Skip to main content

Secure internal access

SSO and request-level policy for internal web applications

Pomerium signs the user in, evaluates route policy on each protected HTTP request, and forwards only an approved request to the internal application.

What this pattern controls

Application route

Map one public route to one private upstream.

Existing SSO

Use the existing OpenID Connect identity provider.

Request policy

Check each protected HTTP request.

Protected route

Put the internal application behind Pomerium

Place one Pomerium HTTPS route in front of the internal web application. The user reaches the route instead of the private upstream address.

  • Define the user-facing From URL and private To URL.
  • Keep the upstream unreachable through an unprotected bypass path.
  • Attach the required allow and deny policy to the route.

Application identity

Send a verified identity to the upstream application

Pomerium handles OpenID Connect sign-in and checks route policy for each protected HTTP request. The application can verify Pomerium's signed identity assertion.

  • Enable Pass Identity Headers when the application needs the user identity.
  • Validate signature, audience, issuer, and expiry.
  • Keep detailed application actions and object permissions in the application.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo