Skip to main content

Attribute, Claim, and Assertion

Separate a source fact, a released claim, and a protected statement sent between an issuer and relying party.

Three information forms

An attribute is a property associated with an entity in a source system, such as a directory group or department. A claim is a statement about a subject, often selected and formatted for a transaction. An assertion is a protected set of claims issued for a relying party. Protocols use specific forms, such as an OpenID Connect ID Token or a SAML assertion.

Provenance and meaning

Record where each attribute originates, who can change it, what it means, and how fresh it is. The issuer decides which claims to release. The relying party must interpret them only within the issuer, audience, schema, assurance, and time context.

Validation and use

Validate the assertion before trusting claims. Check issuer, audience, signature, time, and protocol-specific request binding. Use stable issuer and subject identifiers for account mapping. Do not use a display name or email address as a global identity key unless the system explicitly guarantees the required uniqueness and lifecycle.

Failure and residual risk

A correctly signed assertion can contain an inaccurate or stale source attribute. Two issuers can use the same subject string for different people. Excess claims increase privacy and authorization exposure. A caller-supplied header can look like a claim without being a verified assertion.

Pomerium boundary

Pomerium consumes claims from the configured identity provider and can send a signed identity assertion to an upstream. The upstream must validate the Pomerium assertion before trusting it. The application decides which verified claims are suitable for its permissions.

Evaluation checklist

  • What source owns each attribute, and who can change it?
  • Which issuer, subject, audience, and schema give the claim meaning?
  • Is the assertion validated before any claim is used?
  • Is freshness suitable for the access decision?
  • Are only necessary claims released, logged, and forwarded?

Sources and further reading

Keep learning

Identity and AuthenticationStandards and Protocols

Identity Federation

Establish trust between an identity provider and relying party without treating an assertion as universal authority.

Learn this term
Agentic AccessIdentity and Authentication

Identity Propagation

Identity propagation carries verified information about the originating principal and, when needed, the acting service across request boundaries.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo