Skip to main content

What is Pomerium?

Pomerium is an identity-aware proxy for private applications, services, and AI tools. It verifies identity, checks your access policy, and forwards approved requests.

Actor
Outcome
UserSigned in
Quarterly reports
Quarterly reports

403 Forbidden

If you should have access, contact your administrator with your request id…

200 OK

Pomerium
  1. IdentityACME, Corp employeeOktauser@example.com
    Passed
  2. DeviceApproved devicePomerium device identity
    Passed
  3. LocationUnited StatesGeoIP data203.0.113.42
    Passed
  4. EmploymentActiveBambooHRstatus: active
    Passed

All this happens in tens of milliseconds.

GrafanaHTTP(S)
Dashboards
Quarterly reportsGET
Allowed · Request received

Identity and context match the policy. The request reaches Grafana.

How Pomerium works

  1. Authenticate

    Verify the identity behind a request with your existing identity provider.

  2. Authorize

    Evaluate the route's access policy using identity and request context.

  3. Access

    Forward approved requests to the application. Reject requests that do not meet the policy.

Access decisions with context

Apply policy at each protected route, with identity, context, and logs in one request path.

Protocol-Aware Access

Pomerium operates at Layer 7, which makes it protocol-aware. Your users get to use the tools they already know and love, without a janky wrapper command. You get security controls on each request or action.

Use your browser for private web applications and your standard SSH client for native SSH. TCP and UDP tunnels use a Pomerium client.

See protocol-aware policies
Pomerium connects HTTP, MCP, SSH, gRPC, TCP, and UDP workloads.

Continuous Authorization

Pomerium checks policy on each HTTP request. Access decisions use the identity and context available when the request arrives.

How authorization works
Continuous authorization checks identity, time, location, IP address, and employment status.

Extensible

Use identity claims, device information, and external data in your access policies. Connect your identity provider and the systems you already use.

Use context in access policies
Pomerium integrates external data sources for access decisions.

Full Audit Trail

See who requested access, which route they requested, and why the policy allowed or denied it. Send access and authorization logs to your logging system.

Read the authorization logs
Pomerium records user activity in an audit trail.

Why it matters

Give each identity access to the resources it needs. Pomerium enforces the access policy at the protected route, before forwarding traffic.

Use the same access layer for employees, service accounts, and AI agents, with policies specific to each resource.

Why identity-aware access matters

For security teams

Define who can use each route and use authorization logs to inspect the decision.

For developers and ops

Add authentication and authorization in front of applications without building a separate login and policy system into each one.

Common use cases

Secure Kubernetes access

Control access to Kubernetes APIs and applications with identity-based policies.

Enable distributed access

Give employees and contractors browser access to the web applications they need.

Govern AI agents

Authenticate access to MCP servers and apply policy to the tools an AI agent can call.

Read customer stories

Pick the edition that's right for you

Both editions are built on open-source Pomerium.

Pomerium Zero

Pomerium hosts the control plane. Pomerium Core runs in your environment.

Typically best for: Teams that want simpler management without running a control plane.

Pomerium Zero architecturePomerium hosts the control plane for configuration and policy. Your environment hosts the Pomerium Core data plane and applications. Core checks policy locally before forwarding allowed requests. Applications include HTTP, gRPC, SSH, and Kubernetes.Pomerium cloudYour environmentControl planeConfiguration + policySyncPomerium CoreSelf-hosted data planePolicy enforcementProxyApplicationsHTTPSSHK8sUsers +agents

Pomerium Enterprise

You host the control plane and Pomerium Core in your environment.

Typically best for: Large organizations and teams with self-hosting requirements.

Pomerium Enterprise architectureYour environment hosts the control plane for configuration and policy, the Pomerium Core data plane, and applications. Core checks policy locally before forwarding allowed requests. Applications include HTTP, gRPC, SSH, and Kubernetes.Your environmentControl planeConfiguration + policySyncPomerium CoreSelf-hosted data planePolicy enforcementProxyApplicationsHTTPSSHK8sUsers +agents

Access control that stays out of your users' way