Skip to main content

Secure human access

Private application access without broad network access

Pomerium signs users in through an OpenID Connect identity provider and checks route policy on each protected HTTP request before it forwards the request.

What this pattern controls

Narrow route access

Publish only the selected application route.

Current context

Use identity and current request context in policy.

Decision evidence

Record defined authorization decision fields.

Route policy

Grant access to an application, not a network

A route maps one user-facing address to one selected upstream service. Policy decides whether the current request can use that route.

  • Match user ID, email, domain, token claims, device identity, source IP, HTTP method, or HTTP path.
  • Use date and schedule criteria with Pomerium Zero or Enterprise.
  • Use directory-synced groups and imported external records with Pomerium Enterprise.

Protocol boundary

Use the correct access path for each protocol

Pomerium checks each protected HTTP request. A tunneled TCP or WebSocket connection is checked when the connection starts.

  • Browser-based web access does not need a Pomerium client.
  • Native SSH and tunneled non-HTTP protocols use their documented access path.
  • The upstream application still controls operations and resources that route policy does not cover.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo