Skip to main content
See All Integrations

Internal APIs

Protect access to internal HTTP APIs with identity-aware Pomerium routes.

Standard protected service pattern

Categories
Developer Tools, Upstream Applications

Overview

An internal API is a private HTTP or HTTPS interface used by applications, automation, or employees. It is a concept, not one vendor product. Pomerium can apply route policy before a request reaches the selected endpoint.

Internal APIs can expose sensitive data and administrative operations. A Pomerium route adds identity-aware policy before a request reaches the selected API. The API keeps resource and operation authorization.

Pomerium controls who or what can reach the selected API route. The protected API remains responsible for request validation, resource authorization, data, and operation semantics.

How it works

Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.

Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.

Define separate routes and policy for human and machine access when their trust model differs. Verify signed identity data at the upstream before the API trusts user claims.

Example

A developer uses a reviewed service credential to call an internal deployment API through Pomerium. Pomerium evaluates the route policy. The API still applies its own operation and resource permissions.

Considerations

  • Most API clients cannot complete an interactive browser redirect. Use a suitable noninteractive authentication flow.
  • Pomerium service accounts are Enterprise and Zero features. The API remains responsible for its own authorization.

Sources and official resources

  • Protect access to internal administration panels as upstream web applications.

  • Protect access to Backstage developer portals and software catalogs as an upstream web application.

  • Protect the Jenkins web application and API, with separate WebSocket or TCP access for build agents when required.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo