The identity glossary
Plain-language definitions for the vocabulary of modern identity, customer identity and access management, the governance of AI agents, and the mechanics of migrating off legacy platforms. Written for the people who have to make decisions with these words: architects, security leads, product owners, and the developers who implement them.
The entries people cite most
Pushed Authorization Requests is an OAuth extension that lets a client send its authorization request details directly to the authorization server over a secure back-channel first, receiving a referen…
Read the definitionRich Authorization Requests is an OAuth extension that lets a client describe the access it's requesting in fine-grained, structured detail, such as a specific account, amount, or action, rather than…
Read the definitionPasskeys are a passwordless, phishing-resistant credential based on public key cryptography, usually unlocked with a device's built-in biometric or PIN.
Read the definitionResource indicators are a mechanism, standardized in RFC 8707, that lets a client specify exactly which protected resource it intends to use an access token for, so the authorization server can issue…
Read the definitionAll terms
CIAM
23 termsThe vocabulary of running customer identity and access management, thresholds, flows, and the controls buyers get asked about.
- What are passkeys?Passkeys are a passwordless, phishing-resistant credential based on public key cryptography, usually unlocked with a device's built-in biometric or PIN.CIAM
- What is Authentication?Authentication is the process of confirming that a user or system is who or what it claims to be, typically by verifying a factor such as a password, a one-time code, a biometric, or a cryptographic k…CIAM
- What is Authorization?Authorization is the process of determining what an authenticated identity is permitted to do, such as which data it can read or which action it can take.CIAM
- What is Customer Identity and Access Management (CIAM)?CIAM is the set of technologies and practices that manage how an organization's customers register, authenticate, and access digital services, and how their identity data and consent are governed acro…CIAM
- What is Identity and Access Management (IAM)?IAM is the broader discipline of managing digital identities and controlling what each identity can access, covering employees, contractors, partners, systems, and (increasingly) software agents.CIAM
- What is OAuth 2.0?OAuth 2.0 is an authorization framework that lets an application obtain limited, scoped access to a protected resource on a user's behalf, without that application ever handling the user's password.CIAM
- What is OpenID Connect (OIDC)?OpenID Connect is an identity layer built on top of OAuth 2.0 that adds a standard way for an application to confirm who authenticated and to receive basic profile information as a signed token.CIAM
- What is a refresh token?A refresh token lets an application obtain a new access token without asking the user to sign in again.CIAM
- What is a scope?A scope is a named unit of access that a client can request, such as "read profile" or "read account balance." Scopes let an authorization request be as narrow as possible, a core part of the principl…CIAM
- What is adaptive access (risk-based authentication)?Adaptive access adjusts authentication requirements based on contextual risk signals, such as an unfamiliar device, an unusual location, or an atypical time of access, rather than applying the same fr…CIAM
- What is an ID token?An ID token, from OpenID Connect, carries information about who authenticated, so the application can establish a session.CIAM
- What is an access token?An access token is a credential an application presents to an API to prove it has been granted specific, scoped access; it is typically short-lived.CIAM
- What is an identity provider (IdP)?An identity provider is the system responsible for authenticating a user and issuing a token or assertion that other applications trust as proof of that authentication.CIAM
- What is consent management?Consent management is the capture, storage, and enforcement of a customer's choices about how their personal data may be used, such as marketing communications or data sharing with third parties.CIAM
- What is data residency?Data residency is the practice of storing and processing identity data within a specific country or region to satisfy regulatory, contractual, or sovereignty requirements.CIAM
- What is fraud detection?Fraud detection identifies suspicious account activity, such as unusual login patterns, device anomalies, or signs of a compromised credential, so it can be stopped or challenged before it causes harm…CIAM
- What is identity orchestration?Identity orchestration is the configuration layer that sequences the individual steps of a registration, login, or account-recovery journey, such as identity verification, MFA, consent capture, and da…CIAM
- What is identity verification (identity proofing)?Identity verification confirms that a real-world identity belongs to the person registering or transacting, typically using a government-issued document, a biometric liveness check, or knowledge-based…CIAM
- What is multi-factor authentication (MFA)?MFA requires a user to verify their identity using more than one independent factor, typically something they know (a password), something they have (a device or security key), or something they are (…CIAM
- What is passwordless MFA?Passwordless MFA is a method of multi-factor authentication that does not include a password.CIAM
- What is passwordless authentication?Passwordless authentication lets a user sign in without a password, instead using a method such as a passkey, a one-time code sent by email or SMS, a magic link, or a hardware security key.CIAM
- What is progressive profiling?Progressive profiling collects customer profile information gradually across multiple interactions rather than all at once during initial registration.CIAM
- What is single sign-on (SSO)?SSO lets a user authenticate once and gain access to multiple connected applications without signing in again to each one.CIAM
Agentic AI Management & Governance
24 termsTerms for identity when there is now a machine in the record, authorized, scoped, and revocable.
- What are Pushed Authorization Requests (PAR)?Pushed Authorization Requests is an OAuth extension that lets a client send its authorization request details directly to the authorization server over a secure back-channel first, receiving a referen…Agentic AI
- What are Rich Authorization Requests (RAR)?Rich Authorization Requests is an OAuth extension that lets a client describe the access it's requesting in fine-grained, structured detail, such as a specific account, amount, or action, rather than…Agentic AI
- What are resource indicators / audience restriction (RFC 8707)?Resource indicators are a mechanism, standardized in RFC 8707, that lets a client specify exactly which protected resource it intends to use an access token for, so the authorization server can issue…Agentic AI
- What is Client-Initiated Backchannel Authentication (CIBA)?CIBA is an OpenID Connect flow that lets an authorization happen on a separate device or channel from the one making the request, such as approving an action on a phone while an agent or service compl…Agentic AI
- What is Demonstrating Proof of Possession (DPoP)?DPoP is an OAuth mechanism that cryptographically binds an access token to the specific client that requested it, so a stolen token can't simply be replayed by an attacker from a different device.Agentic AI
- What is Know Your Agent (KYA)?Know Your Agent is the practice of verifying which organization or developer is accountable for a given AI agent before granting it access, similar in spirit to "know your customer" checks in financia…Agentic AI
- What is OAuth 2.1?OAuth 2.1 is a consolidation of OAuth 2.0 best practices developed over a decade into a single, simplified specification, dropping legacy flows that proved insecure and making protections such as PKCE…Agentic AI
- What is a Client ID Metadata Document (CIMD)?A Client ID Metadata Document is an emerging OAuth extension in which a client's identifier is itself a URL that resolves to a document describing the client, allowing an authorization server to ident…Agentic AI
- What is a non-human identity (NHI) / machine identity?A non-human identity, also called a machine identity, is any identity assigned to software rather than a person, including services, scripts, devices, and AI agents.Agentic AI
- What is a protected resource?A protected resource is an API or server, such as a Model Context Protocol (MCP) server, that requires a valid, scoped access token before it will act on a request.Agentic AI
- What is a two-actor audit trail?A two-actor audit trail is a logging pattern that records both the customer on whose behalf an action was taken (the subject) and the AI agent that actually performed it (the actor), rather than colla…Agentic AI
- What is agent lifecycle management?Agent lifecycle management is the ongoing administration of an AI agent's identity from initial registration through active use to eventual deactivation or revocation, mirroring how organizations mana…Agentic AI
- What is agentic CIAM?Agentic CIAM is the application of customer identity and access management principles, authentication, authorization, consent, and audit, to AI agents acting on a customer's behalf, alongside the huma…Agentic AI
- What is agentic identity?Agentic identity is the practice of giving AI agents, software that can act autonomously on a person's or organization's behalf, their own verifiable identity, rather than treating them as an extensio…Agentic AI
- What is an AI agent?In an identity context, an AI agent is a piece of software, often built on a large language model, that can take actions on behalf of a person or organization, such as booking a service, checking an a…Agentic AI
- What is an Identity Assertion Authorization Grant (ID-JAG)?ID-JAG is an emerging OAuth grant type that lets an existing identity assertion (such as an OIDC ID token) be exchanged for a new access token scoped to a different resource, carrying identity context…Agentic AI
- What is an MCP server?An MCP server is a server that implements the Model Context Protocol, exposing a defined set of tools or data an AI agent can call.Agentic AI
- What is delegated authorization?Delegated authorization is the process by which a person grants a third party, such as an application or an AI agent, permission to act on their behalf, without handing over their credentials.Agentic AI
- What is delegated consent?Delegated consent is the customer's explicit, informed approval for a specific AI agent to take specific actions on their account, typically captured during login through a consent screen that names t…Agentic AI
- What is dynamic client registration?Dynamic client registration lets a software client, such as an AI agent, register itself with an authorization server at runtime rather than requiring an administrator to manually provision it in adva…Agentic AI
- What is incremental authorization?Incremental authorization is the process of granting an AI agent additional, narrowly scoped access after the fact, when it attempts an action outside what it was originally authorized for, rather tha…Agentic AI
- What is scoped access (for agents)?Scoped access means an AI agent is granted only the specific, named permissions it needs for a task, such as "read loyalty balance" or "initiate a refund," rather than broad or standing access to an a…Agentic AI
- What is the Model Context Protocol (MCP)?The Model Context Protocol is an open specification that lets AI applications, including AI agents, discover and call external tools and data sources in a standardized way.Agentic AI
- What is token exchange?Token exchange is an OAuth 2.0 extension that lets one token be exchanged for another, often to convert a broader credential into a narrower, resource-specific one, or to pass identity context from on…Agentic AI
Migration
8 termsHow you get customers onto a new identity platform without a cutover or a mass password reset.
- What is CIAM migration?CIAM migration is the process of moving customer accounts, including profile da…Migration
- What is IdP migration?IdP migration is the process of moving customer authentication from an existing identity provider to a new one, so the new product becomes the system that authenticates customer sign in going forward.Migration
- What is bulk migration?Bulk migration transfers all customer accounts to a new system at once, before customers begin signing in through it.Migration
- What is just-in-time migration?Just-in-time (JIT) migration moves a customer's account to a new identity provider the moment they sign in for the first time after the switc…Migration
- What is password hash migration?Password hash migration transfers a customer's hashed password from a legacy system to a new one, so the customer can keep signing in with their existing password instead of resetting it.Migration
- What is user migration?User migration, often called bulk import, transfers customer account records into a new identity system before customers begin signing in through it, rather than migrating one account at a time as cus…Migration
- What is vendor lock-in?Vendor lock-in is a situation where switching away from a CIAM vendor becomes difficult…Migration
- What is zero-downtime migration?Zero-downtime migration is a migration where customer sign in stays available throughout the transition, with no cutover window during which customers lose access.Migration
The three pillars behind this glossary
Every entry belongs to one of these. Each pillar page pulls the terminology together into an argument.
Customer identity & access management
Why CIAM exists, what it replaces, and how you evaluate it without turning identity into a science project.
Explore ciam PillarAgentic AI management & governance
How agents get identities, scopes, and audit trails, before they act on behalf of a person, tenant, or another agent.
Explore agentic AI PillarMigration off legacy identity
How organizations move off a legacy identity platform without a hard cutover or a mass password reset.
Explore migrationReady to move beyond legacy CIAM?
Definitions are the easy part. Go live in weeks with identity that governs AI agents, customers, and partners from one place.
Learn more.avif)