Skip to main content

Scoped multi-tenant access

Route policy and application tenant isolation

Attach policy to a fixed host or path route. For a shared application, verify the Pomerium JWT and enforce tenant permissions inside the application.

What this pattern controls

Route boundary

Match a fixed tenant-facing host or path.

Verified identity

Pass a signed identity assertion upstream.

Application authority

Enforce tenant data access in the application.

Fixed route boundary

Use a separate host or path when the upstream is separate

A Pomerium route has a fixed destination. Pomerium does not select a tenant backend from the caller identity.

  • Use a tenant-specific host or path when each tenant has a separate upstream surface.
  • Attach policy to that fixed route.
  • Pomerium matches routes by host, path, prefix, or regular expression.

Application boundary

Keep tenant and data authorization in the application

For one shared multi-tenant application, pass the signed Pomerium JWT to the application. The application must enforce tenant permissions and data isolation.

  • Enable Pomerium identity headers.
  • Validate signature, issuer, audience, and expiration.
  • Map the verified identity to a tenant inside the application.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo