Skip to main content

Clientless Zero Trust Access

Distinguish browser or native-client access from broad network tunnels and state which protocols still require a local connector.

Access without a network tunnel

Clientless zero trust access lets a user reach a named private application without installing a broad network tunnel client for that resource. A browser can provide this path for HTTP and HTTPS. The browser is still client software. Clientless describes the absence of a dedicated access connector, not the absence of a client.

Choose by protocol

HTTP applications can use browser redirects, cookies, and proxy routes. Native SSH can use an ordinary SSH client when the server trusts the required certificate authority and the access system supports that flow. Arbitrary TCP and UDP protocols usually need a local connector or protocol-specific integration.

Preserve the boundary

Publish only the named resource. Keep the origin private from direct clients. Authenticate and authorize each supported connection. Define what happens to long-lived connections when identity, policy, or device state changes. Keep application object and action authorization active.

Failure and residual risk

Calling all access clientless can hide a required connector, device enrollment, or protocol limit. Browser access can still be phished or run on an unsafe device. An open origin bypasses route policy. Long-lived connections can outlast the context that allowed them.

Pomerium boundary

Pomerium can protect HTTP and HTTPS applications through browser routes. It can also provide documented native SSH and client-assisted TCP or UDP paths. Pomerium does not make every protocol clientless and does not secure an unmanaged endpoint or unsafe application by itself.

Evaluation checklist

  • Is every required protocol and client component named accurately?
  • Does the design grant one named resource instead of broad network membership?
  • Can any client reach the origin without Pomerium?
  • Are connection lifetime and reevaluation limits explicit?
  • Does the upstream keep its own object and action authorization?

Sources and further reading

Keep learning

Network and Infrastructure

Virtual Private Network (VPN)

A VPN creates an encrypted tunnel over another network. Remote-access VPNs connect an endpoint to a private network. Site-to-site VPNs connect networks.

Learn this term
Application and Service AccessZero Trust

Named Resource Access

Grant access to one named application or service without extending general reachability to its network or neighboring systems.

Learn this term
Application and Service AccessNetwork and Infrastructure

Gateway Bypass Path

Find every route that reaches a protected origin without the intended identity, policy, and evidence controls.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo