Skip to main content

Topic index

Identity and Authentication

Learn how systems establish identity and verify users, services, devices, and agents.

Topic index

Understand this domain

Pomerium coverage

Pomerium can use its Hosted Authenticate Service or a configured OpenID Connect provider. It can evaluate verified claims, device identity, and external data in route policy. Pomerium Enterprise and Zero also provide service accounts for machine-to-machine requests.

Limits

  • Authentication proves an identity result. It does not grant every action to that identity.
  • A device identifier is not full operating-system posture.
  • A workload identity does not preserve a human actor unless the design carries separate delegation context.

Primary sources

3 learning paths

Paths for this topic

18 related guides

Guides in this topic

47 related terms

Concepts in this topic

Identity and Authentication

Account Recovery

Restore account access without giving attackers an easier path than the normal authentication and enrollment process.

Learn this term
Identity and Authentication

Authentication

Verify that a claimant controls one or more authenticators bound to an account without confusing that result with authorization.

Learn this term
Identity and Authentication

Back-channel logout

OpenID Connect Back-Channel Logout lets an OpenID Provider notify a relying party through a direct server-to-server request.

Learn this term
Human Factors and Security EconomicsIdentity and Authentication

Biometric Authentication

Use noisy, non-secret human characteristics only within a bounded authenticator, sensor, matching, privacy, fallback, and recovery design.

Learn this term
Agentic AccessAuthorization and Policy

Delegation

Delegation gives an actor limited authority to act for another principal, called the subject.

Learn this term
Agentic AccessAuthorization and Policy

Explicit Delegation

Explicit delegation records a deliberate grant from a subject to an actor with a named audience, actions, lifetime, and authorization evidence.

Learn this term
Identity and Authentication

Front-channel logout

OpenID Connect Front-Channel Logout uses the user's browser to load registered relying-party logout URIs from the OpenID Provider.

Learn this term
Identity and AuthenticationAgentic Access

Identity Collapse

Identity collapse occurs when a downstream service sees a common agent or service identity and loses the originating user or actor relationship.

Learn this term
Identity and AuthenticationStandards and Protocols

Identity Federation

Establish trust between an identity provider and relying party without treating an assertion as universal authority.

Learn this term
Agentic AccessIdentity and Authentication

Identity Propagation

Identity propagation carries verified information about the originating principal and, when needed, the acting service across request boundaries.

Learn this term
Identity and Authentication

Identity Provider (IdP)

An identity provider establishes an authentication event and creates a verifiable assertion for a relying party in an identity federation.

Learn this term
Application and Service AccessIdentity and Authentication

JSON Web Token (JWT)

Learn how JSON Web Tokens carry signed or encrypted claims, which checks a receiver must make, and how Pomerium uses a signed identity assertion.

Learn this term
Network and InfrastructureIdentity and Authentication

Kubernetes Service Account

Use bounded, short-lived Kubernetes service-account tokens for a workload and avoid static namespace-wide credentials.

Learn this term
Agentic AccessAuthorization and Policy

MCP Authorization

Learn how MCP authorization uses OAuth metadata, resource indicators, token audience checks, route policy, and tool authorization.

Learn this term
Identity and AuthenticationAuthorization and Policy

OAuth 2.0

Learn how OAuth 2.0 separates clients, authorization servers, resource servers, scopes, tokens, PKCE, and current OAuth 2.1 guidance.

Learn this term
Identity and AuthenticationStandards and Protocols

OpenID Connect (OIDC)

OpenID Connect is an identity layer on top of OAuth 2.0. It lets a client verify an end user's authentication and receive identity claims in an ID token.

Learn this term
Identity and Authentication

Passkey

Use WebAuthn public-key credentials bound to a relying party and understand sync, recovery, and device boundaries.

Learn this term
Human Factors and Security EconomicsIdentity and Authentication

Phishing

Distinguish deceptive delivery from verifier impersonation, credential relay, malware, payment fraud, and session theft, then use protocol controls.

Learn this term
Standards and ProtocolsIdentity and Authentication

Refresh Token

Use refresh tokens only at the authorization server, bind them to a client, rotate or sender-constrain them, and detect replay.

Learn this term
Identity and AuthenticationSecurity Operations and Risk

Revocation Latency

Measure how long a disabled identity, authenticator, session, claim, or permission can continue to authorize action.

Learn this term
Identity and AuthenticationStandards and Protocols

SCIM Provisioning

Provision and deprovision accounts and groups without confusing lifecycle synchronization with authentication federation.

Learn this term
Identity and Authentication

Security Keys

A security key is a roaming or dedicated hardware cryptographic authenticator, such as a USB, NFC, or Bluetooth key.

Learn this term
Standards and ProtocolsAuthorization and Policy

Security Time and Freshness

Use clocks, expiries, nonces, sequence, versions, and replay state without treating wall time as a complete ordering or trust source.

Learn this term
Identity and Authentication

Single Sign-On (SSO)

SSO lets a user authenticate through one identity service and then access several relying applications without entering credentials at each application.

Learn this term
Identity and AuthenticationStandards and Protocols

WebAuthn

WebAuthn is a W3C API for creating and using public-key credentials scoped to a relying party.

Learn this term
Network and InfrastructureIdentity and Authentication

Workload Attestation

Use platform evidence to select a workload identity without treating mutable labels or network location as proof.

Learn this term
Agentic AccessApplication and Service Access

Workload Identity

Learn how workload, machine, service, and non-human identities differ from user identity, and how to scope machine-to-machine access.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo