Skip to main content
See All Integrations

Okta

Use Okta as Pomerium's OpenID Connect identity provider, apply user and group claims to route policy, and add Enterprise directory sync when needed.

First-party Pomerium integration guide

Category
Identity Providers

Overview

Okta Workforce Identity is an identity and access management service. Pomerium can use Okta as an OpenID Connect identity provider and can evaluate selected user and group claims in route policy.

Using Okta as the identity provider gives protected applications one sign-in path. Each application does not need to implement the same external authentication flow. Pomerium can apply route policy from the authenticated identity and request context.

Okta sends authenticated identity data toward Pomerium. Pomerium uses that data with route policy. Pomerium then sends only approved application traffic toward the protected service.

How it works

Create an Okta OpenID Connect web application with the exact Pomerium callback, refresh token grant, and correct user assignment. Configure Pomerium with the Okta provider URL and client credentials.

Configure Pomerium with the exact issuer or provider URL, client ID, and client secret. Use the Pomerium callback URL as an exact redirect URI. Request only the scopes and claims that access policy needs.

Test discovery, signing-key rotation, the authorization code flow, logout, and required claim mappings before production use. Keep provider credentials outside source control.

Example

A team registers Pomerium as an OpenID Connect client in Okta. Users sign in through Okta. Pomerium validates the identity response and applies route policy before it sends an approved request to a private application.

Considerations

  • The groups claim must be configured and scoped explicitly.
  • Okta directory sync is separate and needs Pomerium Enterprise and an Okta API token.
  • Okta remains responsible for authentication, user lifecycle, and the identity data that it issues.
  • A standards-based OpenID Connect pattern is not evidence of a vendor-specific connector or partnership.

Sources and official resources

  • Connect a compatible OpenID Connect provider to Pomerium with discovery, authorization-code sign-in, identity claims, and route policy.

  • Use OneLogin as Pomerium's OpenID Connect identity provider to authenticate users and apply their identity to route policy.

  • Use Microsoft Entra ID as the identity provider for Pomerium through OpenID Connect.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo