What Is Dormant Token?
A dormant token is a credential — an API key, OAuth token, or service account key — that remains valid and technically capable of granting access, but has not actually been used in an extended period. Unlike an expired or revoked credential, a dormant token was never deactivated: it simply stopped being exercised, often because the integration or automation it supported was replaced, deprioritized, or quietly abandoned without a formal decommissioning step. Dormancy is a usage-based state, not a lifecycle status — a token can appear perfectly legitimate in an inventory, with the right scopes and a valid owner on record, while sitting completely idle for months or years. This makes it distinct from an orphaned account, which is defined by a missing owner rather than a lack of activity, though the two conditions frequently overlap.
Why It Matters
A dormant token is access without a workload behind it — a standing door that no one is using but that also no one has closed. Because it produces no regular activity, there is no established baseline of 'normal' behavior for it, which makes any future use of the token — legitimate or malicious — harder to evaluate as anomalous. An attacker who obtains a dormant token, whether through a leaked secret, a breached repository, or a compromised third-party integration, can often use it without triggering the kind of alerts that would fire on an active credential's unusual behavior, since there's no recent pattern to deviate from. Traditional identity tools built around login events largely miss this risk, since dormant tokens generate no sign-in to flag. This blind spot compounds at scale: with non-human identities outnumbering employees by up to 45 to 1 in many organizations, and OWASP's NHI Top 10 (2025) finding that 80% of identity breaches involve a non-human identity, unused-but-valid credentials represent exactly the kind of overlooked access attackers look for.
How Cydenti Helps
Cydenti continuously tracks credential usage across your environment, distinguishing tokens that are actively doing work from those that have gone quiet, and surfaces dormancy as a first-class risk signal rather than a footnote in an inventory list. Dormant tokens are prioritized alongside their scope and blast radius, so teams can decide quickly whether to revoke, rotate, or reconfirm ownership — closing the gap before it's tested by someone else.
Explore →Frequently Asked Questions
How long does a token need to be unused to be considered dormant?
There's no universal threshold — it depends on the credential's expected usage pattern. A token tied to a daily sync job going quiet for two weeks is a stronger signal than one tied to a quarterly batch process. What matters is the deviation from that specific token's normal cadence, not a fixed number of days.
Is a dormant token the same risk as an orphaned account?
They're related but distinct. A dormant token is defined by lack of use; an orphaned account is defined by lack of a known owner. A token can be actively used but ownerless, or unused but still tied to a valid owner — though in practice, dormancy and lost ownership often occur together.
Discover the machine identities you didn't know you had
— in 27 minutes, for free.
NIS2 enforcement begins October 1, 2026. The Audit Flash delivers your complete NHI exposure snapshot — service accounts, orphaned credentials, OAuth grants, AI agents — with a first report in 3 hours. No commitment.
No commitment • No credit card • Data hosted in Europe • Response within 24h