Skip to main content

Secure model endpoints

Identity-aware access for private model interfaces

Put a Pomerium route in front of the private UI or HTTP model endpoint. Require a user or service-account identity and close the direct bypass path.

What this pattern controls

Exact endpoint

Protect a private UI or endpoint you control.

Known caller

Require an interactive or service identity.

Clear boundary

Keep quotas and model permissions upstream.

Model endpoint scope

Protect an endpoint that your organization controls

Use this pattern for self-hosted model interfaces and private HTTP endpoints. It does not replace an external model provider's API-key or billing system.

  • Define a route to the private model UI or HTTP endpoint.
  • Keep clients from reaching the upstream through a bypass path.
  • Use the application's own provider credential and billing controls when required.

Identity boundary

Select the caller identity and keep model controls upstream

Apply supported identity and request policy before Pomerium forwards the call. Keep model operation, quota, and data permissions in the upstream service.

  • Use identity-provider sign-in for interactive users.
  • Use a Pomerium service account for a headless Zero or Enterprise caller.
  • Record route authorization and HTTP access fields without claiming anomaly detection.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo