Skip to main content

Design service-to-service access

Authenticate workloads, preserve human actor context, authorize target actions, and manage machine credentials through their lifecycle.

Learning outcomes

  • Separate service identity, workload instance, deployment, and originating human actor.
  • Trace credential issuance, presentation, validation, authorization, rotation, and revocation.
  • Preserve delegation without token passthrough or identity collapse.
  • Test replay, wrong audience, compromised workload, stale policy, and direct-service bypass.

System and boundaries

Include the calling workload, workload identity issuer, deployment platform, access gateway or mesh, authorization service, target workload, target resource, credential stores, and evidence. When a user starts the call, include the originating subject and each acting service.

Distinguish the logical service, running workload instance, deployment environment, machine credential, and human actor. A service name is not proof that the current instance is authorized.

Request and decision flow

The platform or credential service authenticates the workload and issues a short-lived identity for an intended trust domain or audience. The caller presents it over an authenticated channel. The target validates issuer, audience, status, time, and workload identity. Policy evaluates the service, resource, action, environment, and any preserved actor. The target enforces local permission and records evidence.

When acting for a user, exchange or attenuate authority for the target. Preserve subject and actor. Do not forward a broad incoming bearer token through the chain.

Failure domains

  • A static service credential is copied to another workload.
  • A token for one service is accepted by another.
  • Service identity erases the human who initiated the action.
  • A compromised workload uses all service authority.
  • Policy authorizes a service name without environment or deployment context.
  • Credential rotation fails and callers fall back to an old secret.
  • Direct cluster or origin traffic bypasses intended policy and evidence.

Design tradeoffs and residual risk

Short-lived workload credentials reduce secret persistence but depend on a trusted issuer and renewal path. Mutual transport authentication binds peers but does not define resource permission. Preserving human context improves authorization and evidence but adds privacy and chain-validation complexity. Shared service identities simplify policy but increase blast radius.

Limit authority by target, action, workload, environment, and time. Treat workload compromise as an expected containment case.

Pomerium boundary

Pomerium can authenticate documented service-account requests, enforce route policy, and preserve original request context for supported flows. Workload platforms and identity systems own instance identity. Target services must validate accepted credentials and authorize their own objects and actions.

Exercise

Trace a web application calling a billing API for a user. Record the user, service, workload instance, credential, issuer, audience, target, action, policy, expiry, rotation, and evidence at each hop.

Test copied credential, wrong audience, wrong environment, revoked user, compromised workload, stale policy, direct service access, and renewal outage.

Evaluation checklist

  • Can the target identify the calling workload and originating actor when needed?
  • Is each credential bound to a trusted issuer, audience, lifetime, and workload?
  • Does policy limit the exact target resource and action?
  • Can credential theft and workload compromise be contained and revoked?
  • Can evidence trace the service chain without storing bearer credentials?

Next learning unit

Token Exchange

Exchange an incoming security token for narrow target authority while preserving subject, actor, audience, and delegation semantics.

Sources and further reading

Keep learning

Application and Service AccessStandards and Protocols

Token Exchange

Exchange an incoming security token for narrow target authority while preserving subject, actor, audience, and delegation semantics.

Learn this term
Agentic AccessAuthorization and Policy

Explicit Delegation

Explicit delegation records a deliberate grant from a subject to an actor with a named audience, actions, lifetime, and authorization evidence.

Learn this term
Authorization and PolicyAgentic Access

Confused Deputy

Prevent a service or agent from using its own authority for a caller that did not have permission to request the action.

Learn this term
Agentic AccessIdentity and Authentication

Identity Propagation

Identity propagation carries verified information about the originating principal and, when needed, the acting service across request boundaries.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo