Application route
Map one public route to one private upstream.
Secure internal access
Pomerium signs the user in, evaluates route policy on each protected HTTP request, and forwards only an approved request to the internal application.
Map one public route to one private upstream.
Use the existing OpenID Connect identity provider.
Check each protected HTTP request.
Protected route
Place one Pomerium HTTPS route in front of the internal web application. The user reaches the route instead of the private upstream address.
Application identity
Pomerium handles OpenID Connect sign-in and checks route policy for each protected HTTP request. The application can verify Pomerium's signed identity assertion.
Create a protected application route.
OpenID Connect authentication behavior.
Validate the signed Pomerium identity assertion.