Skip to main content

Identity Propagation

Identity propagation carries verified information about the originating principal and, when needed, the acting service across request boundaries.

What is Identity Propagation?

Identity propagation carries verified information about the originating principal and, when needed, the acting service across request boundaries. It avoids replacing all callers with one shared identity.

Why it matters

A downstream service needs reliable caller context to apply user-specific policy and create useful audit records. Loss of that context can grant broad shared access or hide accountability.

How it works

  1. Authenticate the originating principal.
  2. Mint or exchange a target-specific signed assertion that retains the needed subject and actor context.
  3. At the downstream service, validate the signature, issuer, audience, expiry, and authorization data before use.

Example

Alice asks an agent to query an inventory service. The request reaches the service with verified user context for Alice and separate context for the acting application.

Pomerium boundary

Pomerium mints a signed JWT from verified identity claims and passes it to an upstream application. The upstream must validate its signature, issuer, audience, and expiry. The Pomerium identity assertion does not contain the original IdP token. An operator can separately configure a route to send an available IdP access token or ID token in an upstream request header.

Limits and non-claims

  • Copying an unsigned identity header is not verified identity propagation.
  • Propagated identity does not make downstream authorization correct.
  • Services must minimize identity data and avoid sending a credential to the wrong audience.

Evaluation checklist

  • Does each hop preserve the originating actor, active subject, issuer, audience, and trust source?
  • How does the receiver verify freshness and prevent a client from supplying the identity assertion?
  • Does the application map the propagated identity to its own resource and action authorization?

Sources and further reading

Keep learning

Identity and AuthenticationAgentic Access

Identity Collapse

Identity collapse occurs when a downstream service sees a common agent or service identity and loses the originating user or actor relationship.

Learn this term
Agentic AccessAuthorization and Policy

Delegation

Delegation gives an actor limited authority to act for another principal, called the subject.

Learn this term
Application and Service AccessStandards and Protocols

Signed Header

Pomerium's signed header is the X-Pomerium-Jwt-Assertion header.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo