OneLogin
Use OneLogin as Pomerium's OpenID Connect identity provider to authenticate users and apply their identity to route policy.
Overview
OneLogin, also marketed as OneLogin by One Identity, is an identity and access management service. Pomerium can use a OneLogin tenant as its OpenID Connect identity provider.
Using OneLogin as the identity provider gives protected applications one sign-in path. Each application does not need to implement the same external authentication flow. Pomerium can apply route policy from the authenticated identity and request context.
OneLogin sends authenticated identity data toward Pomerium. Pomerium uses that data with route policy. Pomerium then sends only approved application traffic toward the protected service.
How it works
Create a OneLogin OpenID Connect web application. Add the exact Pomerium callback, use the POST token endpoint method, enable refresh tokens, and assign the required users. Configure Pomerium with the onelogin provider key and tenant issuer.
Configure Pomerium with the exact issuer or provider URL, client ID, and client secret. Use the Pomerium callback URL as an exact redirect URI. Request only the scopes and claims that access policy needs.
Test discovery, signing-key rotation, the authorization code flow, logout, and required claim mappings before production use. Keep provider credentials outside source control.
Example
A team registers Pomerium as an OpenID Connect client in OneLogin. Users sign in through OneLogin. Pomerium validates the identity response and applies route policy before it sends an approved request to a private application.
Considerations
- The documented provider path does not supply custom OneLogin group claims.
- OneLogin directory sync is separate and needs Pomerium Enterprise and OneLogin API credentials.
- This integration uses OpenID Connect.
- OneLogin remains responsible for authentication, user lifecycle, and the identity data that it issues.
- A standards-based OpenID Connect pattern is not evidence of a vendor-specific connector or partnership.
