Design Security for Real Human Systems
Build security that survives deception, pressure, support, recovery, insider authority, poor incentives, and daily work.
Topic index
Learn how systems establish identity and verify users, services, devices, and agents.
Topic index
Pomerium can use its Hosted Authenticate Service or a configured OpenID Connect provider. It can evaluate verified claims, device identity, and external data in route policy. Pomerium Enterprise and Zero also provide service accounts for machine-to-machine requests.
3 learning paths
Build security that survives deception, pressure, support, recovery, insider authority, poor incentives, and daily work.
Control personal data, metadata, identifiers, correlation, telemetry, inference, release, retention, and deletion across access systems.
Design proofing, enrollment, authenticators, sessions, recovery, federation, and non-human identity as one system.
18 related guides
Trace SPIFFE IDs, SVIDs, trust domains, bundles, Workload API delivery, attestation, rotation, and federation.
Disable identity, revoke credentials and sessions, isolate routes, and measure the last accepted harmful action.
Give people, services, workloads, devices, and agents distinct identity, delegation, credential, and revocation models.
Route sign-in across identity providers without issuer confusion, account collision, unsafe linking, or recovery bypass.
Authenticate workloads, preserve human actor context, authorize target actions, and manage machine credentials through their lifecycle.
Trace WebAuthn registration and authentication across relying party, browser, authenticator, origin, and user verification.
Exchange attested platform identity for short-lived target credentials without copying long-lived cloud keys into workloads.
Reduce claims, identifiers, device signals, policy inputs, assertions, logs, and retention to the minimum required for each access decision.
Carry signed identity context across a proxy boundary and validate issuer, audience, signature, time, and delivery path upstream.
Bind an OAuth authorization code to one client transaction and reject code theft, injection, mix-up, and redirect abuse.
Separate identity-provider, proxy, and application sessions while controlling cookies, CSRF, logout, renewal, and origin trust.
Constrain help-desk, authenticator reset, impersonation, exception, federation, and emergency actions as one privileged control plane.
Design session creation, binding, renewal, expiry, reauthentication, revocation, and termination after sign-in.
Distinguish the device, its key, ownership, management state, health evidence, policy, and freshness limits.
Distinguish and test guessing, stuffing, spraying, phishing, MFA fatigue, recovery abuse, and session theft.
Trace identity provider, service provider, metadata, bindings, assertions, signatures, audience, correlation, and logout.
Follow identity proofing, enrollment, authenticators, federation, sessions, account changes, recovery, and termination.
Trace OpenID Connect sign-in and validate issuer, client, redirect, state, nonce, ID token, and access-token boundaries.
47 related terms
A 2FA authenticator is an authenticator used as one factor in a two-factor authentication process.
Restore account access without giving attackers an easier path than the normal authentication and enrollment process.
Separate the real-world actor, active subject, represented principal, digital identity, and account.
Prevent an agent from using a shared, wrong-user, stale, or excessive identity to act beyond the current delegated task.
Separate a source fact, a released claim, and a protected statement sent between an issuer and relying party.
Verify that a claimant controls one or more authenticators bound to an account without confusing that result with authorization.
OpenID Connect Back-Channel Logout lets an OpenID Provider notify a relying party through a direct server-to-server request.
Use noisy, non-secret human characteristics only within a bounded authenticator, sensor, matching, privacy, fallback, and recovery design.
Distinguish a bound credential, an authenticator, its secret or key, a factor type, and protocol output.
Delegation gives an actor limited authority to act for another principal, called the subject.
Device posture is the current security state of a device.
Select and distinguish identity, authentication, and federation assurance levels for a digital service.
Explicit delegation records a deliberate grant from a subject to an actor with a named audience, actions, lifetime, and authorization evidence.
OpenID Connect Front-Channel Logout uses the user's browser to load registered relying-party logout URIs from the OpenID Provider.
Separate a label, system account, directory record, and real person before joining identity across systems.
Identity and access management uses governance, processes, and technology to establish digital identities and control their access to resources.
Identity collapse occurs when a downstream service sees a common agent or service identity and loses the originating user or actor relationship.
Establish trust between an identity provider and relying party without treating an assertion as universal authority.
Resolve a claimed real-world identity, validate evidence, verify the applicant, and bind the result to an account.
Identity propagation carries verified information about the originating principal and, when needed, the acting service across request boundaries.
An identity provider establishes an authentication event and creates a verifiable assertion for a relying party in an identity federation.
Create, change, and remove identity and access state when a person or workload enters, changes, or leaves a role.
Learn how JSON Web Tokens carry signed or encrypted claims, which checks a receiver must make, and how Pomerium uses a signed identity assertion.
Use bounded, short-lived Kubernetes service-account tokens for a workload and avoid static namespace-wide credentials.
Lightweight Directory Access Protocol (LDAP) is an Internet protocol for clients to access directory services that follow X.500 data and service models.
Learn how MCP authorization uses OAuth metadata, resource indicators, token audience checks, route policy, and tool authorization.
Require authenticators from distinct factor types and evaluate phishing, enrollment, recovery, and session threats.
Mutual TLS, or mTLS, is TLS with certificate authentication for both endpoints.
Learn how OAuth 2.0 separates clients, authorization servers, resource servers, scopes, tokens, PKCE, and current OAuth 2.1 guidance.
The client credentials grant issues authority to a confidential client acting for itself, not for a human user.
OpenID Connect is an identity layer on top of OAuth 2.0. It lets a client verify an end user's authentication and receive identity claims in an ID token.
Bind an OpenID Connect response to the initiating browser, issuer, client, redirect URI, nonce, and authorization request.
Use WebAuthn public-key credentials bound to a relying party and understand sync, recovery, and device boundaries.
Evaluate password verification, storage, throttling, compromised values, phishing, reuse, and recovery as one control.
Distinguish deceptive delivery from verifier impersonation, credential relay, malware, payment fraud, and session theft, then use protocol controls.
Require fresh or stronger authentication when session age, risk, or a sensitive action exceeds the current assurance.
Use refresh tokens only at the authorization server, bind them to a client, rotate or sender-constrain them, and detect replay.
Measure how long a disabled identity, authenticator, session, claim, or permission can continue to authorize action.
Provision and deprovision accounts and groups without confusing lifecycle synchronization with authentication federation.
Security Assertion Markup Language 2.0 exchanges authentication, attribute, and authorization decision assertions between federation parties.
A security key is a roaming or dedicated hardware cryptographic authenticator, such as a USB, NFC, or Bluetooth key.
Treat support, enrollment, authenticator replacement, policy exception, impersonation, and emergency recovery as high-authority security controls.
Use clocks, expiries, nonces, sequence, versions, and replay state without treating wall time as a complete ordering or trust source.
SSO lets a user authenticate through one identity service and then access several relying applications without entering credentials at each application.
WebAuthn is a W3C API for creating and using public-key credentials scoped to a relying party.
Use platform evidence to select a workload identity without treating mutable labels or network location as proof.
Learn how workload, machine, service, and non-human identities differ from user identity, and how to scope machine-to-machine access.