Pomerium
Identity-aware reverse proxy, successor to now obsolete oauth_proxy. It inserts an OAuth step before proxying your request to the backend, so that you can safely expose your self-hosted websites to public Internet.
It acts as an identity‑aware reverse proxy that inserts an OAuth authentication step before forwarding requests to internal services, allowing self‑hosted web applications to be exposed safely to the public Internet. By integrating with any OIDC‑compatible identity provider, it issues cryptographically signed JWTs for upstream connections and enforces access policies defined in YAML‑style code, providing continuous verification and centralized auditing of every request.
The proxy is built on top of the Envoy proxy layer, offering layer‑7 routing, scalability, and the ability to deploy alongside the protected applications without requiring a corporate VPN. It supports clientless access, enabling remote employees, contractors, and distributed teams to reach critical workloads with reduced latency and without installing VPN software.
Pomerium is released under the Apache‑2.0 license, is self‑hostable, and provides a free tier with no subscription requirements. It targets developers and operations teams that need a zero‑trust, context‑aware access solution for internal services while retaining full control over deployment and policy management.
Reviews
Loading reviews…
Similar apps

Password & Security
Authentik
authentik is an open-source identity provider that offers self-hosted authentication, authorization, and user management for businesses of…

Remote Access & VPN
Pangolin
Identity-aware tunneled reverse proxy with dashboard UI, access control, and WireGuard-based tunnels (alternative to Cloudflare Tunnel…

Remote Access & VPN
OpenZiti
Fully-featured, zero trust, full mesh overlay network. Includes a 2FA support out of the box, clients for all major desktop/mobile OS'es.

Security & Identity
Teleport
Certificate authority and access plane for SSH, Kubernetes, web applications, and databases.

Remote Access & VPN
Tailscale
A zero-config mesh VPN built on WireGuard that connects all your devices, no matter where they are, into a single private network.

Remote Access & VPN
Pangolin
Identity-aware VPN and proxy for remote access