Record metadata
type: "Specification"
title: "SPIFFE / SPIRE"
description: "Workload identity and attestation for software systems."
resource: "https://spiffe.io/docs/latest/spiffe-about/overview/"
tags: [spiffe, identity, security]
generated: { by: human:crpage, at: 2026-07-09T09:44:00Z }
status: stable
sources: [{ id: primary, resource: "https://spiffe.io/docs/latest/spiffe-about/overview/" }]
SPIFFE defines open standards for identifying software systems in dynamic environments; SPIRE issues workload identities after node and workload attestation. A complement to OAuth, not an alternative: workload identity establishes what is calling; OAuth establishes on whose behalf. Essential for service meshes and agent runtimes.
Terms
Glossary terms used here: Attestation, Workload identity.