Skip to main content

pages

Changelog

New Pomerium capabilities, security updates, and release details.

Latest dispatches

Explore changelog

What's New?

change logs

Enterprise Console Updates

Several operability fixes and small features for the Pomerium Enterprise Console, covering startup configuration, a returning health view, and two bugs reported by customers.

Several operability fixes and small features for the Pomerium Enterprise Console, covering startup configuration, a returning health view, and two bugs reported by customers.

Highlights:

  • Configure the directory provider via CLI — the console now accepts -directory-provider and related startup flags, so directory sync can be fully configured without touching the web UI.
  • Automatic console route creation — a new -url startup flag lets the console create its own Pomerium route on first boot, removing a manual setup step for new installs.
  • Cluster health view is back — the cluster health panel, previously removed along with a discontinued data-grid dependency, has returned in a lighter-weight implementation.
  • Fixed SSH Host Key / User CA Key validation — the console previously rejected valid SSH Host Keys and User CA Keys with a proto-constraint validation error even when both were already uploaded; saving now works as expected.

See the Enterprise Console configuration reference for the full set of startup options.

change logs

MCP OAuth Compatibility & Hardening

The July 6 changelog Upstream OAuth for MCP routes covered Pomerium acting as an OAuth client toward upstream MCP servers. This update is about the other leg of the proxy — Pomerium acting as the authorization server for the downstream clients (Claude Code, ChatGPT, MCP Inspector, and others) that connect to it. There are also a few compatibility and credential-hygiene fixes along the way.

The July 6 changelog Upstream OAuth for MCP routes covered Pomerium acting as an OAuth client toward upstream MCP servers. This update is about the other leg of the proxy — Pomerium acting as the authorization server for the downstream clients (Claude Code, ChatGPT, MCP Inspector, and others) that connect to it. There are also a few compatibility and credential-hygiene fixes along the way.

Highlights:

  • OAuth Client ID Metadata Document (CIMD) support, inbound — Pomerium's MCP authorization server now accepts client identification from downstream clients via a Client ID Metadata Document, the lighter-weight registration path the MCP OAuth spec is converging on. (Not to be confused with the upstream DCR fallback shipped in July, which covers the opposite direction — Pomerium registering with upstream MCP servers.)
  • Configurable inbound Dynamic Client Registration in Pomerium Zero — inbound DCR (downstream clients registering with Pomerium itself) now ships behind a runtime flag, off by default in Pomerium core, and enabled by default for MCP routes in Zero, but there's a toggle in Zero cluster settings in the MCP section to turn it on/off per cluster.
  • Loopback redirect URIs are now RFC 8252-compliant — CLI clients like Claude Code that request a different loopback port than the one originally registered no longer fail MCP OAuth authorization; Pomerium ignores the port when matching localhost/loopback redirect URIs, per RFC 8252 §7.3.
  • Relaxed client_id metadata URL validation — client identifier URLs that include a query string, as ChatGPT's MCP connector sends, are no longer rejected with a 400.

See the MCP documentation for setup details.

change logs

Platform & Image Hardening

We released two smaller hardening changes that reduce attack surface and make policy configuration more durable, regardless of which Pomerium product you run.

We released two smaller hardening changes that reduce attack surface and make policy configuration more durable, regardless of which Pomerium product you run.

Highlights:

  • Distroless, SSL-free published images — Pomerium's published container images now build on the base-nossl-debian12 distroless variant instead of base-debian12, structurally removing the unused libssl3 library from every deployment rather than just leaving it unused.
  • GitHub directory provider can key users by node_id — as an alternative to the GitHub login (username), which can change or be reused, the GitHub directory provider can now use GitHub's stable node_id as the primary key for directory users — so policy written against a person doesn't break if they rename their GitHub account.

See the core deployment documentation for image and configuration details.

change logs

MCP: Upstream OAuth, Dynamic Client Registration & Route Discovery

Pomerium's MCP gateway now handles more of the OAuth complexity that real-world MCP servers require. This update adds upstream OAuth support with token caching and injection, Dynamic Client Registration as a fallback for clients that don't yet support Client ID Metadata Documents, auto-discovery for MCP connect flows, and the first MCP-facing configuration APIs. The result is less manual upstream OAuth configuration, more reliable session handling, and a cleaner experience in the routes portal.

Pomerium's MCP gateway now handles more of the OAuth complexity that real-world MCP servers require. This update adds upstream OAuth support with token caching and injection, Dynamic Client Registration as a fallback for clients that don't yet support Client ID Metadata Documents, auto-discovery for MCP connect flows, and the first MCP-facing configuration APIs. The result is less manual upstream OAuth configuration, more reliable session handling, and a cleaner experience in the routes portal.

Highlights:

  • Upstream OAuth for MCP routes – Pomerium can now discover upstream OAuth metadata, complete upstream authorization flows, cache client and token state, and inject upstream access tokens into MCP traffic when the target server requires them.
  • Dynamic Client Registration fallback – Pomerium now supports DCR for upstream OAuth flows, providing a practical path for tools like MCP Inspector while Client ID Metadata Document support matures across the ecosystem.
  • Issuer metadata in authorization flows – Pomerium now includes the recommended iss parameter in MCP authorization flows, aligning with the upcoming 2026-07-28 MCP spec. Pomerium's host is returned as the issuer, keeping authorization flows spec-compliant as the standard evolves.
  • Auto-discovery for MCP connect flows – MCP connect, disconnect, and authorize endpoints now support auto-discovery, reducing the static upstream OAuth configuration needed for compatible servers.
  • Safer metadata fetching – MCP metadata discovery uses SSRF-safe HTTP fetching and stricter protected-resource metadata handling, including path-prefix validation.
  • Better routes portal experience – MCP routes now show server indicators and connect/disconnect controls in the routes portal, making MCP-enabled routes easier to identify and manage.
  • More reliable upstream auth recovery – Pomerium refreshes expired upstream tokens before forcing reauthentication, recovers upstream auth after late config delivery, and surfaces clearer errors when upstream tokens can't be resolved.
  • Config API as MCP tools – A new pkg/mcp/configapi library exposes Pomerium's ConfigService as MCP tools, with generated schemas, sensitive-field handling, and update-safety checks — early building blocks for MCP-driven configuration workflows.

See the MCP support docs to learn how Pomerium secures MCP routes and manages upstream OAuth on behalf of clients.

change logs

SSH Session Recording (Enterprise)

Pairing with native SSH access, Pomerium Enterprise can now record and play back SSH sessions . Every keystroke and terminal output for a privileged SSH connection can be captured, stored, and reviewed later from the Console — giving security and compliance teams a full audit trail of what actually happened on a host, not just who connected.

Pairing with native SSH access, Pomerium Enterprise can now record and play back SSH sessions. Every keystroke and terminal output for a privileged SSH connection can be captured, stored, and reviewed later from the Console — giving security and compliance teams a full audit trail of what actually happened on a host, not just who connected.

Highlights:

  • Full session capture & playback – Record interactive SSH sessions and replay them later, terminal output and all, directly from the Enterprise Console.
  • Flexible storage – Point recordings at a local on-disk directory or any S3-compatible bucket, configured per cluster. In Pomerium Zero, recordings are stored in your organization's managed cloud bucket.
  • Guided storage setup in the Console – A new blob-URI builder in the Enterprise Console lets admins configure the recording storage location without hand-writing a connection string for each provider — it exposes the relevant Go CDK driver options, with a free-form field for advanced parameters.
  • Recordings UI – Browse, sort, and filter recordings in the Console by metadata such as the Pomerium route, the SSH user, the target host, duration, and size — then open one to play it back.
  • Open, portable format – Recordings are captured in an asciinema-style (.asciicast) format, so they're easy to store, parse, and replay.
  • Enterprise-gated – Native SSH access remains available in open source, while session recording is an Enterprise/Zero capability enabled for licensed customers.

See the Session Recording and Native SSH Access docs to get started.

change logs

Security & Maintenance: the v0.32 Patch Releases

Beyond the v0.32.0 feature release, the v0.32 line received a steady stream of patch releases focused on security and stability. Most notably, Envoy was updated several times to address CVEs, and a handful of session and configuration fixes landed. If you're on v0.32, staying current on patches is the easiest way to pick these up.

Beyond the v0.32.0 feature release, the v0.32 line received a steady stream of patch releases focused on security and stability. Most notably, Envoy was updated several times to address CVEs, and a handful of session and configuration fixes landed. If you're on v0.32, staying current on patches is the easiest way to pick these up.

Highlights:

  • Envoy security updates – v0.32.3 moved to Envoy v1.36.5 to address five CVEs (CVE-2026-26308 through CVE-2026-26311 and CVE-2026-26330), and v0.32.9 moved to Envoy v1.36.8 to address CVE-2026-47774.
  • Additional security fixes – v0.32.8 includes a fix for advisory GHSA-ggw3-5987-rx77, and v0.32.2 shipped the MCP message-smuggling fix (MCP Go SDK v1.3.1).
  • Session & header handling – v0.32.6 removed exp and nbf from core sessions, and v0.32.9 increased Envoy header size limits to better handle large headers.
  • Reliability fixes – v0.32.2 limited the sync cache batch size to 128MB (avoiding Pebble's 4GB batch limit), v0.32.4 made autocert detect use_proxy_protocol changes on the HTTP redirect server, and v0.32.3 added a Databroker VersionedConfig proto and syncer.
  • Toolchain & dependency upkeep – Go was bumped through 1.25.9 (v0.32.5) and 1.25.10 (v0.32.7), alongside routine dependency updates across the 0.32 branch.
change logs

Revoke and Block: Stronger Session Revocation (Enterprise)

Revoking a session in the Enterprise Console now does what admins expect. Previously, revoking a session could appear ineffective: the user's browser would silently re-authenticate through SSO (a 302 redirect) and get a fresh session almost immediately. The Console now offers a "Revoke and block future authentication" option that stops that loop.

Revoking a session in the Enterprise Console now does what admins expect. Previously, revoking a session could appear ineffective: the user's browser would silently re-authenticate through SSO (a 302 redirect) and get a fresh session almost immediately. The Console now offers a "Revoke and block future authentication" option that stops that loop.

Highlights:

  • Revoke and block – The session revocation dialog adds a secondary option to block the user from re-authenticating, not just to end the current session.
  • No more silent re-auth – Blocking prevents the SSO re-authentication loop, so a revoked user stays out instead of bouncing back in through the IdP.
  • Policy-backed enforcement – Blocked users are added to a deny/revocation list so the block is enforced on subsequent requests.

This was a direct response to enterprise customer feedback and closes a real gap in incident response, where "revoke" needs to mean the user is actually out.

See the Enterprise Console docs for session management.

change logs

Native SSH: Authorization Code Flow, Reverse Tunnels & Jump-Host Mode

Pomerium's Native SSH Access takes a major step forward in v0.32.0. SSH logins now use the standard OAuth Authorization Code flow instead of the Device Code flow, the login experience is smoother end to end, and a new set of capabilities — reverse tunneling, jump-host mode, an interactive routes portal, and per-key session revocation — make identity-aware SSH practical to run at scale.

Pomerium's Native SSH Access takes a major step forward in v0.32.0. SSH logins now use the standard OAuth Authorization Code flow instead of the Device Code flow, the login experience is smoother end to end, and a new set of capabilities — reverse tunneling, jump-host mode, an interactive routes portal, and per-key session revocation — make identity-aware SSH practical to run at scale.

Highlights:

  • Authorization Code OAuth flow – SSH authentication now uses the Authorization Code grant rather than Device Code. The result is a faster, more familiar browser login, with telemetry signals throughout the flow so you can observe and debug it. (Note: upstream IdPs must have the Authorization Code grant enabled; v0.31.x and earlier used Device Code.)
  • Reverse tunneling – Reach SSH servers that can't accept inbound connections. Upstream hosts dial out to Pomerium and register themselves, and Pomerium routes authorized sessions back over that tunnel — ideal for edge devices, NAT'd networks, and isolated environments. Enabled with the ssh_upstream_tunnel runtime flag.
  • Jump-host (ProxyJump) mode – Let clients connect straight through Pomerium to the upstream while Pomerium still enforces policy on the connection. Upstream servers don't need to trust Pomerium's User CA in this mode. Enabled with the ssh_allow_direct_tcpip runtime flag.
  • Interactive routes portal – SSH to Pomerium without naming a route and get an interactive picker of the destinations you're allowed to reach, then connect with one selection. Enabled with the ssh_routes_portal runtime flag.
  • Per-key session management & revocation – Each SSH key is bound to an OAuth user, and bindings can be listed and revoked from the Pomerium UI at any time. Cached credentials honor your session lifetime, and policy is still evaluated on every connection.
  • SSH upstream policy support – Apply Pomerium policy to upstream SSH tunnels, with fixes for several edge cases uncovered along the way.

See the Native SSH Access and Reverse Tunneling docs to get started.

change logs

Configurable DNS Resolvers

Pomerium v0.32.0 adds DNS configuration options, giving you direct control over how Pomerium resolves upstream hostnames. Instead of relying solely on the host system's resolver, you can now point Pomerium at specific DNS servers and tune how often it refreshes records — useful for split-horizon DNS, service discovery, and environments where upstream IPs change frequently.

Pomerium v0.32.0 adds DNS configuration options, giving you direct control over how Pomerium resolves upstream hostnames. Instead of relying solely on the host system's resolver, you can now point Pomerium at specific DNS servers and tune how often it refreshes records — useful for split-horizon DNS, service discovery, and environments where upstream IPs change frequently.

Highlights:

  • Custom resolvers – Specify the DNS servers Pomerium should use to resolve upstream routes, independent of the underlying host configuration.
  • Tunable refresh behavior – Configure DNS refresh rates so Pomerium picks up record changes on a schedule that matches your environment, rather than caching stale addresses.
  • Consistent upstream resolution – Predictable, centrally configured name resolution across all Pomerium components, which matters most in dynamic and clustered deployments.

See the Pomerium configuration reference for the new DNS options.

change logs

Faster Config Updates & a New Databroker Query Engine

Pomerium v0.32.0 includes a round of data-plane and storage improvements aimed at large deployments. Route changes now propagate incrementally instead of triggering full reloads, and the Databroker gains a real query and indexing layer — querying records by field, richer filter operators, ordering, and a faster in-memory store. The payoff is quicker configuration updates and better behavior as the number of routes, sessions, and records grows.

Pomerium v0.32.0 includes a round of data-plane and storage improvements aimed at large deployments. Route changes now propagate incrementally instead of triggering full reloads, and the Databroker gains a real query and indexing layer — querying records by field, richer filter operators, ordering, and a faster in-memory store. The payoff is quicker configuration updates and better behavior as the number of routes, sessions, and records grows.

Highlights:

  • Incremental config diffing for routes – When routes change, Pomerium now computes and applies just the difference rather than rebuilding the whole configuration, reducing churn and speeding up updates on large route sets.
  • Databroker indexing & query support – Records can be indexed and queried by field, with a new GetOptions API and support for additional filter operators and order by. This makes targeted lookups far more efficient than scanning.
  • Faster in-memory storage – The in-memory store now uses Pebble, improving performance and bringing it in line with the persistent backend, with a sensible default path for the file backend.
  • Sturdier sync – Sync now supports a "latest stream" option, safely aborts calls with invalid record versions, and no longer panics on unknown sync message types — a more resilient databroker overall.

See the Pomerium architecture documentation for background on the Databroker.

change logs

Hosted Identity Provider

Pomerium v0.32.0 introduces a new hosted identity provider type. This lets Pomerium use a Pomerium-managed identity provider for authentication, lowering the setup barrier for teams that don't want to stand up and maintain their own OIDC provider before getting started.

Pomerium v0.32.0 introduces a new hosted identity provider type. This lets Pomerium use a Pomerium-managed identity provider for authentication, lowering the setup barrier for teams that don't want to stand up and maintain their own OIDC provider before getting started.

Highlights:

  • New hosted provider type – Select a Pomerium-hosted IdP as your identity source, an alternative to wiring up an external OIDC provider yourself.
  • Refresh handling built in – The hosted provider authenticates refresh requests and correctly handles hashing of the derived IdP configuration, so sessions refresh cleanly.
  • Faster path to first login – A simpler on-ramp for evaluations and smaller deployments, while keeping the door open to bring your own IdP later.

See the Pomerium authentication documentation for identity provider options.

change logs

MCP: Refresh Tokens, Dynamic Client Registration & Friendlier Errors

Building on Pomerium's experimental Model Context Protocol (MCP) support , the v0.32 line hardens the MCP gateway for real-world AI workflows. Sessions now survive longer thanks to OAuth refresh tokens, clients can register themselves dynamically, error pages are clearer, and a security fix in the underlying SDK closes a message-smuggling vulnerability.

Building on Pomerium's experimental Model Context Protocol (MCP) support, the v0.32 line hardens the MCP gateway for real-world AI workflows. Sessions now survive longer thanks to OAuth refresh tokens, clients can register themselves dynamically, error pages are clearer, and a security fix in the underlying SDK closes a message-smuggling vulnerability.

Highlights:

  • OAuth refresh token support – Pomerium now issues and honors refresh tokens for MCP sessions, so long-running agents and clients can stay connected without forcing repeated interactive logins.
  • Dynamic client registration – Support for client ID metadata documents lets MCP clients register with Pomerium automatically, removing manual setup steps when onboarding new clients.
  • Customizable, friendlier error pages – The MCP 401 page can be customized, and unauthorized client domains now get a clear, user-friendly error instead of a cryptic failure. Allowed client domains are also optional, simplifying configuration.
  • Security hardening – The MCP Go SDK was updated to v1.3.1 to fix a message-smuggling vulnerability caused by case-insensitive JSON unmarshalling, and Pomerium now sets a proper WWW-Authenticate header on unauthorized responses.

See the MCP documentation for configuration details.

change logs

Observability & Debugging Upgrades

Pomerium v0.32.0 ships a set of improvements for operators who need to see what's happening inside a running deployment. Custom stat names make metrics and logs easier to correlate, health updates can be streamed over gRPC, and new built-in debugging tools — a control-plane debug server, a Databroker browser, and gRPC channelz — give you direct visibility into Pomerium's internals.

Pomerium v0.32.0 ships a set of improvements for operators who need to see what's happening inside a running deployment. Custom stat names make metrics and logs easier to correlate, health updates can be streamed over gRPC, and new built-in debugging tools — a control-plane debug server, a Databroker browser, and gRPC channelz — give you direct visibility into Pomerium's internals.

Highlights:

  • Custom stat names in logs and metrics – Set an alternate stat name and have it surface in logs as cluster-stat-name, making it far easier to map metrics and log lines back to specific routes and clusters.
  • Streaming health updates via gRPC – Health status is now available as a gRPC stream, so dashboards and the Enterprise Console can reflect component health in real time.
  • Control-plane debug server – A built-in debug endpoint exposes internal state for troubleshooting, including gRPC channelz support for inspecting live gRPC channels and connections.
  • Databroker browser – A debug view for browsing Databroker records directly, handy when diagnosing session, policy, or sync issues.
  • More forgiving logging config – Pomerium no longer exits on invalid logfields, and Prometheus metrics were cleaned up (no more redundant unit/scope tags), with stats prefixes added to listeners.

See the Pomerium reference docs for metrics and logging configuration.

Announcing Pomerium v0.21
change logs

Depends_on changelog

Pomerium now supports Additional Login Redirect Hosts to solve cross-origin authentication challenges in modern web applications. Cross-origin fetch requests often fail if the browser hasn't set a session cookie for the target domain—especially during the initial login flow. This new feature ensures seamless authentication across multiple domains.

Pomerium now supports Additional Login Redirect Hosts to solve cross-origin authentication challenges in modern web applications. Cross-origin fetch requests often fail if the browser hasn't set a session cookie for the target domain—especially during the initial login flow. This new feature ensures seamless authentication across multiple domains.

Highlights:

Pre-established sessions – By specifying other routes a route depends on, Pomerium performs additional logins during authentication to set session cookies across up to five domains. No more broken fetch calls or manual visits to subdomain APIs.

Invisible to users – The dependency chain executes during the OAuth flow with seamless redirects. Users experience a single login that authenticates them across all necessary domains automatically.

No CORS workarounds – Eliminates the need for proxying API calls through the primary domain or requiring users to manually hit multiple subdomains. Cross-origin requests just work once the session is established.

Route-level control – Define authentication dependencies at the route level using the new pomerium_additional_hosts query parameter. Perfect for frontend/backend splits and multi-subdomain architectures.

See the docs for more information on configuring cross-origin authentication dependencies!

Experimental MCP Support
change logs

Experimental MCP Support

Pomerium now offers experimental support for securing access to Model Context Protocol (MCP) servers , bringing zero trust principles to agentic AI workflows. MCP turns language models into autonomous agents that can query databases, trigger workflows, and update infrastructure. But when AI agents have this power, traditional security models break down. Most organizations are deploying MCP servers directly exposed to agents, creating significant security risks.

Pomerium now offers experimental support for securing access to Model Context Protocol (MCP) servers, bringing zero trust principles to agentic AI workflows. MCP turns language models into autonomous agents that can query databases, trigger workflows, and update infrastructure. But when AI agents have this power, traditional security models break down. Most organizations are deploying MCP servers directly exposed to agents, creating significant security risks.

Highlights:

Unified access control – Apply the same identity-based policies to AI agents that you use for human users and services. No more separate security models or access sprawl across your infrastructure.

Granular enforcement – Control access at every level: which MCP servers an agent can reach, down to individual tools within each server. Policies can restrict entire servers, specific functions, or individual tools based on context and identity.

Comprehensive audit trail – Every MCP method call, tool parameter, and authorization decision is logged with full context. Critical for compliance, incident response, and understanding how AI agents interact with your systems.

Zero trust for AI workflows – Unlike static OAuth scopes, Pomerium's policies adapt to changing conditions with rate limiting, time-based restrictions, and behavioral monitoring to prevent runaway AI processes.

OAuth2 gateway – Pomerium acts as a secure gateway between MCP clients and servers, handling OAuth 2.1 flows with upstream services so you don't need to implement OAuth in your MCP server. Features proper token separation and PKCE support with policies that adapt to changing conditions.

Changelog Experimental MCP Support

See our MCP documentation and demo application to get started with secure AI agent access.

Note: This is an experimental feature and may change in future releases. We welcome feedback as we refine MCP support for production environments.

Introducing Pomerium Zero
change logs

Native SSH Access

Teams can now SSH securely without tunneling or workflow changes, as Pomerium introduces native SSH oauth-integrated authentication that works with standard SSH clients and leverages identity-aware, policy-driven authorization.

Teams can now SSH securely without tunneling or workflow changes, as Pomerium introduces native SSH oauth-integrated authentication that works with standard SSH clients and leverages identity-aware, policy-driven authorization.

With this release, Pomerium acts as an SSH certificate authority (CA), signing temporary certificates based on successful OAuth authentication. Instead of managing per-user static keys on every server, access is tied to your identity provider (IdP) and enforced in real time by policy.

This makes SSH access:

  • Zero Trust-aligned
  • OAuth-backed and centrally authorized
  • Ephemeral and auditable
  • Easy to manage at scale

How it works

Users connect via:
SSH client → Envoy → Pomerium

  1. The user initiates an SSH connection.
  2. Pomerium prompts an OAuth login (via keyboard-interactive + device code flow).
  3. After successful authentication, Pomerium evaluates context-aware policy for authorization, then generates a short-lived SSH certificate.
  4. The certificate is signed using a configured User CA private key.
  5. Pomerium creates an SSH connection to the desired host using the short-lived SSH certificate.
  6. The SSH server grants access if it trusts the User CA and the certificate fields match policy.
  7. If a user logs in again with the same public key, their credentials will be cached for the duration of the pomerium session or until revoked

No changes are required to SSH clients or existing key setups. Servers must be configured to trust Pomerium's User CA via sshd_config (TrustedUserCAKeys).

The generated certificates embed fields like:

  • Valid principals (usernames)
  • Expiration time
  • Session restrictions (e.g., deny port forwarding, shell access)

Why it matters

Static SSH keys are risky and hard to manage at scale. With native SSH support, Pomerium enables:

  • Fine-grained access based on identity and policy
  • Fast, easy revocation (just disable the user or change a policy)
  • Short-lived certs that reduce exposure without burdening users
  • No need for VPNs, bastion hosts, or custom ssh clients

Perfect for on-call access, ephemeral production access, or Zero Trust SSH in regulated environments.

Getting started

  1. Generate a User CA key pair
  2. Update your pomerium.config.yaml to enable SSH support
  3. Define your SSH routes
  4. Distribute the User CA public key to trusted servers (sshd_config → TrustedUserCAKeys)
  5. Restart SSHD

📖 See our docs for the full setup guide.

What’s next

We're just getting started with SSH:

  • Command restrictions and session metadata (coming soon)
  • Audit integrations for session logging

Secure SSH, simplified and policy-driven.
This is SSH the Zero Trust way — powered by Pomerium.

Experimental MCP Support
change logs

Identity-Aware UDP Tunneling

Pomerium can now protect UDP-based services with the same identity-aware access controls you use for web apps. In v0.29.0, you’re able to tunnel UDP traffic over HTTP, enforcing who can access your UDP services. This means you can secure things like DNS servers, game servers, and other UDP apps without a VPN.

Pomerium can now protect UDP-based services with the same identity-aware access controls you use for web apps. In v0.29.0, you’re able to tunnel UDP traffic over HTTP, enforcing who can access your UDP services. This means you can secure things like DNS servers, game servers, and other UDP apps without a VPN.

Highlights:

  • UDP over HTTPS – Pomerium uses HTTP/3 datagram support (MASQUE’s CONNECT-UDP) under the hood to forward UDP packets securely. No modifications to your UDP applications are required.
  • Consistent policy enforcement – Apply Pomerium’s access policies to UDP routes just like HTTP routes. If a user isn’t authorized, their UDP traffic won’t go through.
  • Easy client access – Use the pomerium-cli or Pomerium Desktop to connect. For example, pomerium-cli udp myservice.corp.example:1234 spins up a local proxy for your UDP app.
  • Works with any UDP service – Protect game servers, database UDP ports, time servers, or any custom UDP protocol with identity-based authentication and logging, bringing zero trust to new protocols.

V0290 Identity Aware Udp Tunneling

See the docs, and factorio and dns examples for more information!

Agentic Access Management for Model Context Protocol (MCP) Workflows
change logs

HTTP/3 Support

v0.29.0 adds support for HTTP/3, so connections to Pomerium can now use the latest web transport protocol. HTTP/3 (built on QUIC) brings speed and reliability improvements that your users will benefit from automatically:

v0.29.0 adds support for HTTP/3, so connections to Pomerium can now use the latest web transport protocol. HTTP/3 (built on QUIC) brings speed and reliability improvements that your users will benefit from automatically:

  • Faster handshakes – QUIC’s efficient connection setup means quicker initial load times, especially on high-latency networks.
  • Improved performance – Eliminates head-of-line blocking issues present in HTTP/2. Multiple requests can fly in parallel without one slow request holding up others.
  • Resilience – Connections are more robust to packet loss, and session resumption is faster, making Pomerium feel snappier on spotty networks (e.g. mobile).
  • Transparent enablement – Pomerium will negotiate HTTP/3 with clients that support it (while seamlessly falling back to HTTP/2 for others). No special configuration needed — just upgrade and enjoy the throughput boost.

V0290 Http 3 Support

V0290 Http 3 Support2

7 Things to Know About Kubernetes Health Checks
change logs

OpenTelemetry Tracing

Pomerium’s tracing is now powered by OpenTelemetry, making it easier to plug into your existing observability stack. With industry-standard tracing, you get deeper insight into every request that flows through Pomerium. Key improvements include:

Pomerium’s tracing is now powered by OpenTelemetry, making it easier to plug into your existing observability stack. With industry-standard tracing, you get deeper insight into every request that flows through Pomerium. Key improvements include:

  • Seamless integration – Export Pomerium trace data to your favorite monitoring tools (Jaeger, Datadog, Honeycomb, etc.) without custom adapters.
  • End-to-end visibility – Each Pomerium service generates standardized spans, so you can follow a user’s journey across authenticate, proxy, envoy, and authorize components in one trace.
  • Easier debugging – Quickly pinpoint performance bottlenecks or errors in request handling with the rich context provided by OpenTelemetry spans.

V0290 Open Telemetry Tracing

All of this works out of the box in v0.29.0—just configure your tracing backend of choice and you’re good to go.

Announcing Pomerium v0.16
change logs

Terraform Provider

Pomerium Enterprise now supports comprehensive configuration through the official Terraform provider . Users can fully define and manage routes, policies, namespaces, service accounts, and general settings entirely within their Terraform plans.

Pomerium Enterprise now supports comprehensive configuration through the official Terraform provider. Users can fully define and manage routes, policies, namespaces, service accounts, and general settings entirely within their Terraform plans.

Users can now fully bootstrap Pomerium Proxy using Terraform, eliminating the need for manual or interactive configuration via the Enterprise UI. This enhancement streamlines infrastructure-as-code practices, facilitating automated deployments and management workflows.

  • Simplified Automation: Full Terraform support enables automation and integration with existing CI/CD pipelines.
  • Reproducible Configuration: Enhances consistency and reproducibility of deployments.
  • Declarative Configuration: Enables efficient, declarative management of complex access policies and configurations.
  • External References: Allows dynamic reference to external entities such as IdP users and groups that you manage in the Terraform.

For more details, check out the official Configure with Terraform documentation.

Announcing Pomerium v0.25
change logs

Selective JWT Group Claims

Tired of bloated JWTs or exposing too much group information? Pomerium v0.29.0 gives you control over which user groups get embedded in the JWT token that it mints for upstream services. By including only the groups you care about, you can slim down tokens and limit what data gets shared. Highlights:

Tired of bloated JWTs or exposing too much group information? Pomerium v0.29.0 gives you control over which user groups get embedded in the JWT token that it mints for upstream services. By including only the groups you care about, you can slim down tokens and limit what data gets shared. Highlights:

  • Trim down token size – Some users belong to hundreds of groups, which can make the JWT payload large which can break application and server header limits. Now you can include just a subset of groups (for instance, only groups used in policy checks or with a certain prefix), avoiding hitting header size limits and improving performance.
  • Per-route or global settings – Set a global default filter for JWT group claims, and override on specific routes as needed. This flexibility lets you expose broad group info to services that need it, while limiting it for others.
  • Privacy by design – Only divulge the group context that’s necessary. Internal apps don’t get a long list of every group a user is in—just the ones you’ve deemed relevant.
  • Simpler downstream logic – Upstream applications no longer have to handle extraneous group data. They can trust that the groups claim in the JWT is already curated to what they expect, making authorization checks more straightforward.

V0290 Selective Group Claims

In short, this feature helps you send cleaner, leaner JWTs to your services without sacrificing the rich identity context Pomerium provides. It’s especially handy for organizations with complex directory structures, ensuring that Pomerium’s tokens stay efficient and purposeful.

Announcing Pomerium v0.22
change logs

Direct Identity Provider Token Authentication

Building on Pomerium’s authentication capabilities, v0.29.0 introduces the ability to forward downstream Identity Provider (Entra, OIDC, etc) tokens directly to upstream services. In short, you can now optionally have Pomerium authenticate your APIs and applications using the original IdP-issued token (such as an OAuth access token or OpenID Connect ID token) instead of Pomerium’s JWT. Why is this useful?

Building on Pomerium’s authentication capabilities, v0.29.0 introduces the ability to forward downstream Identity Provider (Entra, OIDC, etc) tokens directly to upstream services. In short, you can now optionally have Pomerium authenticate your APIs and applications using the original IdP-issued token (such as an OAuth access token or OpenID Connect ID token) instead of Pomerium’s JWT. Why is this useful?

  • Seamless backend integration – If your upstream service or API expects an IdP’s bearer token, Pomerium can provide it. Your apps can verify the token as if the user logged in directly, enabling out-of-the-box compatibility with systems that already know how to handle your IdP tokens.
  • Configurable per route – You can toggle this behavior on routes that need it. For example, for an API service that performs its own token introspection with the IdP, simply enable “IdP token pass-through” and Pomerium will pass along the user’s access token in the Authorization header.
  • No custom glue code – This eliminates the need for awkward workarounds or custom middleware. Pomerium handles the secure exchange with the IdP, then transparently forwards the token upstream.
  • Keeps zero-trust principles – Pomerium still gatekeeps the initial authentication and authorization. The IdP token is only forwarded after Pomerium has verified and allowed the request. You get the convenience of direct IdP token use without exposing unsecured endpoints.

V0 29 0 Direct Identity Provider Token Authentication

This feature is perfect for service-to-service scenarios and integrations where Pomerium acts as an authentication broker, simplifying access to APIs.

Announcing Pomerium v0.20
change logs

Routes Portal

Navigating to your internal applications just got easier. Routes Portal is a new user interface that lists all the routes (apps and services) you have access to, all in one place. After logging in through Pomerium, users can be presented with a portal page showing available resources, making access more intuitive.

V 029 Routes Portal

Navigating to your internal applications just got easier. Routes Portal is a new user interface that lists all the routes (apps and services) you have access to, all in one place. After logging in through Pomerium, users can be presented with a portal page showing available resources, making access more intuitive.

Here’s what it offers:

  • Single landing page – Upon sign-in, users see a dashboard of all their authorized routes. No more remembering a bunch of URLs; just click the service you need from the list.
  • Quick access – Each route is one click away. The portal displays application names (and can show icons or descriptions, if configured) for easy identification.
  • Dynamic updates – The list reflects the user’s current access rights. As soon as an admin adds or removes access, the portal updates to show the correct set of resources.
  • Better user experience – Especially in organizations with dozens of internal apps be they HTTP, TCP or UDP, the Routes Portal serves as a friendly “app launcher” homepage for your infrastructure. Users can navigate confidently, which means fewer support questions about “Where do I go to access X?”.

No setup required — enable the Routes Portal feature, and Pomerium will automatically present it to your users after authentication.

Announcing Pomerium v0.29.0
change logs

Pomerium v0.29.0

We're thrilled to launch Pomerium v0.29.0 , packed with features to improve secure access, user experience, and operational insights for your infrastructure.

We're thrilled to launch Pomerium v0.29.0, packed with features to improve secure access, user experience, and operational insights for your infrastructure.

This release introduces:

  • Routes Portal: An intuitive "app dashboard" for end-users to easily discover and access their authorized services.
  • Identity-Aware UDP Tunneling: Extend Pomerium's Zero Trust enforcement to critical UDP-based protocols like DNS, syslog, and internal tools.
  • OpenTelemetry Tracing: Standardize observability with OTEL for end-to-end visibility across Pomerium services (Note: This is a breaking change from previous tracing methods).
  • HTTP/3 Support: Leverage the performance benefits of QUIC for faster and more resilient connections.
  • Direct IdP Token Authentication: Streamline programmatic access using Azure AD tokens directly.
  • Terraform Provider (Enterprise): Fully manage Pomerium configuration as code.

These updates, along with JWT group filtering, hot reloading, and performance optimizations, make managing secure access easier and more comprehensive.

Important: Review the breaking changes, especially regarding tracing configuration, before upgrading.

Dive into the details in our full announcement.

Announcing Pomerium v0.28
change logs

Pomerium v0.28.0

Pomerium v0.28 is here, packed with major updates enhancing our Kubernetes integration, deployment flexibility, and security configurations across all editions. This release also includes significant performance optimizations and several critical bug fixes.

Pomerium v0.28 is here, packed with major updates enhancing our Kubernetes integration, deployment flexibility, and security configurations across all editions. This release also includes significant performance optimizations and several critical bug fixes.

Downloads are available on GitHub Releases, CloudSmith, and Docker Hub for all supported platforms.

Major updates include:

  • Support for Structured Authentication Configuration ( Kubernetes 1.30+) enabling secure kubectl and Kubernetes API access. Beyond basic Kubernetes RBAC, Pomerium brings the same centralized, context-aware authorization capabilities you love so you can manage your Kubernetes control plane like it was any other workload. For more details, visit our Kubernetes Access documentation.
  • Our Ingress Controller now includes experimental support for the Kubernetes Gateway API, designed to streamline ingress configuration and enhance role-based resource management in complex Kubernetes environments. Supports Gateway API v1.2 "Core" features, with both "Gateway" and "HTTP" conformance profiles. We’re actively expanding Gateway API support and welcome your feedback to guide future improvements.
  • Simplified Kubernetes Deployments with Helm and Kustomize. Our new Helm chart, alongside existing Kustomize manifests, enables quick and seamless integration into Kubernetes environments. Ready to get started? Check out our setup guide in our installs repo.
  • Performance enhancements including faster header evaluation (2x faster than before) and more efficient route matching (unlocking tens of thousands of routes within a given cluster).

Please view the Core and Enterprise changelogs for more information.

Big thank you to all our users, and to everyone who contributed to this release!

Best,

The Pomerium Team

Pomerium v0.27.2 and v0.27.3
change logs

Pomerium v0.27.2 and v0.27.3

We're announcing a double patch upgrade this time! Pomerium v0.27.2 and v0.27.3 are here with various improvements, a new integration, and a Pomerium Zero import tool.

We're announcing a double patch upgrade this time! Pomerium v0.27.2 and v0.27.3 are here with various improvements, a new integration, and a Pomerium Zero import tool.

  • OSS to Zero: The Core to Zero import tool is for those who want to bring an existing Pomerium configuration into Pomerium Zero, our hosted control plane.
  • Need more routes? Upgrade with ease: For users interested in bringing Zero into their professional organizations, we now provide an easier process to upgrade to Professional!
  • Squashed bugs and improvements: We fixed some bugs regarding the databroker and fixed a few behavioral issues. Several unused configuration options were also removed.

Pomerium v0.27.3 is an Enterprise-focused patch upgrade:

  • Integrating devices: Our first mobile device management solution integration is FleetDM to support policy enforcement based on device state. Check out our FleetDM integration here.
  • New: There is a new "Kubernetes Service Account Token File" route setting.
  • Various improvements and fixes: We've improved handling of records and a few UI/UX fixes.

Please view the Core and Enterprise changelogs for more information.

Big thank you to all our users, and to everyone who contributed to this release!

Best,

The Pomerium Team

Pomerium v0.27.1
change logs

Pomerium v0.27.1

Pomerium v0.27.1 is here to address a security vulnerability and several bug fixes.

Pomerium v0.27.1 is here to address a security vulnerability and several bug fixes.

We fixed a security vulnerability affecting the internal API. This affected only Pomerium Enterprise and Pomerium Zero deployments utilizing service accounts.

Please view the Core and Enterprise changelogs for more information and make sure to address any necessary changes to your configuration before upgrading.

Big thank you to all our users, and to everyone who contributed to this release!

Pomerium v0.27
change logs

Pomerium v0.27

Pomerium v0.27 is here! This update brings new features to Enterprise and Core, in addition to officially announcing Pomerium Zero with its own updates. We've also made a slew of performance and stability improvements.

Pomerium v0.27 is here! This update brings new features to Enterprise and Core, in addition to officially announcing Pomerium Zero with its own updates. We've also made a slew of performance and stability improvements.

Please view the Core and Enterprise changelogs for more information and make sure to address any necessary changes to your configuration before upgrading.

For the full announcement post, read here!

Big thank you to all our users, and to everyone who contributed to this release!

Best,

Pomerium Team

Pomerium v0.26
change logs

Pomerium v0.26

Pomerium v0.26 is here with performance improvements and bug fixes!

Pomerium v0.26 is here with performance improvements and bug fixes!

This update focuses on bug fixes, performance, and stability improvements as well as policy builder enhancements for working with client certificates in Pomerium Enterprise.

Please view the Core and Enterprise changelogs for more information and make sure to address any necessary changes to your configuration before upgrading.

Big thank you to all our users, and to everyone who contributed to this release!

Best,

Pomerium Team

Pomerium v0.25
change logs

Pomerium v0.25

Pomerium v0.25 is here! This is a performance and maintenance-focused upgrade to everyone’s favorite identity and context-aware proxy for clientless access.

Pomerium v0.25 is here! This is a performance and maintenance-focused upgrade to everyone’s favorite identity and context-aware proxy for clientless access.

Please view the Core and Console release notes for more information and make sure to address any necessary changes to your configuration before upgrading. The full list of changes, improvements, and squashed bugs can be found in our announcement post here!

Big thank you to all our users, and to everyone who contributed to this release!

Best,

Pomerium Team

Pomerium v0.24
change logs

Pomerium v0.24

Pomerium v0.24 is here! This performance-focused upgrade helps Pomerium run faster and returns it to its previous baseline RAM-usage in addition to adding certificate matching to the Enterprise Console PPL builder.

Pomerium v0.24 is here! This performance-focused upgrade helps Pomerium run faster and returns it to its previous baseline RAM-usage in addition to adding certificate matching to the Enterprise Console PPL builder.

We also encourage reading the announcement post for more information.

Big thank you to all our users, and to everyone who contributed to this release!

Best,

Pomerium Team

Pomerium v0.23
change logs

Pomerium v0.23

Pomerium v0.23 is here! This version brings improved Observability capabilities and mTLS settings, followed by major performance improvements and bug fixes.

Pomerium v0.23 is here! This version brings improved Observability capabilities and mTLS settings, followed by major performance improvements and bug fixes.

Please read the announcement post for more information.

Big thank you to all our users, and to everyone who contributed to this release!

Best,

Pomerium Team

Pomerium v0.22
change logs

Pomerium v0.22

We have just released Pomerium v0.22. It’s got new features, one for getting Pomerium up and running faster and the other for simplifying policy writing. Then, we have support for a new identity provider (the fruit), followed by performance improvements and bug fixes.

We have just released Pomerium v0.22. It’s got new features, one for getting Pomerium up and running faster and the other for simplifying policy writing. Then, we have support for a new identity provider (the fruit), followed by performance improvements and bug fixes.

A complete list can be found in the announcement post.

Big thank you to all our users, and to everyone who contributed to this release!

Pomerium v0.21
change logs

Pomerium v0.21

We have just released Pomerium v0.21 which includes a bunch of new features, quality of life changes, and bug fixes including:

We have just released Pomerium v0.21 which includes a bunch of new features, quality of life changes, and bug fixes including:

  • Authenticate Service is Now Stateless

  • TCP Gateway Support

  • Automatic TLS for Internal Services

  • Forward Authentication is Deprecated

This release also includes other new features, general improvements, and bug fixes. A complete list can be found in the announcement post.

Big thank you to all our users, and to everyone who contributed to this release!

Pomerium v0.20
change logs

Pomerium v0.20

We have just released Pomerium v0.20 which includes a bunch of new features, including:

We have just released Pomerium v0.20 which includes a bunch of new features, including:

This release also includes other new features, general improvements, and bug fixes. A complete list can be found in the announcement post.

Big thank you to all our users, and to everyone who contributed to this release!

Get release notes, technical guidance, and new research from the Pomerium team.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo