Skip to main content
See All Integrations

Dex

Use Dex as the identity provider for Pomerium through OpenID Connect.

Standards-based OpenID Connect pattern

Category
Identity Providers

Overview

Dex is an open-source federated OpenID Connect service. It usually authenticates users through another connector, such as LDAP, SAML, GitHub, or a second OpenID Connect provider, and then issues an OpenID Connect response to Pomerium.

Dex lets Pomerium use one OpenID Connect client while Dex bridges the selected upstream identity system and protocol.

The selected upstream identity system authenticates the user and owns the user lifecycle. Dex brokers that authentication and issues the OpenID Connect response. Pomerium validates the response and applies route policy.

How it works

Create a Dex static client for Pomerium or register the client through the deployment management process. Configure the Dex issuer, client secret, exact callback URL, and the connector claims that Pomerium needs.

Configure Pomerium with the exact issuer or provider URL, client ID, and client secret. Use the Pomerium callback URL as an exact redirect URI. Request only the scopes and claims that access policy needs.

Test discovery, signing-key rotation, the authorization code flow, logout, and required claim mappings before production use. Keep provider credentials outside source control.

Example

A team registers Pomerium as a Dex static client and configures an LDAP connector. Dex sends the user through the connector, maps the result, and issues an OpenID Connect response to Pomerium.

Considerations

  • Dex normally brokers identity from an upstream connector. It is not a general user store.
  • Refresh tokens, groups, and preferred_username claims vary by the selected Dex connector.
  • The selected upstream identity system remains responsible for authentication and user lifecycle.
  • A standards-based OpenID Connect pattern is not evidence of a vendor-specific connector or partnership.

Sources and official resources

  • Use Keycloak as the identity provider for Pomerium through OpenID Connect.

  • Use authentik as the identity provider for Pomerium through OpenID Connect.

  • Use Ory Hydra as the identity provider for Pomerium through OpenID Connect.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo