OpenID Connect
Connect a compatible OpenID Connect provider to Pomerium with discovery, authorization-code sign-in, identity claims, and route policy.
Overview
OpenID Connect 1.0 is an identity layer on OAuth 2.0. Pomerium can connect to a compatible provider through discovery and the authorization code flow.
OpenID Connect gives Pomerium a standard sign-in path across compatible providers. The team must still verify provider-specific claims, refresh-token behavior, and logout behavior.
The OpenID Provider authenticates the user and issues identity claims. Pomerium acts as the relying party, validates the response, creates its session, and applies route policy.
How it works
Register Pomerium as a confidential web client. Add the exact callback. Configure the provider issuer, client ID, client secret, generic oidc provider key, and required scopes. Use OpenID Connect discovery when the provider supports it.
Configure Pomerium with the exact issuer or provider URL, client ID, and client secret. Use the Pomerium callback URL as an exact redirect URI. Request only the scopes and claims that access policy needs.
Test discovery, signing-key rotation, the authorization code flow, logout, and required claim mappings before production use. Keep provider credentials outside source control.
Example
A team registers Pomerium as a confidential client with a compatible OpenID Provider. The provider authenticates the user and returns an OpenID Connect response. Pomerium validates the response and applies route policy before it forwards approved traffic.
Considerations
- OAuth 2.0 by itself is not an identity protocol. The provider must supply the required OpenID Connect behavior.
- Claims, group data, logout, and token behavior vary by provider.
- Vendor directory sync is separate from the generic OpenID Connect sign-in flow.
- The selected OpenID Provider remains responsible for authentication, user lifecycle, and the identity data that it issues.
- A standards-based OpenID Connect pattern is not evidence of a vendor-specific connector or partnership.
