Skip to main content

Topic index

Application and Service Access

Learn how identity-aware access protects web applications, APIs, and non-HTTP services.

Topic index

Understand this domain

Pomerium coverage

Pomerium can proxy protected HTTP and WebSocket routes, tunnel supported TCP and UDP protocols, and provide native SSH access. It can send a signed identity assertion to an upstream HTTP application. Each route needs a reachable upstream and an explicit policy.

Limits

  • One HTTP route does not cover a service protocol that uses a separate port or transport.
  • TCP and UDP tunnels require a supported Pomerium client. Native SSH has separate server requirements.
  • A protected route does not make an unsafe upstream application safe.

Primary sources

2 learning paths

Paths for this topic

21 related guides

Guides in this topic

24 related terms

Concepts in this topic

Application and Service AccessNetwork and Infrastructure

Bastion Host

A bastion host is a hardened system that provides controlled administrative access to a more protected network or resource.

Learn this term
Application and Service AccessNetwork and Infrastructure

Clientless Zero Trust Access

Distinguish browser or native-client access from broad network tunnels and state which protocols still require a local connector.

Learn this term
Application and Service AccessNetwork and Infrastructure

Context-Aware Proxy

A context-aware proxy is a policy enforcement point placed between a requester and a protected service.

Learn this term
Application and Service AccessNetwork and Infrastructure

Gateway Bypass Path

Find every route that reaches a protected origin without the intended identity, policy, and evidence controls.

Learn this term
Standards and ProtocolsApplication and Service Access

HTTP Semantics

HTTP semantics define request methods, targets, fields, responses, status codes, authorities, and intermediary behavior.

Learn this term
Application and Service AccessIdentity and Authentication

JSON Web Token (JWT)

Learn how JSON Web Tokens carry signed or encrypted claims, which checks a receiver must make, and how Pomerium uses a signed identity assertion.

Learn this term
Application and Service Access

Layer-7 Enforcement

Layer 7 enforcement uses protocol facts, such as host, route, method, tool name, and verified identity, to make access decisions.

Learn this term
Application and Service AccessZero Trust

Named Resource Access

Grant access to one named application or service without extending general reachability to its network or neighboring systems.

Learn this term
Agentic AccessApplication and Service Access

Per-Request Authorization

Per-request authorization evaluates each action against current identity, resource, policy, and request context immediately before enforcement.

Learn this term
Application and Service Access

Route

In Pomerium, a route defines how a requester reaches a service behind Pomerium.

Learn this term
Application and Service AccessStandards and Protocols

Secure Route Selection

Select a route from trusted authority and path data so an attacker cannot redirect policy or credentials to the wrong upstream.

Learn this term
Application and Service AccessStandards and Protocols

Signed Header

Pomerium's signed header is the X-Pomerium-Jwt-Assertion header.

Learn this term
Standards and ProtocolsApplication and Service Access

SSH Protocol

SSH authenticates a server and client, then multiplexes sessions, commands, and forwarding channels over one transport.

Learn this term
Application and Service Access

Stateless

A stateless service does not keep server-side session state between requests.

Learn this term
Application and Service AccessStandards and Protocols

Token Exchange

Exchange an incoming security token for narrow target authority while preserving subject, actor, audience, and delegation semantics.

Learn this term
Application and Service AccessNetwork and Infrastructure

Upstream and Downstream

Upstream and downstream describe direction relative to one intermediary, so the reference point must be explicit.

Learn this term
Application and Service AccessStandards and Protocols

WebSocket Access

WebSocket access starts with an HTTP upgrade and then carries long-lived bidirectional messages on one connection.

Learn this term
Agentic AccessApplication and Service Access

Workload Identity

Learn how workload, machine, service, and non-human identities differ from user identity, and how to scope machine-to-machine access.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo