Skip to main content
See All Integrations

ZITADEL

Use ZITADEL as the identity provider for Pomerium through OpenID Connect.

Standards-based OpenID Connect pattern

Category
Identity Providers

Overview

ZITADEL is open-source identity infrastructure that is available as managed cloud software or for self-hosting. It can authenticate Pomerium users through OpenID Connect.

Using ZITADEL as the identity provider gives protected applications one sign-in path. Each application does not need to implement the same external authentication flow. Pomerium can apply route policy from the authenticated identity and request context.

ZITADEL sends authenticated identity data toward Pomerium. Pomerium uses that data with route policy. Pomerium then sends only approved application traffic toward the protected service.

How it works

Create an OpenID Connect application in the correct ZITADEL project. Configure the exact custom-domain issuer, client settings, redirect URI, roles, and project claims. Use discovery so clients follow signing-key rotation.

Configure Pomerium with the exact issuer or provider URL, client ID, and client secret. Use the Pomerium callback URL as an exact redirect URI. Request only the scopes and claims that access policy needs.

Test discovery, signing-key rotation, the authorization code flow, logout, and required claim mappings before production use. Keep provider credentials outside source control.

Example

A team registers Pomerium as an OpenID Connect client in ZITADEL. Users sign in through ZITADEL. Pomerium validates the identity response and applies route policy before it sends an approved request to a private application.

Considerations

  • The issuer and redirect URI must match exactly, including the custom domain when one is configured.
  • Roles and project claims depend on grants and project settings. Signing keys can rotate without notice.
  • ZITADEL remains responsible for authentication, user lifecycle, and the identity data that it issues.
  • A standards-based OpenID Connect pattern is not evidence of a vendor-specific connector or partnership.

Sources and official resources

  • Use Keycloak as the identity provider for Pomerium through OpenID Connect.

  • Use authentik as the identity provider for Pomerium through OpenID Connect.

  • Use Ory Hydra as the identity provider for Pomerium through OpenID Connect.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo