Protect data with applied cryptography
Learn cryptographic primitives, key systems, data lifecycle controls, storage protection, and migration without inventing protocols.
Topic index
Learn the standards and protocols that systems use for identity, policy, encryption, and transport.
Topic index
Pomerium uses standards such as TLS, OpenID Connect, JSON Web Tokens, HTTP, WebSocket, CONNECT, and Model Context Protocol in documented paths. Operators must use the current Pomerium reference and the applicable protocol specification for the selected deployment.
2 learning paths
Learn cryptographic primitives, key systems, data lifecycle controls, storage protection, and migration without inventing protocols.
Validate TLS, X.509, OAuth, OpenID Connect, JOSE, WebAuthn, metadata, token, and version boundaries.
17 related guides
Place authentication and authorization around WebSocket upgrade, HTTP CONNECT, CONNECT-UDP, and long-lived tunnels.
Compare bearer, DPoP, and mutual-TLS token use and test proof binding, freshness, audience, and replay defenses.
Separate OAuth scopes, roles, entitlements, consent, and application permissions before a resource server authorizes an action.
Trace WebAuthn registration and authentication across relying party, browser, authenticator, origin, and user verification.
Inventory protocol profiles, detect use, migrate consumers, and remove obsolete versions without permanent compatibility paths.
Generate, store, issue, distribute, rotate, revoke, destroy, and recover credentials and cryptographic keys.
Separate token expiry, introspection, revocation, session termination, and replay response and measure the effective denial time.
Inventory cryptographic dependencies and migrate protocols, algorithms, keys, certificates, code, hardware, and stored data safely.
Reject tokens issued for another resource and exchange or broker credentials instead of forwarding bearer authority through agents.
Bind an OAuth authorization code to one client transaction and reject code theft, injection, mix-up, and redirect abuse.
Trace resolution, routing, certificate names, endpoint authentication, and failover without treating DNS as identity.
Separate remote Streamable HTTP authorization from local stdio process, executable, environment, and operating-system security.
Trace identity provider, service provider, metadata, bindings, assertions, signatures, audience, correlation, and logout.
Trace TLS 1.3 authentication, key establishment, record protection, termination, and early-data risk across an access path.
Trace OpenID Connect sign-in and validate issuer, client, redirect, state, nonce, ID token, and access-token boundaries.
Validate X.509 paths, service names, key usage, constraints, time, and revocation without expanding the trust boundary.
Separate JWT claims, JWS signatures, JWE encryption, and JWK key data and apply a fixed validation policy.
39 related terms
Separate a source fact, a released claim, and a protected statement sent between an issuer and relying party.
Use consent to record a user's informed grant without treating it as proof that an action is safe or permitted.
Issue, deploy, rotate, revoke, recover, and retire certificates and private keys without breaking name or trust validation.
A DNS CNAME record states that its owner name is an alias for another domain name.
Encryption transforms plaintext into ciphertext under a cryptographic key. Symmetric encryption uses a shared secret key.
Prevent HTTP intermediaries from disagreeing about message boundaries, request length, transfer coding, and the start of the next request.
HTTP semantics define request methods, targets, fields, responses, status codes, authorities, and intermediary behavior.
Explain HTTPS as HTTP over an authenticated, encrypted TLS channel with explicit names, endpoints, and termination boundaries.
Establish trust between an identity provider and relying party without treating an assertion as universal authority.
Identity propagation carries verified information about the originating principal and, when needed, the acting service across request boundaries.
IPsec is a suite of protocols that protects IP traffic under a security policy.
Learn how JSON Web Tokens carry signed or encrypted claims, which checks a receiver must make, and how Pomerium uses a signed identity assertion.
Select trusted JSON Web Keys from an approved set, restrict algorithms and key use, and rotate without trusting token-controlled URLs.
Lightweight Directory Access Protocol (LDAP) is an Internet protocol for clients to access directory services that follow X.500 data and service models.
Learn how MCP authorization uses OAuth metadata, resource indicators, token audience checks, route policy, and tool authorization.
Model Context Protocol security is the set of controls that protects hosts, clients, servers, tools, authorization flows, and downstream resources.
Model Context Protocol is a client-server protocol for context exchange between AI applications and external systems.
Mutual TLS, or mTLS, is TLS with certificate authentication for both endpoints.
Learn how OAuth 2.0 separates clients, authorization servers, resource servers, scopes, tokens, PKCE, and current OAuth 2.1 guidance.
The client credentials grant issues authority to a confidential client acting for itself, not for a human user.
Discover authorization and resource metadata without allowing untrusted issuer, endpoint, key, or resource expansion.
An OAuth resource indicator identifies the protected resource for which a client requests an access token.
OpenID Connect is an identity layer on top of OAuth 2.0. It lets a client verify an end user's authentication and receive identity claims in an ID token.
Bind an OpenID Connect response to the initiating browser, issuer, client, redirect URI, nonce, and authorization request.
The OSI model is a seven-layer reference model, not a guarantee that each protocol provides reliability.
PKI is the people, policies, processes, and technology used to issue, validate, renew, and revoke public-key certificates.
Use refresh tokens only at the authorization server, bind them to a client, rotate or sender-constrain them, and detect replay.
Provision and deprovision accounts and groups without confusing lifecycle synchronization with authentication federation.
Select a route from trusted authority and path data so an attacker cannot redirect policy or credentials to the wrong upstream.
SSL 2.0 and SSL 3.0 are obsolete and must not be used. Modern systems use TLS.
Security Assertion Markup Language 2.0 exchanges authentication, attribute, and authorization decision assertions between federation parties.
Use clocks, expiries, nonces, sequence, versions, and replay state without treating wall time as a complete ordering or trust source.
Pomerium's signed header is the X-Pomerium-Jwt-Assertion header.
Software-defined networking separates programmable control functions from the packet-forwarding plane through defined abstractions and interfaces.
SSH authenticates a server and client, then multiplexes sessions, commands, and forwarding channels over one transport.
Exchange an incoming security token for narrow target authority while preserving subject, actor, audience, and delegation semantics.
Accept a token only from a trusted issuer and only at the resource audience for which the token was issued.
WebAuthn is a W3C API for creating and using public-key credentials scoped to a relying party.
WebSocket access starts with an HTTP upgrade and then carries long-lived bidirectional messages on one connection.