In brief: NIST and CISA have released final IR 8587 guidance against stolen, forged and replayed identity tokens. It defines measurable controls for cloud providers and US agencies. For enterprises, the main shift is from persistent machine secrets to short-lived workload identities.
Specific limits replace broad IAM advice
The guidance covers asymmetrically signed identity and access tokens for single sign-on, federation, APIs and workloads. It extends NIST SP 800-53. Conformance remains voluntary unless policy or contracts make it binding, although capitalised MUST and SHOULD terms define testable requirements.
Signing keys for high-impact systems should remain active for no more than 90 days; low- and moderate-impact systems should stay below one year. Creation, overlap, deactivation, revocation and destruction must be documented and automated where practical. Depending on risk, IR 8587 calls for hardware-backed or otherwise isolated key storage and use.
Identity and access tokens should generally remain valid for no more than one hour. Each must identify its issuer, audience, validity window and unique ID; systems must reject missing or incorrect audiences. NIST recommends sender-constrained mechanisms such as mutual TLS or DPoP against replay. API and machine refresh tokens should be as short-lived as possible.
Revocation remains an architecture problem
Immediate global revocation before expiry is not always possible with stateless tokens. Providers should distribute revocation state through introspection endpoints, status lists or shared signals; connected services must reject revoked tokens and terminate sessions. Short lifetimes reduce exposure but do not replace anomaly detection or tamper-resistant logs.
For workloads, IR 8587 requires tightly scoped, short-lived tokens from approved identity platforms. SPIFFE-based identities can eliminate static credentials and rotate automatically. This applies to services and AI agents using signed tokens for tools or APIs.
Pandorex Analysis
The value is not a new login method but an end-to-end lifecycle. Cloud contracts and architecture reviews should specify key and token lifetimes, emergency rotation, cross-service revocation and exportable event data. Successful MFA offers limited protection if other services accept a stolen token for hours.
The document is deliberately incomplete for AI agents. Its rules cover signed access, but broader agent risks remain outside scope. IR 8587 is a foundation for machine identities, not a complete security model for autonomous agents.
