
Kolide by 1Password
Use selected Kolide inventory records in Pomerium policy through a customer-owned external data source.
Overview
Kolide by 1Password is a device trust and posture service. Its API exposes device and user records. A customer-owned adapter can import a selected record set into Pomerium Enterprise, but the export does not reproduce Kolide browser-based device assertions.
Selected Kolide by 1Password data can add organization, inventory, or security context to an access decision. A small, reviewed record set is easier to understand and protect than a broad export of the source system.
Pomerium can evaluate selected Kolide by 1Password records after a customer-owned adapter maps them to supported request or user keys. Pomerium does not call the vendor API directly and does not manage the source system.
How it works
Create a Kolide API key with the required administrator access. Read selected records through the current versioned API. Follow cursor pagination and the documented rate limit.
Map only the fields that policy needs. Each imported record must use a Pomerium-supported foreign key: user.id, user.email, request.ip, or request.client_certificate.fingerprint.
Publish the records through a protected JSON, CSV, tar, or ZIP source. Configure Pomerium Enterprise to poll that source. Evaluate the imported fields with a Pomerium Policy Language record matcher.
Example
An adapter maps a reviewed Kolide inventory state to a verified work email. Pomerium evaluates the imported user record as one policy signal. The imported Kolide record does not prove the posture of the device making this request.
Considerations
- Only full administrators can create Kolide API keys.
- The documented API limit is 270 requests per minute.
- An exported API record does not reproduce Kolide cryptographic device trust in a browser flow.
- This is a customer-owned connector pattern, not a built-in Pomerium connector.
- External data sources need Pomerium Enterprise and update on a polling schedule.
- A vendor device or asset ID does not prove which device made the current Pomerium request.
