Auth0
Use Auth0 as Pomerium's OpenID Connect identity provider, then apply authenticated identity and selected claims to private application policy.
Overview
Auth0 is an identity platform from Okta. Pomerium can use an Auth0 tenant as its OpenID Connect identity provider for protected routes.
Using Auth0 as the identity provider gives protected applications one sign-in path. Each application does not need to implement the same external authentication flow. Pomerium can apply route policy from the authenticated identity and request context.
Auth0 sends authenticated identity data toward Pomerium. Pomerium uses that data with route policy. Pomerium then sends only approved application traffic toward the protected service.
How it works
Create a confidential web application in Auth0. Add the Pomerium sign-in URL, exact OAuth callback URL, and signed-out URL. Configure Pomerium with the Auth0 domain, client ID, client secret, and the auth0 provider key.
Configure Pomerium with the exact issuer or provider URL, client ID, and client secret. Use the Pomerium callback URL as an exact redirect URI. Request only the scopes and claims that access policy needs.
Test discovery, signing-key rotation, the authorization code flow, logout, and required claim mappings before production use. Keep provider credentials outside source control.
Example
A team registers Pomerium as an OpenID Connect client in Auth0. Users sign in through Auth0. Pomerium validates the identity response and applies route policy before it sends an approved request to a private application.
Considerations
- The base OpenID Connect setup does not add Auth0 groups automatically. Use a reviewed Auth0 Action or Pomerium Enterprise directory sync when policy needs group data.
- Use an Auth0 application type that can keep a client secret. Do not treat a public native client as a confidential server application.
- Auth0 remains responsible for authentication, user lifecycle, and the identity data that it issues.
- A standards-based OpenID Connect pattern is not evidence of a vendor-specific connector or partnership.
