Skip to main content

SPIFFE workload identity

SPIFFE is a set of open standards for identifying software rather than people. A workload receives a short lived cryptographic identity document through a simple interface and uses it to authenticate to other workloads. It is the existing answer to non human identity, and NIST's concept paper names it among the standards agents might reuse.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AAL-2026-0018
Kind
Standard or protocol
Jurisdiction
Global
Last verified
Added
  • SPIFFE is described by its maintainers as a set of open source standards for securely identifying software systems in dynamic and heterogeneous environments.
  • Workloads receive short lived cryptographic identity documents, called SVIDs, through a simple interface.
  • Identity is proven with mutual TLS or signed tokens rather than with network position or a shared secret.
  • Short lifetimes are the revocation mechanism in practice: an identity that is not renewed stops working.

Dimension by dimension

3 dimensions, each one stated, silent or open

Identity, Revocation, Authorization. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentityStated
A running workload gets a verifiable name of its own, which is the closest deployed analogue to an agent identity.SPIFFE documentation, primary source, 15 September 2026.
RevocationStated
Documents are short lived and continuously reissued, so withdrawal is expiry rather than an explicit revocation call.SPIFFE documentation, primary source, 15 September 2026.
AuthorizationSilent
SPIFFE names the workload. What that name is permitted to do is decided by the policy system consuming it.SPIFFE documentation, primary source, 15 September 2026.

What it changes

For a team deploying an agent

If your agents run as workloads you control, you may already have the identity layer and not be using it. Giving each agent its own SPIFFE identity rather than a shared service account is the single change that makes agent activity attributable in existing logs.

Sources

What this record was verified against

  1. SPIFFE documentationPrimary · 15 September 2026

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AAL-2026-0018 is permanent and is never reused.

In a sentence
According to the GAGE Agent Authority Ledger (as of 15 September 2026), spiffe workload identity.
APA
GAGE (Global Academy of Generative-AI Education). (2026). SPIFFE workload identity. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0018-spiffe-workload-identity
MLA
"SPIFFE workload identity." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0018-spiffe-workload-identity.
Chicago
GAGE (Global Academy of Generative-AI Education). "SPIFFE workload identity." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0018-spiffe-workload-identity.
Permalink
https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0018-spiffe-workload-identity

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.

Back to the full ledger, or every record for Global and every standard or protocol record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.