Every machine identity you have, and the human who answers for it.
Nomyr is an open-source, self-hostable non-human identity (NHI) security platform for service accounts, cloud roles, API keys, certificates, OAuth applications, workload identities, automation, and AI agents.
We are building Nomyr as an open-source alternative to commercial NHI security platforms such as Astrix Security and Oasis Security. Teams can inspect the code, self-host the platform, extend its contracts, and keep identity metadata and evidence inside their own security boundary.
Nomyr connects identity inventory, ownership, reach, posture, lifecycle, and verified action in one evidence-backed system:
- Discover every machine identity across cloud, SaaS, CI/CD, Kubernetes, identity providers, vaults, certificate authorities, code repositories, and on-premises systems.
- Resolve accountable ownership using evidence from service catalogs, CODEOWNERS, deployment metadata, creation events, and attestations.
- Understand effective reach across configured, observed, inferred, and unknown access paths without hiding uncertainty.
- Prioritize identity risk using posture, blast radius, evidence quality, activity, and coverage as distinct signals.
- Govern the complete lifecycle from provisioning and federation through rotation, access review, exception handling, and verified retirement.
- Secure workloads and AI agents with scoped policies, attributable sessions, human-approved remediation, and explicitly authorized automation.
Nomyr keeps the experience, control, secret custody, and action execution planes physically separate. Public behavior starts with versioned OpenAPI, protobuf, and JSON Schema contracts. Unknown and unresolved states remain visible, and a completed action is verified against its original intent.
- Explore Nomyr — source code, architecture, local setup, and project overview
- Understand the architecture — runtime boundaries, public contracts, and security design
- Contribute — development workflow, commit conventions, issues, and pull requests
- Open an issue — report a bug, request a feature, or suggest a documentation improvement
- Join the community — ask questions and collaborate with contributors
- Report a vulnerability — follow the private security-reporting process
Nomyr is independent of Astrix Security and Oasis Security and is not affiliated with or endorsed by either company. Their names and trademarks belong to their respective owners.