
Network & Infrastructure Security
Pomerium Zero Trust Proxy
Identity-aware proxy for zero trust access to applications without VPN or client software.
Pomerium Zero Trust Proxy Overview
What it does
Pomerium is an open-source Zero Trust Network Access (ZTNA) platform built as an identity-aware reverse proxy rather than a VPN or endpoint agent. Built on Envoy as a Layer 7 proxy, it sits in front of internal web applications, Kubernetes clusters, SSH hosts, databases, and Model Context Protocol (MCP) servers and evaluates user identity, device identity, and request context against Pomerium Policy Language rules on every request. It ships as Apache 2.0 Pomerium Core, Pomerium Zero with a managed control plane, and self-hosted Pomerium Enterprise.
How it works
Users authenticate through any OpenID Connect (OIDC) identity provider, then each request is authorized against Pomerium Policy Language rules combining email, domain, group, claim, and device criteria, with deny overriding allow. Authorized requests are proxied upstream with a JSON Web Token (JWT) identity, so applications need no separate login. Device identity comes from TPM enclaves or FIDO keys, and FleetDM posture data can feed policy. TCP services tunnel through CONNECT, native SSH uses OAuth with ephemeral certificates, Kubernetes access maps users to cluster RBAC, and a Model Context Protocol (MCP) gateway brokers upstream OAuth and per-tool allowlists for AI agents.
Credentials and traction
Pomerium holds a SOC 2 attestation published through a Vanta-hosted trust center. Published customers include Uber, Mercedes-Benz, NVIDIA, Okta, Zendesk, Writer, Ahold Delhaize, and Recursion, with case studies from Obsidian Security, Optoro, Crusoe Energy, Traders Club, Stellenbosch University, Pitt County School District, and a global CRM vendor securing more than 100,000 routes. The open-source proxy has passed 1.6 billion Docker Hub pulls, and adoption spans individual developers and homelab users through Global Fortune 2000 enterprises running self-hosted zero trust.
Key Capabilities
mapped to solution categoriesProvides access to browser-based internal applications through a reverse proxy without requiring a device agent, enabling secure access from unmanaged or contractor devices.
Grants access to individual named applications rather than network segments, users and devices can only reach explicitly authorized applications regardless of network position.
Re-evaluates user and device trust signals throughout an active session, revoking or stepping down access when anomalous behavior is detected, not just at authentication time.
Checks endpoint health (OS patch level, EDR presence, disk encryption, certificate validity) at each access request, enforcing minimum device security standards before granting application access.
Discovers internal applications accessible via VPN or direct network routes that should be brought under ZTNA policy, surfacing unmanaged application access.
Brokers authentication, upstream OAuth token injection, and per-tool authorization for AI agents calling internal Model Context Protocol servers through the access proxy.
Fronts the Kubernetes API server and maps identity-provider users and groups to cluster RBAC through impersonation or JWT authentication, replacing per-cluster kubeconfig credentials.
Proxies SSH natively with OAuth authentication and short-lived certificates issued per session, without a custom client, optionally recording sessions for audit.
Expresses per-route access rules in a declarative, version-controllable policy language evaluated on every request, distinct from console-only policy builders.
Integrations
compatible toolsImplementation & support
Info last updated on September 7, 2026
Buyers
Start a shortlist with Pomerium Zero Trust Proxy
Compare options, add your notes, and run informed evaluations.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.