Skip to main content

Confused Deputy

Prevent a service or agent from using its own authority for a caller that did not have permission to request the action.

Deputy with authority

A confused deputy is a service, tool, proxy, or agent that has legitimate authority but applies it for the wrong caller, resource, or purpose. The attacker does not need the deputy's credential. The attacker induces the deputy to use it.

Find the confusion

Trace the originating actor, active subject, deputy, target resource, action, audience, and policy at every hop. Ask whose authority each credential represents. A deputy that receives a resource name from one party and authority from another needs a binding rule between them.

Bind authority to intent

Use audience-restricted credentials, explicit resource indicators, per-caller authorization, token exchange with subject and actor semantics, narrow tool contracts, and server-side allowlists. The target must validate that the credential was issued for it. The deputy must verify that the caller can request the specific action.

Failure and residual risk

Token passthrough can erase the deputy boundary. Shared service credentials can make all callers look the same. A user approval can describe one action while the deputy performs another. An agent can select a more powerful tool than the user's instruction requires. Logs that retain only the deputy hide the originating actor.

Pomerium boundary

Pomerium can pass a verified user identity to an upstream and can enforce route policy. The upstream still must bind that user or delegated actor to each application action. Pomerium must not be treated as proof that a downstream token has the correct resource audience.

Evaluation checklist

  • Can evidence identify the originating actor, deputy, target, and action?
  • Does each credential name or constrain its intended audience or resource?
  • Does the deputy authorize the caller before it uses its own authority?
  • Can caller-controlled input select a resource outside the approved boundary?
  • Do tests cover token passthrough, wrong audience, wrong actor, and tool substitution?

Sources and further reading

Keep learning

Agentic AccessAuthorization and Policy

Explicit Delegation

Explicit delegation records a deliberate grant from a subject to an actor with a named audience, actions, lifetime, and authorization evidence.

Learn this term
Agentic AccessIdentity and Authentication

Identity Propagation

Identity propagation carries verified information about the originating principal and, when needed, the acting service across request boundaries.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo