categories
Authentication
Browse Pomerium articles in the Authentication category.
Topic archive
Resources Categorized: Authentication
Achieving zero trust with Pomerium JWTs
We discuss how Pomerium JWTs enable zero trust architecture for verifying each request.
.jpg.CWC_SBoG.webp)
Context-Aware Authentication: Meaning, Tools, Examples
In this article, we'll explore what context-aware authentication means, share real-life examples, discuss the top implementation tools, and dive into use cases.

SSO: OAuth2 vs OIDC vs SAML
Single Sign-On (SSO) is a way for users to be authenticated for multiple applications and services with one process. Should you use OAuth2, OIDC, or SAML?

5 Lessons Learned Connecting Every IdP to OIDC
Integrating OIDC with various identity providers (IdPs) is notoriously complex and time-consuming for developers. We share five lessons learned while simplifying the process, including the challenges of standardizing tokens, handling directory sync at scale, and managing diverse IdP quirks.

Authn vs. Authz — Authentication vs. Authorization
When it comes to access control, authentication (AuthN) and authorization (AuthZ) fulfill different functions as methods to control access. In the modern world, those resources can be sensitive assets, applications, programs, devices, or more.

The Move to Passwordless Authentication
There's been a big move to passwordless authentication in recent years. After all, large scale data breaches are occurring on a weekly basis — and data breaches are just one way security breaches manifest themselves . Compromised credentials are, by and large, the hardest problem to identify and fix. Take a look at this chart from IBM's Cost of a Data Breach Report 2021 :
