Skip to main content
Demo
Get Access
Interactive Demo|NHI Security Dashboard with sample dataBack to Demo

Non-Human Identity Security

Discover, monitor, and secure service accounts, OAuth apps, and API tokens

Total NHIs
17
15 active, 2 inactive
Critical
3
Immediate attention
High Risk
5
Review and remediate
Medium Risk
5
Monitor closely
Total Issues
15
3 expired, 5 orphaned
3
Expired Credentials
5
Over-Privileged
5
Orphaned
2
Unused 90+ Days
NameTypeRiskStatusLast UsedIssues
Legacy Provisioning Service
0oa8k3xCritical01
Service AccountCRITICAL
Score: 95
ACTIVE
May 14, 2025
268 days ago
  • Super Admin role assigned
  • Credentials expired 287 days ago
  • +2 more
prod-ci-deploy-token
0oa8k3xCritical02
API TokenCRITICAL
Score: 92
ACTIVE
Feb 5, 2026
1 days ago
  • Full admin API token with no scope restrictions
  • Created by terminated employee
  • +1 more
External HR Sync Bot
0oa8k3xCritical03
Service PrincipalCRITICAL
Score: 88
ACTIVE
Feb 6, 2026
0 days ago
  • Read/write access to all user profiles
  • Credentials shared across 3 environments
  • +1 more
Salesforce SSO Integration
0oa8k3xHigh01
SAML AppHIGH
Score: 74
ACTIVE
Feb 6, 2026
0 days ago
  • SAML certificate expiring in 12 days
  • Granted access to 847 users including contractors
GitHub Enterprise OAuth
0oa8k3xHigh02
OAuth AppHIGH
Score: 71
ACTIVE
Feb 4, 2026
2 days ago
  • Overly broad scopes: okta.users.manage, okta.groups.manage
  • Token refresh not enforced
Jenkins CI Pipeline
0oa8k3xHigh03
API TokenHIGH
Score: 68
ACTIVE
Feb 5, 2026
1 days ago
  • Token not rotated in 180+ days
  • Used from 14 different IP addresses
Datadog Monitoring Agent
0oa8k3xHigh04
Service AccountHIGH
Score: 65
ACTIVE
Feb 6, 2026
0 days ago
  • Granted read access to security logs and audit events
  • Service account owner left the organization
Slack SCIM Provisioner
0oa8k3xMed01
OAuth AppMEDIUM
Score: 45
ACTIVE
Feb 6, 2026
0 days ago
  • Token not rotated in 90+ days
Azure AD Sync Service
0oa8k3xMed02
OIDC AppMEDIUM
Score: 42
ACTIVE
Feb 6, 2026
0 days ago
  • Client secret approaching expiration (30 days)
  • No secondary credential configured
staging-test-token
0oa8k3xMed03
API TokenMEDIUM
Score: 38
ACTIVE
Jan 3, 2026
34 days ago
  • Token used infrequently (last use: 34 days ago)
Zoom SAML Integration
0oa8k3xMed04
SAML AppMEDIUM
Score: 35
ACTIVE
Feb 5, 2026
1 days ago
  • SAML assertion lifetime set to 24 hours (recommended: 5 min)
Okta Verify Push Service
0oa8k3xLow01
Service AccountLOW
Score: 12
ACTIVE
Feb 6, 2026
0 days ago
No issues
Google Workspace SSO
0oa8k3xLow02
SAML AppLOW
Score: 8
ACTIVE
Feb 6, 2026
0 days ago
No issues
Jira Cloud OIDC
0oa8k3xLow03
OIDC AppLOW
Score: 10
ACTIVE
Feb 6, 2026
0 days ago
No issues
PagerDuty Alerts Service
0oa8k3xLow04
Service AccountLOW
Score: 5
ACTIVE
Feb 6, 2026
0 days ago
No issues
Deprecated SCIM Bridge v1
0oa8k3xInactive01
Service AccountHIGH
Score: 62
INACTIVE
Sep 10, 2025
149 days ago
  • Inactive service account still has admin credentials
  • Not deprovisioned after migration
old-monitoring-webhook
0oa8k3xInactive02
API TokenMEDIUM
Score: 40
INACTIVENever
  • Inactive token never revoked

NHI Backup & Recovery

Butterfly Security backs up and monitors all non-human identities in your Okta organization. If a service account or OAuth app is compromised, instantly roll back to a known-good state. Critical and high-risk identities are flagged automatically with actionable remediation steps.