Internal APIs
Protect access to internal HTTP APIs with identity-aware Pomerium routes.
Overview
An internal API is a private HTTP or HTTPS interface used by applications, automation, or employees. It is a concept, not one vendor product. Pomerium can apply route policy before a request reaches the selected endpoint.
Internal APIs can expose sensitive data and administrative operations. A Pomerium route adds identity-aware policy before a request reaches the selected API. The API keeps resource and operation authorization.
Pomerium controls who or what can reach the selected API route. The protected API remains responsible for request validation, resource authorization, data, and operation semantics.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.
Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.
Define separate routes and policy for human and machine access when their trust model differs. Verify signed identity data at the upstream before the API trusts user claims.
Example
A developer uses a reviewed service credential to call an internal deployment API through Pomerium. Pomerium evaluates the route policy. The API still applies its own operation and resource permissions.
Considerations
- Most API clients cannot complete an interactive browser redirect. Use a suitable noninteractive authentication flow.
- Pomerium service accounts are Enterprise and Zero features. The API remains responsible for its own authorization.
