
Snipe-IT
Use selected Snipe-IT asset data in Pomerium policy through a custom external data source.
Overview
Snipe-IT is an open-source IT asset management system. Its REST API exposes selected asset and assignment records. A customer-owned adapter can map a narrow inventory record set to Pomerium Enterprise external data.
Selected Snipe-IT data can add organization, inventory, or security context to an access decision. A small, reviewed record set is easier to understand and protect than a broad export of the source system.
Pomerium can evaluate selected Snipe-IT records after a customer-owned adapter maps them to supported request or user keys. Pomerium does not call the vendor API directly and does not manage the source system.
How it works
Create a Snipe-IT API token for a least-privilege account. Read the selected asset, user, and assignment records through the REST API. Inspect the response body as well as the HTTP status.
Map only the fields that policy needs. Each imported record must use a Pomerium-supported foreign key: user.id, user.email, request.ip, or request.client_certificate.fingerprint.
Publish the records through a protected JSON, CSV, tar, or ZIP source. Configure Pomerium Enterprise to poll that source. Evaluate the imported fields with a Pomerium Policy Language record matcher.
Example
An adapter maps a current asset assignment to a verified user email. Pomerium can evaluate that imported inventory fact. The Snipe-IT asset ID and status are not live device posture and do not bind the current endpoint.
Considerations
- Some Snipe-IT responses report an application error in the body even when the HTTP status is successful.
- Assignment and asset status are inventory facts. They are not a live endpoint security signal.
- This is a customer-owned connector pattern, not a built-in Pomerium connector.
- External data sources need Pomerium Enterprise and update on a polling schedule.
- A vendor device or asset ID does not prove which device made the current Pomerium request.
