Skip to main content

Federated access for third-party tools

One protected route for each external automation tool

Create a separate service account for each external CI job, monitoring process, or automation tool. Limit that identity to the required route.

What this pattern controls

Correct caller model

Select a service or user-driven identity flow.

Separate integration

Create one identity for one external tool.

Limited route

Permit only the selected internal service route.

Caller model

Separate autonomous tools from user-driven programs

Choose the caller model before you configure policy. Service accounts are available with Pomerium Zero and Enterprise.

  • Use a service account for an autonomous tool.
  • Use programmatic access when a person can complete identity-provider sign-in.
  • Do not reuse a human account for background automation.

Credential boundary

Limit the integration identity to one route

Match the service account user ID in only the required route policy. The protected service must still enforce its own roles and operations.

  • Create one service account for one integration.
  • Store the JWT in the tool's secret store.
  • Send it in a documented Pomerium authorization header, not a URL.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo