Join our Newsletter — 33% off our NHI Course
Home Glossary Identity Beyond IAM Burning
Identity Beyond IAM

Burning

← Back to Glossary
By NHI Mgmt Group Updated August 27, 2026 Domain: Identity Beyond IAM

The process of permanently destroying tokens to release a corresponding asset, credit, or locked position. In tokenized infrastructure, burning is a reversal control, often used to reclaim underlying value or access. Security teams should treat it as a high-trust action requiring strong authorization and audit logging.

Expanded Definition

Burning is the irreversible destruction of a token so that its associated value, entitlement, or locked position is removed from circulation. In tokenized infrastructure, it functions as a reversal control rather than a creation control, and it is usually tied to a smart contract, ledger rule, or administrative workflow that records the event. In NHI security terms, the same governance mindset applies to any action that permanently revokes a high-value digital object, because the control must be explicit, auditable, and resistant to misuse.

Definitions vary across vendors when burning is discussed alongside token retirement, revocation, or offboarding. No single standard governs this yet, so practitioners should separate permanent destruction from temporary suspension or access denial. That distinction matters because a burned token cannot be restored without a new issuance event, which changes both risk posture and recovery procedure. For that reason, burning aligns more closely with privileged lifecycle governance than with ordinary access administration, as reflected in the broader lifecycle guidance in Ultimate Guide to NHIs and the control-centric approach of the NIST Cybersecurity Framework 2.0.

The most common misapplication is treating burning as a reversible revoke-and-reissue step, which occurs when teams confuse permanent destruction with temporary disabling in operational workflows.

Examples and Use Cases

Implementing burning rigorously often introduces recovery friction, requiring organisations to weigh irreversible risk reduction against the operational cost of reissuance, reconciliation, and incident response.

  • A wrapped asset is burned before the underlying asset is released back to a treasury or custody system, ensuring there is no double-counting of value.
  • An expired delegation token is burned after a service transition, so a new token must be issued under current policy and approval.
  • A compromised API key is burned during incident containment, with the burn event recorded separately from the account disablement workflow.
  • An NFT or entitlement token is burned to retire a license, reclaim a reserved slot, or close out a bounded access right.
  • A privileged agent credential is burned at offboarding time, which prevents any reuse of the old secret and forces a clean trust reset.

In NHI programs, this is closely related to the lifecycle and offboarding concerns covered in Ultimate Guide to NHIs, while the broader governance pattern mirrors NIST Cybersecurity Framework 2.0 expectations for controlled changes and accountable access handling.

Why It Matters in NHI Security

Burning matters because it is often the only action that fully removes a token from future use, which is critical when tokens represent access, authority, or recoverable value. If teams rely on soft deletion, deactivation, or undocumented manual steps, stale trust can remain in place and later be reused by attackers, automation drift, or an operator with excessive privileges. The governance issue is especially sharp in NHI environments, where machine-issued credentials and tokenized permissions can outlive the systems that created them.

NHIMG research shows that 71% of NHIs are not rotated within recommended time frames, and only 20% of organisations have formal processes for offboarding and revoking API keys, which makes permanent destruction controls even more important during shutdown and compromise response. When burning is properly controlled, it supports least privilege, incident containment, and clean asset reconciliation across distributed systems. It also gives security teams a clear audit point for proving that a token no longer exists in usable form, rather than merely being marked inactive. Organisations typically encounter the need for burning only after a token has already been abused, at which point the control becomes operationally unavoidable to address.

For broader lifecycle context, see Ultimate Guide to NHIs alongside the access-governance principles in NIST Cybersecurity Framework 2.0.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-02Burning depends on strict secret and token lifecycle control to prevent reuse.
NIST CSF 2.0PR.ACBurning is a privileged access lifecycle action that supports access removal.
NIST Zero Trust (SP 800-207)Zero Trust requires continuous distrust of formerly valid credentials after burn.
NIST SP 800-63Identity assurance guidance informs how strong replacement credentials must be after burn.
OWASP Agentic AI Top 10A06Agentic systems must not retain authority after a credential is burned.

Ensure burned tokens are irrecoverable and removed from all secret stores, caches, and logs.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org