Private upstream
Keep the upstream API on a private address.
Secure internal APIs
Place an HTTP or HTTPS Pomerium route in front of the private API. Authenticate the caller and apply route policy before forwarding the request.
Keep the upstream API on a private address.
Select a user or service account flow.
Keep operation and data permissions in the API.
API caller
The caller reaches the Pomerium From URL. Pomerium forwards an approved request to the private To address that it can reach.
API boundary
Pomerium checks route policy before it forwards the request. The API still controls the operation and resource after the route boundary.
Create the private upstream route.
Authenticate an autonomous machine caller.
Match request identity, method, and path.