Narrow route access
Publish only the selected application route.
Secure human access
Pomerium signs users in through an OpenID Connect identity provider and checks route policy on each protected HTTP request before it forwards the request.
Publish only the selected application route.
Use identity and current request context in policy.
Record defined authorization decision fields.
Route policy
A route maps one user-facing address to one selected upstream service. Policy decides whether the current request can use that route.
Protocol boundary
Pomerium checks each protected HTTP request. A tunneled TCP or WebSocket connection is checked when the connection starts.
Identity and context criteria for route policy.
Browser and non-HTTP client behavior.
Available authorization decision fields.