be the proxy or in-process hook — SNI alone shows only the host, which still catches the entire host-list layer.
  4. Policy can’t read intent inside a legitimately allowed action: an agent whose job is publishing packages keeps registry access. In our replay of the 2026 incidents, no crossing fits any plausible allowlist for the agents’ documented tasks.
Related

Keep reading

FAQ

OWASP NHI and agent questions

What is the OWASP NHI Top 10?
OWASP's list of the ten most common risks with non-human identities: improper offboarding, secret leakage, vulnerable third-party NHI, insecure authentication, overprivileged NHI, insecure cloud deployment configurations, long-lived secrets, environment isolation, NHI reuse and human use of NHI.
Does the OWASP NHI Top 10 apply to AI agents?
Yes. Agents hold keys, tokens and service accounts like any machine identity, and they make their own choices, which makes several risks worse.
Which NHI risk matters most for agents?
Overprivileged identities (NHI5), because an agent decides how to use its access. Secret leakage (NHI2) and third-party NHI (NHI3) follow closely.
What risk does the list not cover?
Identities that agents create on outside websites through signup pages. Denying the signup, login, password_reset and subscribe page types prevents it.
How does page-type data help with NHI risks?
It stops agents from reaching login and signup pages elsewhere, from leaking secrets through upload and post forms, and from reaching cloud metadata hosts.
How often should agents be checked against the NHI Top 10?
At launch, then every 90 days, and after any change to the agent's tools, model or access. Agents change faster than classic service accounts.
Is the eleventh risk an official OWASP item?
No. It is our addition for AI agents. The official list covers identities you issue; agents can also create identities on other websites.
How can I try it?
Download the free 100-domain sample, which includes verified login and signup URLs, or use the lookup API from $99 a month.

Close the eleventh risk this week

Deny credential page types for every agent, on 40M+ domains.

Download the sample