Skip to content
Identity and access

Machine callers are identities too.

API Access Management issues and governs tokens for programmatic callers, so a service or integration authenticates with a scoped credential rather than a broad one. Our work is inventorying machine callers and scoping the tokens they hold.

API Access Management governs what a service, script, or integration may call. It is where non-human access is either scoped deliberately or granted broadly and forgotten.

What it is

API Access Management issues and governs tokens for programmatic callers, so a service or integration authenticates with a scoped credential rather than a broad one.

It is for organizations whose integrations currently authenticate with credentials created by whoever built them.

identity owner expires one owner recorded, five unaccounted L1 L2 L3 L4

What it does

Scoped tokens

A caller gets what it needs rather than what was convenient at the time.

Tokens with a lifecycle

Issued, rotated, and revoked, which is what makes an inventory meaningful.

Where it fits

L1, identity and access, controlling behavior that appears at L2 and L4. Every integration and every agent is a machine caller. Scoping those callers is the same work as scoping people, and it is done far less often.

Where it earns its place

An estate with scripted integrations

Credentials in scripts on somebody's machine are the most common unowned access in any estate.

An organization connecting assistants

An assistant is a machine caller. The same scoping applies.

Questions we get

Is this only for our own APIs?
No. The discipline applies to anything holding a token, including integrations into systems you do not run.

Find out who can reach what.

Fixed scope. The assessment starts at the identity layer: human and non-human access, the accounts nobody owns, and what has to be true before an agent gets one. You get the findings, the ownership gaps, and the order to close them in.