Build secure software and web applications
Move from security requirements through safe implementation, browser boundaries, authorization tests, and vulnerability response.
Topic index
Learn how identity-aware access protects web applications, APIs, and non-HTTP services.
Topic index
Pomerium can proxy protected HTTP and WebSocket routes, tunnel supported TCP and UDP protocols, and provide native SSH access. It can send a signed identity assertion to an upstream HTTP application. Each route needs a reachable upstream and an explicit policy.
2 learning paths
Move from security requirements through safe implementation, browser boundaries, authorization tests, and vulnerability response.
Design browser, API, service, SSH, TCP, and UDP access without losing identity or creating a direct bypass.
21 related guides
Place authentication and authorization around WebSocket upgrade, HTTP CONNECT, CONNECT-UDP, and long-lived tunnels.
Place transport and application enforcement where the required identity, destination, protocol, resource, and action are visible.
Place access enforcement across identity-aware proxies, API gateways, service meshes, load balancers, and network tunnels.
Compare central and local authorization while preserving complete enforcement, current context, and safe failure behavior.
Compare device agent and gateway, enclave gateway, resource portal, and application sandbox deployment boundaries.
Compare bearer, DPoP, and mutual-TLS token use and test proof binding, freshness, audience, and replay defenses.
Define fail-closed, fail-open, degraded, cached, and break-glass states for every access dependency before an outage.
Give people, services, workloads, devices, and agents distinct identity, delegation, credential, and revocation models.
Protect API inventory, clients, routes, versions, objects, actions, credentials, quotas, and evidence with explicit owners.
Map user identity and policy to non-HTTP connections while controlling clients, ports, names, lifetime, and protocol limits.
Authenticate workloads, preserve human actor context, authorize target actions, and manage machine credentials through their lifecycle.
Distinguish reverse, forward, transparent, and identity-aware proxies by client, destination, trust, and enforcement role.
Carry signed identity context across a proxy boundary and validate issuer, audience, signature, time, and delivery path upstream.
Design named administrative access with strong identity, narrow routes, native server controls, session limits, and evidence.
Remove untrusted identity fields, authenticate the proxy path, validate signed assertions, and close direct-origin bypass.
Separate identity-provider, proxy, and application sessions while controlling cookies, CSRF, logout, renewal, and origin trust.
Design origins, sessions, cross-origin reads, state changes, frames, messages, and scripts as separate browser security controls.
Trace authentication, gateway route authorization, and application permission as separate decisions with separate evidence.
Trace one protected request, find trust boundaries and bypass paths, and test which access decisions belong at the gateway and application.
Trace DNS, TLS, authentication, session, route, policy, upstream, application authorization, response, and evidence.
Separate JWT claims, JWS signatures, JWE encryption, and JWK key data and apply a fixed validation policy.
24 related terms
An access token is a credential that a client presents to a resource server.
A bastion host is a hardened system that provides controlled administrative access to a more protected network or resource.
Distinguish browser or native-client access from broad network tunnels and state which protocols still require a local connector.
A context-aware proxy is a policy enforcement point placed between a requester and a protected service.
Credential injection supplies a bounded upstream credential after access policy allows a request.
Find every route that reaches a protected origin without the intended identity, policy, and evidence controls.
HTTP semantics define request methods, targets, fields, responses, status codes, authorities, and intermediary behavior.
Identity-aware rate limiting bounds request volume by accountable subject, client, resource, action, and cost.
Authenticate agent messages, bind them to one task and audience, validate content, and preserve actor and delegation evidence.
Learn how JSON Web Tokens carry signed or encrypted claims, which checks a receiver must make, and how Pomerium uses a signed identity assertion.
Layer 7 enforcement uses protocol facts, such as host, route, method, tool name, and verified identity, to make access decisions.
Grant access to one named application or service without extending general reachability to its network or neighboring systems.
Authorize every application action against the exact object instead of trusting route access, a role, or an object ID.
Per-request authorization evaluates each action against current identity, resource, policy, and request context immediately before enforcement.
In Pomerium, a route defines how a requester reaches a service behind Pomerium.
Select a route from trusted authority and path data so an attacker cannot redirect policy or credentials to the wrong upstream.
Pomerium's signed header is the X-Pomerium-Jwt-Assertion header.
SSH authenticates a server and client, then multiplexes sessions, commands, and forwarding channels over one transport.
A stateless service does not keep server-side session state between requests.
Exchange an incoming security token for narrow target authority while preserving subject, actor, audience, and delegation semantics.
Keep model output, tool arguments, generated code, interpreters, and sandboxes from becoming uncontrolled host execution.
Upstream and downstream describe direction relative to one intermediary, so the reference point must be explicit.
WebSocket access starts with an HTTP upgrade and then carries long-lived bidirectional messages on one connection.
Learn how workload, machine, service, and non-human identities differ from user identity, and how to scope machine-to-machine access.