Skip to main content

Secure internal APIs

Identity-aware access for private HTTP APIs

Place an HTTP or HTTPS Pomerium route in front of the private API. Authenticate the caller and apply route policy before forwarding the request.

What this pattern controls

Private upstream

Keep the upstream API on a private address.

Known caller

Select a user or service account flow.

Clear authority

Keep operation and data permissions in the API.

API caller

Choose the correct identity flow for the API client

The caller reaches the Pomerium From URL. Pomerium forwards an approved request to the private To address that it can reach.

  • Use a service account for an autonomous Zero or Enterprise caller.
  • Use programmatic access for a user-driven CLI or application.
  • Use separate routes when people and machines have different trust requirements.

API boundary

Apply route policy and keep API authorization upstream

Pomerium checks route policy before it forwards the request. The API still controls the operation and resource after the route boundary.

  • Use PPL to check identity, HTTP method, or path.
  • Validate X-Pomerium-Jwt-Assertion when the API needs identity.
  • Keep endpoint, operation, object, and data authorization in the API.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo