# spiffe

Source: https://startwithidentity.com/glossary/spiffe/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

Secure Production Identity Framework for Everyone. A CNCF-graduated specification for workload identity. SPIFFE IDs are URI-like identifiers; SVIDs are the cryptographic credentials (x509 or JWT) that prove a workload owns its ID.

SPIFFE matters because it gives workloads an identity the platform attests, rather than a secret someone provisioned, which removes the credential from the threat model entirely. The identity is derived from where and what the workload is, and the SVID is short-lived by design. It is the cleanest available answer to service-to-service authentication in Kubernetes and multi-cloud estates.

See also: [workload identity](https://startwithidentity.com/glossary/workload-identity/), [mTLS](https://startwithidentity.com/glossary/mtls/), [what is machine identity](https://startwithidentity.com/guides/fundamentals/what-is-machine-identity/), [machine identity vendors](https://startwithidentity.com/vendors/machine-identity/)
