Skip to main content

← Back to glossary

Term · 32. Workload Identity & Cloud-native

Ephemeral Credentials

IDM/IGA Domain

Definition

Credentials with very short lifetime (minutes) issued just-in-time and revoked after use. Replaces long-lived secrets in NHI and AI agent contexts. Foundation of zero-trust workload patterns. Mitigates credential theft impact — stolen ephemeral creds expire before exploitation.

Synonyms
  • Short-lived Credentials
  • Just-in-Time Credentials
Application
Regulatory: CNCF — SPIFFE / SPIRE specs · NIST SP 800-63 (Digital Identity Guidelines) · OWASP NHI Top 10 (2025) / SAMM
Standards & regulations
  • CNCF
  • NIST
  • OWASP