Native client
Use the standard SSH client already in the operator workflow.
Native SSH access
Users connect with a standard SSH client. Pomerium authenticates them through OAuth, applies SSH route policy, and presents an ephemeral certificate to the upstream server.
Use the standard SSH client already in the operator workflow.
Issue a short-lived user certificate after authentication.
Apply route and SSH-specific policy before access.
SSH trust path
Pomerium terminates the downstream SSH connection, authenticates the user, evaluates policy, and connects to the upstream with a signed user certificate.
Protocol boundary
Native SSH requires server-side CA trust and Pomerium SSH configuration. It is different from the pomerium-cli TCP tunnel path.
SSH keys, certificate authority, routes, and connection flow.
Zero and Enterprise recording, storage, and playback for native SSH sessions.
Policy criteria and allow or deny decision fields.