Skip to main content
See All Integrations

PingAM

Use PingAM, formerly ForgeRock Access Management, as the identity provider for Pomerium through OpenID Connect.

Standards-based OpenID Connect pattern

Category
Identity Providers

Overview

PingAM is the current name for ForgeRock Access Management. It is a self-managed access management platform and OpenID Connect provider. Pomerium can use PingAM through the standard OpenID Connect provider pattern.

Using PingAM as the identity provider gives protected applications one sign-in path. Each application does not need to implement the same external authentication flow. Pomerium can apply route policy from the authenticated identity and request context.

PingAM sends authenticated identity data toward Pomerium. Pomerium uses that data with route policy. Pomerium then sends only approved application traffic toward the protected service.

How it works

Create an OpenID Connect client in the correct PingAM realm. Configure the realm issuer, discovery service, client secret, redirect URI, scopes, and claim mappings. Use PingAM documentation for the installed release.

Configure Pomerium with the exact issuer or provider URL, client ID, and client secret. Use the Pomerium callback URL as an exact redirect URI. Request only the scopes and claims that access policy needs.

Test discovery, signing-key rotation, the authorization code flow, logout, and required claim mappings before production use. Keep provider credentials outside source control.

Example

A team registers Pomerium as an OpenID Connect client in PingAM. Users sign in through PingAM. Pomerium validates the identity response and applies route policy before it sends an approved request to a private application.

Considerations

  • ForgeRock Access Management became PingAM in 2024. Older deployments and search terms still use the ForgeRock AM name.
  • The Pomerium PingOne guide does not document PingAM and must not be presented as a named PingAM integration.
  • PingAM remains responsible for authentication, user lifecycle, and the identity data that it issues.
  • A standards-based OpenID Connect pattern is not evidence of a vendor-specific connector or partnership.

Sources and official resources

  • Use Keycloak as the identity provider for Pomerium through OpenID Connect.

  • Use IBM Verify as the identity provider for Pomerium through OpenID Connect.

  • Use PingOne for Workforce as Pomerium's OpenID Connect identity provider and apply Ping identity or group data to access policy.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo