Pomerium
An identity and context-aware access proxy written in Go that secures internal apps and services without a corporate VPN.
- GitHub stars
- 5k
- Last commit
- today
- Latest release
- v0.33.3
- Licence
- Apache-2.0
- Self-hosted
- Yes
- Hosted version
- Available

Pomerium is an identity and context-aware reverse proxy that makes secure, clientless connections to internal web apps and other services. The goal is to protect internal resources without asking users to connect through a corporate VPN.
According to the project, clientless access makes it easier to adopt, running tunnel-free and close to your apps and services makes it faster, and verifying each action before it executes makes it safer. Context-aware policies can draw on data from several sources, so access decisions can reflect your organization's own needs. Repository topics point to zero-trust, BeyondCorp-style, identity-aware proxy and IAM use cases.
Pomerium is written in Go and licensed under Apache-2.0. Teams that want a hosted control plane and a management GUI can look at Pomerium Zero, while the open-source proxy can be run on your own infrastructure. Documentation and tutorials are available on pomerium.com.
Key features
- Identity-aware reverse proxy
- Clientless access to internal apps
- Per-request verification of every action
- Context-aware access policies
- Tunnel-free deployment near your services
- Hosted control plane via Pomerium Zero
Pricing: Free Personal plan. Business costs $7 per user per month billed annually, with a free trial; Enterprise for fully self-hosted deployments is quoted.
